cbcvebase.
CVE-2026-47262
published 2026-07-01

CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously…

PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.27%
18.2th percentile
containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
aquasecuritytrivy
buildah_projectbuildah
container-tools_rhel8buildah
container-tools_rhel8conmon
container-tools_rhel8podman
container-tools_rhel8skopeo
containerdcontainerd
containerdcontainerd
containerdcontainerd
containerdcontainerd
containerdcontainerd
github.comcontainerd_containerd>= 1.7.0 < 1.7.331.7.33
github.comcontainerd_containerd_v2>= 2.0.0 < 2.0.102.0.10
github.comcontainerd_containerd_v2>= 2.1.0 < 2.1.92.1.9
github.comcontainerd_containerd_v2>= 2.2.0 < 2.2.52.2.5
github.comcontainerd_containerd_v2>= 2.3.0 < 2.3.22.3.2
linuxfoundationcontainerd>= 1.7.0 < 1.7.331.7.33
linuxfoundationcontainerd>= 2.0.0 < 2.0.102.0.10
linuxfoundationcontainerd>= 2.1.0 < 2.1.92.1.9
linuxfoundationcontainerd>= 2.2.0 < 2.2.52.2.5
linuxfoundationcontainerd>= 2.3.0 < 2.3.22.3.2
open-telemetryopentelemetry-collector-contrib
podman_projectpodman
ubuntucontainerd
ubuntucontainerd-app

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu7.5HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.