CVE-2026-53488
published 2026-07-01CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image…
PriorityP350high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.16%
5.8th percentile
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Affected
206 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| advanced-cluster-security | rhacs-operator-bundle | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-rhel9-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel9 | — | — |
| ansible-automation-platform-24 | aap-must-gather-rhel8 | — | — |
| ansible-automation-platform-25 | aap-must-gather-rhel8 | — | — |
| ansible-automation-platform-26 | aap-must-gather-rhel9 | — | — |
| ansible-automation-platform-27 | aap-must-gather-rhel9 | — | — |
| aquasecurity | trivy | — | — |
| assisted | agent-preinstall-image-builder-rhel9 | — | — |
| container-native-virtualization | cnv-must-gather-rhel8 | — | — |
| container-native-virtualization | cnv-must-gather-rhel9 | — | — |
| container-native-virtualization | multus-dynamic-networks-rhel9 | — | — |
| containerd | containerd | < 1.7.33 | 1.7.33 |
| containerd | containerd | — | — |
| containerd | containerd | — | — |
| containerd | containerd | — | — |
| containerd | containerd | — | — |
| devspaces | traefik-rhel9 | — | — |
| dvo | deployment-validation-rhel8-operator | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.4CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
containerd up to 2.3.1 CRI Plugin access control (Nessus ID 321802 / WID-SEC-2026-2009)
vuldb·2026-06-21
CVE-2026-53488 [CRITICAL] containerd up to 2.3.1 CRI Plugin access control (Nessus ID 321802 / WID-SEC-2026-2009)
A vulnerability has been found in containerd up to 1.7.32/2.0.9/2.1.8/2.2.4/2.3.1 and classified as critical. Affected by this issue is some unknown functionality of the component CRI Plugin. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-53488. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
ghsa·2026-06-19
CVE-2026-53488 [HIGH] CWE-74 containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
### Impact
A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations.
### Patches
This bug has been fixed in the following containerd versions:
* 2.3.2
* 2.2.5
* 2.1.9
* 2.0.10
* 1.7.33
Users should update to these versions to resolve the issue.
### Workarounds
Ensure that only trusted images are used.
### Credits
The containerd project would like to thank Anthropic Research, in collaboration with Claude, the GKE Security Team usi
Red Hat
github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
vendor_redhat·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CWE-78 github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversight could enable an attacker to execute arbitrary commands on the host system through a plugin that processes these unvalidated labels. The primary impact is host-root command execution, allowing unauthorized control over the underlying system.
Statement: A flaw was found in containerd where the CRI plugin propagates labels from an image configuration (LABEL instruction in a Dockerfile) to a container without validation. This may r
Ubuntu
containerd vulnerabilities
vendor_ubuntu·2026-06-25·CVSS 7.5
CVE-2026-53492 [HIGH] containerd vulnerabilities
Title: containerd vulnerabilities
Summary: Several security issues were fixed in containerd.
It was discovered that containerd incorrectly handled HTTP/2 SETTINGS
frames. A remote attacker could possibly use this issue to cause containerd
to enter an infinite loop, resulting in a denial of service. (CVE-2026-33814)
Jakub Ciolek and Kyle Elliott discovered that containerd incorrectly
handled group parsing when creating containers from images. An attacker
could possibly use this issue to cause containerd to consume excessive
memory, resulting in a denial of service. (CVE-2026-47262)
Henry Beberman and Robert Prast discovered that containerd incorrectly
validated image references when importing container checkpoints. An
attacker could possibly use this issue to poison the local image cach
Ubuntu
containerd vulnerabilities
vendor_ubuntu·2026-06-25·CVSS 7.5
CVE-2026-33814 [HIGH] containerd vulnerabilities
Title: containerd vulnerabilities
Summary: Several security issues were fixed in containerd.
It was discovered that containerd incorrectly handled HTTP/2 SETTINGS
frames. A remote attacker could possibly use this issue to cause containerd
to enter an infinite loop, resulting in a denial of service. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2026-33814)
Jakub Ciolek and Kyle Elliott discovered that containerd incorrectly
handled group parsing when creating containers from images. An attacker
could possibly use this issue to cause containerd to consume excessive
memory, resulting in a denial of service. (CVE-2026-47262)
Robert Prast discovered that containerd incorrectly propagated labels
from image configurations to container
Ubuntu
containerd vulnerabilities
vendor_ubuntu·2026-06-25·CVSS 7.5
CVE-2026-47262 [HIGH] containerd vulnerabilities
Title: containerd vulnerabilities
Summary: Several security issues were fixed in containerd.
It was discovered that containerd incorrectly handled HTTP/2 SETTINGS
frames. A remote attacker could possibly use this issue to cause containerd
to enter an infinite loop, resulting in a denial of service. (CVE-2026-33814)
Jakub Ciolek and Kyle Elliott discovered that containerd incorrectly
handled group parsing when creating containers from images. An attacker
could possibly use this issue to cause containerd to consume excessive
memory, resulting in a denial of service. (CVE-2026-47262)
Henry Beberman and Robert Prast discovered that containerd incorrectly
validated image references when importing container checkpoints. An
attacker could possibly use this issue to poison the local image cach
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53488 trivy: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 trivy: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
CVE-2026-53488 trivy: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
CVE-2026-53488 containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
CVE-2026-53488 github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 inspektor-gadget: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 inspektor-gadget: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
CVE-2026-53488 inspektor-gadget: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 k9s: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 k9s: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
CVE-2026-53488 k9s: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 trivy: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 trivy: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
CVE-2026-53488 trivy: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 pack: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 pack: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
CVE-2026-53488 pack: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Bugzilla
CVE-2026-53488 stargz-snapshotter: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
bugzilla·2026-07-01·CVSS 9.4
CVE-2026-53488 [CRITICAL] CVE-2026-53488 stargz-snapshotter: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
CVE-2026-53488 stargz-snapshotter: containerd: Host-root command execution via unvalidated image config labels in CRI plugin [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.1
2026-07-01
Published