<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – containerd</title>
  <link>https://cvedaily.com/pages/tags/containerd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/containerd.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – containerd</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-27887 – Spin is an open source developer tool for building and running serverless applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27887</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27887</strong></p>
  <p>Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to buffer the entire response before delivering it to the guest, which can lead to…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24054 – Kata Containers is an open source project focusing on a standard implementation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24054</guid>
    <pubDate>Thu, 29 Jan 2026 18:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24054</strong></p>
  <p>Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the container rootfs. When the Kata runtime attempts to mount the container rootfs, the b…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64329 – containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64329</guid>
    <pubDate>Fri, 07 Nov 2025 05:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64329</strong></p>
  <p>containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25621 – containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25621</guid>
    <pubDate>Thu, 06 Nov 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25621</strong></p>
  <p>containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorr…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-279</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47291 – containerd is an open-source container runtime. A bug was found in the container...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47291</guid>
    <pubDate>Wed, 21 May 2025 18:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47291</strong></p>
  <p>containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honored. This may cause a denial of service of the Kubernetes node. This bug has been fixed in containerd…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47290 – containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47290</guid>
    <pubDate>Tue, 20 May 2025 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47290</strong></p>
  <p>containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The only affected version of containerd is 2.1.0.  Other versions of containerd are not affected. This bug has been fixed in containerd 2.1.1. Users…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40635 – containerd is an open-source container runtime. A bug was found in containerd pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40635</guid>
    <pubDate>Mon, 17 Mar 2025 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40635</strong></p>
  <p>containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-32684 – Lima launches Linux virtual machines, typically on macOS, for running containerd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32684</guid>
    <pubDate>Tue, 30 May 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-32684</strong></p>
  <p>Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is mounted from the host. The official templates of Lima and the well-known third party products (Colima, Rancher Desktop, and Finch) are unlikely to be affected by…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25173 – containerd is an open source container runtime. A bug was found in containerd pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25173</guid>
    <pubDate>Thu, 16 Feb 2023 15:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25173</strong></p>
  <p>containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially g…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25153 – containerd is an open source container runtime. Before versions 1.6.18 and 1.5.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25153</guid>
    <pubDate>Thu, 16 Feb 2023 15:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25153</strong></p>
  <p>containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18.  Users should update to these versions to resolve the i…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23471 – containerd is an open source container runtime. A bug was found in containerd's ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23471</guid>
    <pubDate>Wed, 07 Dec 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23471</strong></p>
  <p>containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails to launch due to, for example, a faulty command, the goroutine will be stuck waiting to send without a receiver, resultin…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31030 – containerd is an open source container runtime. A bug was found in the container...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31030</guid>
    <pubDate>Thu, 09 Jun 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31030</strong></p>
  <p>containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be c…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24778 – The imgcrypt library provides API exensions for containerd to support encrypted ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24778</guid>
    <pubDate>Fri, 25 Mar 2022 18:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24778</strong></p>
  <p>The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt function `CheckAuthorization` is supposed to check whether the current used is authorized to access an encrypted image and prevent the user from running an image that another user…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23648 – containerd is a container runtime available as a daemon for Linux and Windows. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23648</guid>
    <pubDate>Thu, 03 Mar 2022 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23648</strong></p>
  <p>containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforc…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43816 – containerd is an open source container runtime. On installations using SELinux, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43816</guid>
    <pubDate>Wed, 05 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43816</strong></p>
  <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved b…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41103 – containerd is an open source container runtime with an emphasis on simplicity, r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41103</guid>
    <pubDate>Mon, 04 Oct 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41103</strong></p>
  <p>containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32760 – containerd is a container runtime. A bug was found in containerd versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32760</guid>
    <pubDate>Mon, 19 Jul 2021 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32760</strong></p>
  <p>containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, an…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21334 – In containerd (an industry-standard container runtime) before versions 1.3.10 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21334</guid>
    <pubDate>Wed, 10 Mar 2021 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21334</strong></p>
  <p>In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers. If the affected contai…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15257 – containerd is an industry-standard container runtime and is available as a daemo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15257</guid>
    <pubDate>Tue, 01 Dec 2020 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15257</strong></p>
  <p>containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict access to the abstract Unix domain s…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15157 – In containerd (an industry-standard container runtime) before version 1.2.14 the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15157</guid>
    <pubDate>Fri, 16 Oct 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15157</strong></p>
  <p>In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15157">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
