VYPR

Firecracker

by AWS

Source repositories

CVEs (2)

  • CVE-2026-5747HigApr 8, 2026
    risk 0.42cvss 7.5epss 0.00

    An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via…

  • CVE-2026-1386MedJan 23, 2026
    risk 0.39cvss 6.0epss 0.00

    A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the…