CVEs
Container runtime and Kubernetes CVEs, checked against what runs
Recent containerd, CRI-O and Kubernetes vulnerabilities: what each one does, the affected versions, commands to check your own nodes, and what configuration cannot show you.
- CVE-2026-39987 · marimo · criticalmarimo terminal WebSocket gives an unauthenticated shell
- CVE-2026-82329 · JFrog Artifactory · criticalJFrog Artifactory authentication bypass to admin
- CVE-2026-15801 · CRI-O · criticalCRI-O checkpoint restore writes files as root to a path the archive chooses
- CVE-2026-53493 · containerd · mediumcontainerd image pull denial of service from a crafted OCI index
- CVE-2026-92574 · CRI-O · criticalCRI-O checkpoint restore runs with the checkpoint's privileges
- CVE-2026-95837 · containerd · criticalcontainerd checkpoint restore ignores the pod's security context