github.com/opencontainers/runc vulnerabilities
CVEs whose affected-version data names the github.com/opencontainers/runc package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-41579Medium· 3.3runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
▾ Sunlitopencontainers · github.com/opencontainers/runcEPSS 0.19%via GHSA
CVE-2021-43784Medium· 6.0Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
▾ Sunlitopencontainers · github.com/opencontainers/runcEPSS 1.7%via OSV
CVE-2021-30465High· 7.6mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
▾ Twilightopencontainers · github.com/opencontainers/runcEPSS 6.6%via OSV