CVE-2026-41326High· 8.2▾ TwilightKata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile han…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.
confidential_containers >= 0.9.0, < 0.20.0kata_containers >= 3.4.0, < 3.29.0Upgrade past the affected range:
confidential_containers 0.20.0kata_containers 3.29.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63125Critical· 9.9Incus is a system container and virtual machine manager
CVE-2026-64846Low· 2.8Nix is a package manager for Linux and other Unix systems
CVE-2026-47766Nonecrun is an open source OCI Container Runtime fully written in C
CVE-2026-91202Medium· 6.1A flaw was found in cockpit-files
CVE-2026-92958High· 8.5vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM
CVE-2026-91099Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP