VYPR
Vendor

Podman

Products
1
CVEs
15
Across products
15
Status
Private

Products

1

Recent CVEs

15
  • CVE-2026-94603impSep 29, 2026
    risk 0.56cvss 8.6epss —

    podman: podman: The `podman run` command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotation

  • CVE-2024-1753HigMar 18, 2024
    risk 0.56cvss 8.6epss 0.00

    A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause…

  • CVE-2024-3056HigAug 2, 2024
    risk 0.50cvss 7.7epss 0.01

    A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to…

  • CVE-2019-10152HigJul 30, 2019
    risk 0.47cvss 7.2epss 0.00

    A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator…

  • CVE-2026-57231HigJun 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that…

  • CVE-2021-4024MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is…

  • CVE-2022-2989HigSep 13, 2022
    risk 0.39cvss 7.1epss 0.00

    An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access…

  • CVE-2021-20188HigFeb 11, 2021
    risk 0.39cvss 7.0epss 0.00

    A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root…

  • CVE-2021-20199MedFeb 2, 2021
    risk 0.38cvss 5.9epss 0.01

    Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects…

  • CVE-2023-0778MedMar 27, 2023
    risk 0.37cvss 6.8epss 0.01

    A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

  • CVE-2025-11395MedSep 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

  • CVE-2026-55686MedJun 26, 2026
    risk 0.27cvss 5.3epss 0.00

    Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that…

  • CVE-2026-19730MedAug 13, 2026
    risk 0.20cvss 4.2epss 0.00

    The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in…

  • CVE-2024-9676MedOct 15, 2024
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned…

  • CVE-2022-1227HigApr 29, 2022
    risk 0.00cvss 8.8epss 0.04

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the…