Containers Bubblewrap vulnerabilities
2 known vulnerabilities affecting containers/bubblewrap.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-5291P3HIGHCVSS 7.8fixed in 0.4.12020-03-31
CVE-2020-5291 [HIGH] CWE-648 CVE-2020-5291: Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivi
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in set
nvdosv
CVE-2026-41163P3HIGHCVSS 7.0v>= 0.11.0, < 0.11.22026-05-09
CVE-2026-41163 [HIGH] CWE-269 CVE-2026-41163: bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2
bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "
nvd