Vendor
Containers vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in Containers: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88265, was published on 10 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 0
- Exploited in the wild
- 0
About Containers
Containers is an open-source organization focused on providing tools for container image management and execution.
Containers technologies
Latest Containers vulnerabilities
- CVE-2026-88265: crun symlink following in /dev/null leads to host file accessmediumCVSS 5.6EPSS 0.1%
- CVE-2026-88264: crun terminal setup path redirection vulnerabilitymediumCVSS 5.6EPSS 0.1%
- CVE-2026-84042: crun privilege escalation in libkrun with passt networkinghighCVSS 7.8EPSS 0.1%
- CVE-2026-44517: Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in…mediumCVSS 6.3EPSS 0.2%
- CVE-2026-52791: containers fuse-overlayfs SUID bit preservation on truncateinfoCVSS 2
- CVE-2026-55686: Podman symlink traversal in WORKDIR path resolutionmediumCVSS 5.3
- CVE-2026-33414: Podman command injection in HyperV machine backendhighCVSS 7.8EPSS 0.5%
- CVE-2026-35406: Containers Aardvark-dns infinite loop via malformed TCP DNS queryhighCVSS 7.5EPSS 0.4%
- CVE-2025-9566: Podman path traversal host file overwrite in kube playhighCVSS 8.1EPSS 0.1%
- CVE-2024-9675: containers Buildah path traversal in cache mountsmediumCVSS 4.4EPSS 0.4%
Most severe Containers vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-9566: Podman path traversal host file overwrite in kube playhighCVSS 8.1EPSS 0.1%
- CVE-2026-33414: Podman command injection in HyperV machine backendhighCVSS 7.8EPSS 0.5%
- CVE-2026-84042: crun privilege escalation in libkrun with passt networkinghighCVSS 7.8EPSS 0.1%
- CVE-2026-35406: Containers Aardvark-dns infinite loop via malformed TCP DNS queryhighCVSS 7.5EPSS 0.4%
- CVE-2026-44517: Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in…mediumCVSS 6.3EPSS 0.2%
- CVE-2026-88265: crun symlink following in /dev/null leads to host file accessmediumCVSS 5.6EPSS 0.1%
- CVE-2026-88264: crun terminal setup path redirection vulnerabilitymediumCVSS 5.6EPSS 0.1%
- CVE-2026-55686: Podman symlink traversal in WORKDIR path resolutionmediumCVSS 5.3
- CVE-2024-9675: containers Buildah path traversal in cache mountsmediumCVSS 4.4EPSS 0.4%
- CVE-2026-52791: containers fuse-overlayfs SUID bit preservation on truncateinfoCVSS 2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/containers.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Containers vulnerabilities", https://junglewise.ai/threats/vendors/containers, 26 September 2026.