containers has 12 CVEs on record between 2021 and 2026. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: github.com/containers/buildah (4), github.com/containers/podman/v4 (3), aardvark-dns (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Products
- github.com/containers/buildah 4
- github.com/containers/podman/v4 3
- aardvark-dns 1
- common 1
- github.com/containers/image 1
- github.com/containers/podman/v3 1
Worst active — by depth score
CVE-2022-1227High· 8.8Podman publishes a malicious image to public registries61CVE-2024-11218High· 8.6A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile47CVE-2024-1753High· 8.6Podman affected by CVE-2024-1753 container escape at build time 47CVE-2025-6032High· 8.3A flaw was found in Podman46CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library46
containers vulnerabilities
CVEs affecting containers, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-44517Medium· 6.3Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive
Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive
CVE-2026-55686Medium· 5.3Podman: WORKDIR symlink traversal vulnerability
Podman: WORKDIR symlink traversal vulnerability
CVE-2025-6032High· 8.3A flaw was found in Podman
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
CVE-2024-11218High· 8.6A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …
CVE-2024-9341Medium· 5.4A flaw was found in Go
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic …
CVE-2024-8418High· 7.5A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to b…
CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVE-2024-1753High· 8.6Podman affected by CVE-2024-1753 container escape at build time
Podman affected by CVE-2024-1753 container escape at build time
CVE-2022-1227High· 8.8PoCPodman publishes a malicious image to public registries
Podman publishes a malicious image to public registries
CVE-2022-27649High· 7.5Podman's default inheritable capabilities for linux container not empty
Podman's default inheritable capabilities for linux container not empty
CVE-2022-27651Medium· 6.8Non-empty default inheritable capabilities for linux container in Buildah
Non-empty default inheritable capabilities for linux container in Buildah
CVE-2021-3602Medium· 5.5Buildah processes using chroot isolation may leak environment values to intermediate processes
Buildah processes using chroot isolation may leak environment values to intermediate processes