opencontainers
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/19/2026, opencontainers recorded 1 security vulnerabilities in the last 90 days across 1 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, runc had the most security vulnerabilities in the opencontainers ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-41579runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published07/01/2026 | SeverityLow |
CVE-2025-52881runc: LSM labels can be bypassed with malicious config using dummy procfs files | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published11/06/2025 | SeverityHigh |
CVE-2025-52565container escape due to /dev/console mount and related races | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published11/06/2025 | SeverityHigh |
CVE-2025-31133runc container escape via "masked path" abuse due to mount race conditions | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published11/06/2025 | SeverityHigh |
CVE-2024-45310runc can be confused to create empty files/directories on the host | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published09/03/2024 | SeverityLow |
CVE-2024-21626runc container breakout through process.cwd trickery and leaked fds | Exploitation statusPublic exploit | FixNot confirmed | Affected productrunc | Published01/31/2024 | SeverityHigh |
CVE-2023-25809rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc | Exploitation statusNot known exploited | FixNot confirmed | Affected productrunc | Published03/29/2023 | SeverityMedium |
CVE-2023-28642AppArmor bypass with symlinked /proc in runc | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published03/29/2023 | SeverityMedium |
CVE-2022-29162Incorrect Default Permissions in runc | Exploitation statusNot known exploited | FixYes | Affected productrunc | Published05/17/2022 | SeverityMedium |
CVE-2021-43784Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration | Exploitation statusNot known exploited | FixNot confirmed | Affected productrunc | Published12/06/2021 | SeverityMedium |
CVE-2021-41190Clarify Content-Type handling in OCI spec | Exploitation statusNot confirmed | FixNot confirmed | Affected productdistribution-spec | Published11/17/2021 | SeverityLow |