VulnSea

containerd has 14 CVEs on record between 2021 and 2026. 1 was published in the last 90 days. The median CVSS is 5.7 (medium). None have a confirmed exploitation report. Most affected products: github.com/containerd/containerd (10), github.com/containerd/containerd/v2 (3), containerd (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.7
Publish → KEV
Last 90 days
1 prev 2

Products

  • github.com/containerd/containerd 10
  • github.com/containerd/containerd/v2 3
  • containerd 1
14
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

containerd vulnerabilities

CVEs affecting containerd, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-53495Medium· 6.8
1w ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …

Sunlitcontainerd · containerdEPSS 0.19%via NVD
CVE-2026-47262Medium
3mo ago

containerd image-triggered runtime DoS via unbounded group parsing

containerd image-triggered runtime DoS via unbounded group parsing

Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.27%via GHSA
CVE-2026-50195Medium
3mo ago

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.30%via GHSA
CVE-2024-40635Medium· 4.6PoC
1y ago

containerd has an integer overflow in User ID handling

containerd has an integer overflow in User ID handling

Twilightcontainerd · github.com/containerd/containerd/v2EPSS 0.29%via OSV
CVE-2021-21334Medium· 6.3
2y ago

containerd environment variable leak

containerd environment variable leak

Sunlitcontainerd · github.com/containerd/containerdEPSS 2.0%via OSV
GHSA-7ww5-4wqc-m92cMedium
2y ago

containerd allows RAPL to be accessible to a container

containerd allows RAPL to be accessible to a container

Sunlitcontainerd · github.com/containerd/containerdvia OSV
CVE-2023-25153Medium· 5.5
3y ago

OCI image importer memory exhaustion in github.com/containerd/containerd

OCI image importer memory exhaustion in github.com/containerd/containerd

Sunlitcontainerd · github.com/containerd/containerdEPSS 0.36%via OSV
CVE-2022-23471Medium· 5.7
3y ago

containerd CRI stream server vulnerable to host memory exhaustion via terminal

containerd CRI stream server vulnerable to host memory exhaustion via terminal

Sunlitcontainerd · github.com/containerd/containerdEPSS 1.1%via OSV
CVE-2022-31030Medium· 5.5
4y ago

containerd CRI plugin: Host memory exhaustion through ExecSync

containerd CRI plugin: Host memory exhaustion through ExecSync

Sunlitcontainerd · github.com/containerd/containerdEPSS 0.38%via OSV
CVE-2020-15157Medium· 6.1
4y ago

containerd v1.2.x can be coerced into leaking credentials during image pull

containerd v1.2.x can be coerced into leaking credentials during image pull

Sunlitcontainerd · github.com/containerd/containerdEPSS 2.3%via OSV
CVE-2021-43816High· 8.0
4y ago

Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux

Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux

Twilightcontainerd · github.com/containerd/containerdEPSS 1.7%via OSV
GHSA-5j5w-g665-5m35Low· 3.0
4y ago

Ambiguous OCI manifest parsing

Ambiguous OCI manifest parsing

Sunlitcontainerd · github.com/containerd/containerdvia OSV
CVE-2021-41103Medium· 5.9
4y ago

Insufficiently restricted permissions on plugin directories

Insufficiently restricted permissions on plugin directories

Sunlitcontainerd · github.com/containerd/containerdEPSS 0.52%via OSV
CVE-2020-15257Medium· 5.2PoC
5y ago

containerd-shim API Exposed to Host Network Containers

containerd-shim API Exposed to Host Network Containers

Twilightcontainerd · github.com/containerd/containerdEPSS 3.2%via OSV
containerd vulnerabilities (CVEs) · VulnSea