youki
crates.io2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting youkipage 1 of 1
- CVE-2025-62161CRITICALCVSS 10.0EG 10.0✓ Fixed in 0.5.72025-11-06
Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask…
- CVE-2025-62596CRITICALCVSS 10.0EG 10.0✓ Fixed in 0.5.72025-11-06
Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with path substitution during pathname resolution, can allow w…
Check whether youki is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for youki CVEs against the assets you own.
Start Free Scan →