CVE-2022-1227High· 8.8▾ MidnightPoC availablePodman publishes a malicious image to public registries
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
4.2%
1 GitHub repo (last check)
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
github.com/containers/podman/v3 < 3.4github.com/containers/psgo < 1.7.2Upgrade to a patched release:
github.com/containers/podman/v3 3.4github.com/containers/psgo 1.7.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-27649High· 7.5Podman's default inheritable capabilities for linux container not empty
CVE-2024-1753High· 8.6Podman affected by CVE-2024-1753 container escape at build time
CVE-2025-6032High· 8.3A flaw was found in Podman
CVE-2022-27651Medium· 6.8Non-empty default inheritable capabilities for linux container in Buildah
CVE-2021-3602Medium· 5.5Buildah processes using chroot isolation may leak environment values to intermediate processes
CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library