VulnSea

containers has 12 CVEs on record between 2021 and 2026. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: github.com/containers/buildah (4), github.com/containers/podman/v4 (3), aardvark-dns (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 2

Products

  • github.com/containers/buildah 4
  • github.com/containers/podman/v4 3
  • aardvark-dns 1
  • common 1
  • github.com/containers/image 1
  • github.com/containers/podman/v3 1
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

containers vulnerabilities

CVEs affecting containers, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-44517Medium· 6.3
3mo ago

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Sunlitcontainers · github.com/containers/buildahEPSS 0.18%via GHSA
CVE-2026-55686Medium· 5.3
3mo ago

Podman: WORKDIR symlink traversal vulnerability

Podman: WORKDIR symlink traversal vulnerability

Sunlitcontainers · github.com/containers/podman/v5EPSS 0.37%via GHSA
CVE-2025-6032High· 8.3
1y ago

A flaw was found in Podman

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

Twilightcontainers · github.com/containers/podman/v4EPSS 0.48%via NVD
CVE-2024-11218High· 8.6
1y ago

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …

Twilightcontainers · github.com/containers/buildahEPSS 0.36%via NVD
CVE-2024-9341Medium· 5.4
1y ago

A flaw was found in Go

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic …

Sunlitcontainers · commonEPSS 1.0%via NVD
CVE-2024-8418High· 7.5
2y ago

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to b…

Twilightcontainers · aardvark-dnsEPSS 0.77%via NVD
CVE-2024-3727High· 8.3
2y ago

A flaw was found in the github.com/containers/image library

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Twilightcontainers · github.com/containers/imageEPSS 1.3%via NVD
CVE-2024-1753High· 8.6
2y ago

Podman affected by CVE-2024-1753 container escape at build time

Podman affected by CVE-2024-1753 container escape at build time

Twilightcontainers · github.com/containers/podman/v4EPSS 0.49%via OSV
CVE-2022-1227High· 8.8PoC
4y ago

Podman publishes a malicious image to public registries

Podman publishes a malicious image to public registries

Midnightcontainers · github.com/containers/podman/v3EPSS 4.2%via OSV
CVE-2022-27649High· 7.5
4y ago

Podman's default inheritable capabilities for linux container not empty

Podman's default inheritable capabilities for linux container not empty

Twilightcontainers · github.com/containers/podman/v4EPSS 1.4%via OSV
CVE-2022-27651Medium· 6.8
4y ago

Non-empty default inheritable capabilities for linux container in Buildah

Non-empty default inheritable capabilities for linux container in Buildah

Sunlitcontainers · github.com/containers/buildahEPSS 1.3%via OSV
CVE-2021-3602Medium· 5.5
5y ago

Buildah processes using chroot isolation may leak environment values to intermediate processes

Buildah processes using chroot isolation may leak environment values to intermediate processes

Sunlitcontainers · github.com/containers/buildahEPSS 0.33%via OSV
containers vulnerabilities (CVEs) · VulnSea