Junglewise Threat Intelligence

CVE-2026-53488: containerd command execution via unvalidated CRI image labels

CVE-2026-53488 · Severity: high · CVSS 4 · Published 2026-07-01

Technologies: Containerd, github.com/containerd/containerd (Go), github.com/containerd/containerd/v2 (Go). Vendors: Containerd, Go.

Executive brief

containerd is a widely used industry-standard container runtime that manages the lifecycle of software containers. A vulnerability exists where malicious metadata embedded in a container image can bypass security checks and trigger the execution of unauthorized commands on the underlying host server. This could allow an attacker who can trick a system into pulling a malicious image to gain full control over the host machine, potentially leading to data theft or service disruption.

Technical details

A vulnerability in the containerd CRI (Container Runtime Interface) plugin involves improper input validation of labels defined in an image configuration (e.g., the LABEL instruction in a Dockerfile). The plugin propagates these labels to the container without validation. If a secondary plugin or system component consumes these container labels for operations without further sanitization, an attacker can achieve arbitrary command execution on the host. The attack vector is local in the sense that it requires the system to pull and process a malicious image. The issue is addressed in containerd versions 1.7.33, 2.0.10, 2.1.9, 2.2.5, and 2.3.2.

Affected products

  • containerd containerd >= 1.7.0, < 1.7.33; >= 2.0.0, < 2.0.10; >= 2.1.0, < 2.1.9; >= 2.2.0, < 2.2.5; >= 2.3.0, < 2.3.2

Timeline

  • 2026-06-18: advisory: Initial GitHub advisory published
  • 2026-07-01: disclosed: NVD publication date
  • 2026-06-30: patched: Fixes released in multiple versions

References

Related threats