Technology · Go
github.com/cri-o/cri-o (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in github.com/cri-o/cri-o (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-4437, was published on 29 August 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest github.com/cri-o/cri-o (Go) vulnerabilities
- CVE-2025-4437: GO-2025-3897 - CRI-O has Potential High Memory Consumption from File Read in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.3%
- CVE-2025-0750: GO-2025-3426 - CRI-O Path Traversal vulnerability in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.2%
- CVE-2024-8676: GO-2024-3292 - CRI-O: Maliciously structured checkpoint file can gain arbitrary node access in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.8%
- CVE-2022-4318: GO-2022-1206 - CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.3%
- CVE-2022-2995: GO-2022-1014 - CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure in…lowCVSS 3.1EPSS 0.4%
- CVE-2022-0532: GO-2022-0608 - Incorrect Permission Assignment for Critical Resource in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.8%
- CVE-2022-1708: GO-2022-0480 - Node DOS by way of memory exhaustion through ExecSync request in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 3.1%
- CVE-2022-27652: GO-2022-0426 - Incorrect Default Permissions in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.3%
- CVE-2022-0811: GO-2022-0354 - Code Injection in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 19.1%
- GO-2022-0363 - Sysctls applied to containers with host IPC or host network namespaces can affect the host in github.com/cri-o/cri-oinfo
- CVE-2023-6476: GO-2024-2458 - CRI-O's pods can break out of resource confinement on cgroupv2 in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.9%
- CVE-2024-5154: GO-2024-2919 - malicious container creates symlink "mtab" on the host External in github.com/cri-o/cri-olowCVSS 3.1EPSS 1.2%
- CVE-2024-3154: GO-2024-2791 - CRI-O vulnerable to an arbitrary systemd property injection in github.com/cri-o/cri-olowCVSS 3.1EPSS 1.4%
Most severe github.com/cri-o/cri-o (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-0811: GO-2022-0354 - Code Injection in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 19.1%
- CVE-2022-1708: GO-2022-0480 - Node DOS by way of memory exhaustion through ExecSync request in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 3.1%
- CVE-2024-3154: GO-2024-2791 - CRI-O vulnerable to an arbitrary systemd property injection in github.com/cri-o/cri-olowCVSS 3.1EPSS 1.4%
- CVE-2024-5154: GO-2024-2919 - malicious container creates symlink "mtab" on the host External in github.com/cri-o/cri-olowCVSS 3.1EPSS 1.2%
- CVE-2023-6476: GO-2024-2458 - CRI-O's pods can break out of resource confinement on cgroupv2 in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.9%
- CVE-2022-0532: GO-2022-0608 - Incorrect Permission Assignment for Critical Resource in CRI-O in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.8%
- CVE-2024-8676: GO-2024-3292 - CRI-O: Maliciously structured checkpoint file can gain arbitrary node access in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.8%
- CVE-2022-2995: GO-2022-1014 - CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure in…lowCVSS 3.1EPSS 0.4%
- CVE-2022-4318: GO-2022-1206 - CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.3%
- CVE-2025-4437: GO-2025-3897 - CRI-O has Potential High Memory Consumption from File Read in github.com/cri-o/cri-olowCVSS 3.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-cri-o-cri-o.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/cri-o/cri-o (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-cri-o-cri-o, 27 September 2026.