Please see https://github.com/containerd/project/blob/main/SECURITY.md
Repository navigation
Security: containerd/containerd
Security
SECURITY.md
-
containerd CRI plugin: Checkpoint restore bypasses destination security contextGHSA-p7v4-vr35-mj6f published
Sep 1, 2026 by samuelkarpCritical -
CDI annotation smuggling during CRI checkpoint restoreGHSA-33vj-92qq-66hc published
Jun 18, 2026 by samuelkarpCritical -
containerd CRI — image-config LABEL flows to host-root command execution from an image pullGHSA-xhf5-7wjv-pqxp published
Jun 18, 2026 by samuelkarpCritical -
containerd CRI plugin: Unbounded I/O draining in ExecSync causes node-level denial of serviceGHSA-7jxh-36q5-gcqv published
Sep 4, 2026 by samuelkarpModerate -
CRI checkpoint import allows local image tag poisoningGHSA-cvxm-645q-p574 published
Jun 18, 2026 by samuelkarpCritical -
Arbitrary host file read via symlink following in CRI checkpoint restoreGHSA-rgh6-rfwx-v388 published
Jun 18, 2026 by samuelkarpHigh -
Unpack DoS via repeated opaque whiteoutsGHSA-rp3h-jf77-q9p4 published
Sep 4, 2026 by samuelkarpModerate -
Image-pull DoS via crafted OCI index graph amplificationGHSA-pg57-6jwg-q645 published
Sep 24, 2026 by samuelkarpModerate -
containerd image-triggered runtime DoS via unbounded group parsingGHSA-jpcc-p29g-p8mq published
Jun 18, 2026 by samuelkarpModerate -
containerd user ID handling bypass allows runAsNonRoot evasionGHSA-fqw6-gf59-qr4w published
May 20, 2026 by samuelkarpModerate
Learn more about advisories related to containerd/containerd in the GitHub Advisory Database