Technology · Go
github.com/opencontainers/runc (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in github.com/opencontainers/runc (Go): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-41579, was published on 1 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About github.com/opencontainers/runc (Go)
A CLI tool for spawning and running containers according to the OCI specification.
Latest github.com/opencontainers/runc (Go) vulnerabilities
- CVE-2026-41579: opencontainers runc symlink following in rootfs setuplowCVSS 3.3EPSS 0.2%
- CVE-2025-31133: GO-2025-4096 - Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runchighCVSS 4EPSS 0.8%
- CVE-2025-52881: GO-2025-4098 - Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in…mediumCVSS 4EPSS 0.6%
- CVE-2025-52565: GO-2025-4097 - Container escape with malicious config due to /dev/console mount and related races in…mediumCVSS 4EPSS 0.6%
- CVE-2025-27612: Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw66lowCVSS 3.1EPSS 0.2%
- CVE-2024-45310: GO-2024-3110 - Can be confused to create empty files/directories on the host in github.com/opencontainers/runclowCVSS 3.1EPSS 0.3%
- CVE-2021-30465: GO-2022-0914 - Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in…lowCVSS 3.1EPSS 6.6%
- CVE-2016-9962: GO-2022-0835 - Information Exposure in RunC in github.com/opencontainers/runclowCVSS 3EPSS 0.4%
- CVE-2022-29162: GO-2022-0452 - Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runclowCVSS 3.1EPSS 0.4%
- GO-2022-0396 - Devices resource list treated as a blacklist by default in github.com/opencontainers/runcinfo
- CVE-2023-28642: GO-2023-1683 - AppArmor bypass with symlinked /proc in github.com/opencontainers/runclowCVSS 3.1EPSS 0.3%
- CVE-2023-25809: GO-2023-1682 - Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runclowCVSS 3.1EPSS 0.3%
- CVE-2023-27561: GO-2023-1627 - Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runclowCVSS 3.1EPSS 0.4%
- Withdrawn: Runc allows an arbitrary systemd property to be injectedlowCVSS 3.1
- CVE-2024-21626: opencontainers runc container breakout via leaked file descriptorshighCVSS 8.6EPSS 18.1%
- CVE-2021-43784: GO-2022-0274 - Namespace restriction bypass in github.com/opencontainers/runclowCVSS 3.1EPSS 1.7%
- devices resource list treated as a blacklist by defaultinfo
- CVE-2019-19921: GO-2021-0087 - Race condition in github.com/opencontainers/runclowCVSS 3.1EPSS 0.4%
- CVE-2016-3697: GO-2021-0070 - Privilege escalation in github.com/opencontainers/runclowCVSS 3.1EPSS 0.4%
- CVE-2019-16884: GO-2021-0085 - Authorization bypass in github.com/opencontainers/runclowCVSS 3.1EPSS 4.4%
Most severe github.com/opencontainers/runc (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-21626: opencontainers runc container breakout via leaked file descriptorshighCVSS 8.6EPSS 18.1%
- CVE-2025-31133: GO-2025-4096 - Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runchighCVSS 4EPSS 0.8%
- CVE-2025-52565: GO-2025-4097 - Container escape with malicious config due to /dev/console mount and related races in…mediumCVSS 4EPSS 0.6%
- CVE-2025-52881: GO-2025-4098 - Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in…mediumCVSS 4EPSS 0.6%
- CVE-2026-41579: opencontainers runc symlink following in rootfs setuplowCVSS 3.3EPSS 0.2%
- CVE-2021-30465: GO-2022-0914 - Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in…lowCVSS 3.1EPSS 6.6%
- CVE-2019-16884: GO-2021-0085 - Authorization bypass in github.com/opencontainers/runclowCVSS 3.1EPSS 4.4%
- CVE-2021-43784: GO-2022-0274 - Namespace restriction bypass in github.com/opencontainers/runclowCVSS 3.1EPSS 1.7%
- CVE-2023-27561: GO-2023-1627 - Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runclowCVSS 3.1EPSS 0.4%
- CVE-2019-19921: GO-2021-0087 - Race condition in github.com/opencontainers/runclowCVSS 3.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-opencontainers-runc.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/opencontainers/runc (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-opencontainers-runc, 28 September 2026.