The container runtime that pulls images and runs containers under Kubernetes.
Version: 2.3.6
Type: Runtime
License:
| Expand | CVE | Title | Status | Sev |
|---|---|---|---|---|
| CVE-2026-46680 Open CVE-2026-46680 in a new tab | containerd user ID handling bypass allows runAsNonRoot evasion | Not affected | Unknown | |
| CVE-2026-47262 Open CVE-2026-47262 in a new tab | containerd image-triggered runtime DoS via unbounded group parsing | Not affected | Unknown | |
| CVE-2026-53488 Open CVE-2026-53488 in a new tab | containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull | Not affected | Unknown | |
| CVE-2026-53493 Open CVE-2026-53493 in a new tab | Containerd has image-pull DoS via crafted OCI index graph amplification | Not affected | Unknown | |
| CVE-2026-53495 Open CVE-2026-53495 in a new tab | containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service | Not affected | Unknown | |
| GO-2026-5064 Open GO-2026-5064 in a new tab | containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd | Not affected | Unknown | |
| GO-2026-5338 Open GO-2026-5338 in a new tab | containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd | Not affected | Unknown | |
| GO-2026-5622 Open GO-2026-5622 in a new tab | Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd | Not affected | Unknown |
containerd user ID handling bypass allows runAsNonRoot evasion
containerd image-triggered runtime DoS via unbounded group parsing
containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
Containerd has image-pull DoS via crafted OCI index graph amplification
containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service
containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd
containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd