Vulnerabilidades en containerd
23 resultadosAnálisis Vexday
O containerd apresenta 23 vulnerabilidades catalogadas, com 6 reveladas nos últimos 90 dias, indicando risco contínuo em um componente crítico de infraestrutura de containers. Nenhuma vulnerabilidade está sob exploração ativa conhecida (KEV), mas apenas 1 crítica foi identificada, reduzindo o nível imediato de alerta. A fraqueza dominante (CWE-400: Uncontrolled Resource Consumption) sugere problemas de negação de serviço, requerendo monitoramento de aplicações dependentes deste projeto.
CVE-2022-23648HIGHInsecure handling of image volumes in containerd CRI pluginEPSS 27.4%CVE-2020-15257MEDIUMcontainerd-shim API Exposed to Host Network ContainersEPSS 3.2%CVE-2022-24778HIGHIncorrect Authorization in imgcryptEPSS 2.7%CVE-2020-15157MEDIUMcontainerd can be coerced into leaking credentials during image pullEPSS 2.2%CVE-2021-21334MEDIUMenvironment variable leakEPSS 2.0%CVE-2021-43816HIGHImproper Preservation of Permissions in containerdEPSS 1.7%CVE-2021-32760MEDIUMArchive package allows chmod of file outside of unpack target directoryEPSS 1.6%CVE-2022-23471MEDIUMcontainerd CRI stream server: Host memory exhaustion through terminal resize goroutine leakEPSS 1.0%CVE-2023-25173MEDIUMcontainerd supplementary groups are not set up properlyEPSS 0.5%CVE-2021-41103MEDIUMInsufficiently restricted permissions on plugin directoriesEPSS 0.5%CVE-2025-47290HIGHContainerd vulnerable to host filesystem access during image unpackEPSS 0.5%CVE-2022-31030MEDIUMcontainerd CRI plugin: Host memory exhaustion through ExecSyncEPSS 0.4%CVE-2023-25153MEDIUMcontainerd OCI image importer memory exhaustionEPSS 0.4%CVE-2026-53492HIGHcontainerd CRI checkpoint restore CDI annotation smugglingEPSS 0.3%CVE-2026-50195MEDIUMcontainerd: CRI checkpoint import allows local image tag poisoningEPSS 0.3%CVE-2024-40635MEDIUMcontainerd has an integer overflow in User ID handlingEPSS 0.3%CVE-2026-47262MEDIUMcontainerd image-triggered runtime DoS via unbounded group parsingEPSS 0.3%CVE-2025-47291MEDIUMcontainerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.EPSS 0.2%CVE-2026-46680HIGHcontainerd user ID handling bypass allows runAsNonRoot evasionEPSS 0.2%CVE-2026-53489HIGHcontainerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restoreEPSS 0.2%