LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-50195

linuxfoundation · containerd

Published
CVSS9.9
Severitycritical
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknowingly execute the attacker's malicious image instead of the legitimate one. This can lead to a compr

References

← Back to the CVE Tracker

Our coverage of CVE-2026-50195

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-50195.