containerd has 14 CVEs on record between 2021 and 2026. 1 was published in the last 90 days. The median CVSS is 5.7 (medium). None have a confirmed exploitation report. Most affected products: github.com/containerd/containerd (10), github.com/containerd/containerd/v2 (3), containerd (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.7
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Products
- github.com/containerd/containerd 10
- github.com/containerd/containerd/v2 3
- containerd 1
Worst active — by depth score
CVE-2021-43816High· 8.0Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux44CVE-2020-15257Medium· 5.2containerd-shim API Exposed to Host Network Containers41CVE-2026-53495Medium· 6.8containerd is an open-source container runtime37CVE-2024-40635Medium· 4.6containerd has an integer overflow in User ID handling37CVE-2021-21334Medium· 6.3containerd environment variable leak35
containerd vulnerabilities
CVEs affecting containerd, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-53495Medium· 6.8containerd is an open-source container runtime
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …
CVE-2026-47262Mediumcontainerd image-triggered runtime DoS via unbounded group parsing
containerd image-triggered runtime DoS via unbounded group parsing
CVE-2026-50195Mediumcontainerd: CRI checkpoint import allows local image tag poisoning
containerd: CRI checkpoint import allows local image tag poisoning
CVE-2024-40635Medium· 4.6PoCcontainerd has an integer overflow in User ID handling
containerd has an integer overflow in User ID handling
CVE-2021-21334Medium· 6.3containerd environment variable leak
containerd environment variable leak
GHSA-7ww5-4wqc-m92cMediumcontainerd allows RAPL to be accessible to a container
containerd allows RAPL to be accessible to a container
CVE-2023-25153Medium· 5.5OCI image importer memory exhaustion in github.com/containerd/containerd
OCI image importer memory exhaustion in github.com/containerd/containerd
CVE-2022-23471Medium· 5.7containerd CRI stream server vulnerable to host memory exhaustion via terminal
containerd CRI stream server vulnerable to host memory exhaustion via terminal
CVE-2022-31030Medium· 5.5containerd CRI plugin: Host memory exhaustion through ExecSync
containerd CRI plugin: Host memory exhaustion through ExecSync
CVE-2020-15157Medium· 6.1containerd v1.2.x can be coerced into leaking credentials during image pull
containerd v1.2.x can be coerced into leaking credentials during image pull
CVE-2021-43816High· 8.0Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
GHSA-5j5w-g665-5m35Low· 3.0Ambiguous OCI manifest parsing
Ambiguous OCI manifest parsing
CVE-2021-41103Medium· 5.9Insufficiently restricted permissions on plugin directories
Insufficiently restricted permissions on plugin directories
CVE-2020-15257Medium· 5.2PoCcontainerd-shim API Exposed to Host Network Containers
containerd-shim API Exposed to Host Network Containers