github.com/containers/podman/v5
Go10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/containers/podman/v5page 1 of 1
- CVE-2024-1753HIGHCVSS 8.6EG 8.6fixed in 5.0.12024-03-18
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root…
- CVE-2024-3056HIGHCVSS 7.7EG 7.72024-08-02
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The…
- CVE-2024-9407MEDIUMCVSS 4.7EG 4.7fixed in 5.2.42024-10-01
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. T…
- CVE-2025-4953HIGHCVSS 7.4EG 7.42025-09-16
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build con…
- CVE-2025-6032HIGHCVSS 8.3EG 8.3fixed in 5.5.22025-06-24
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
- CVE-2025-9566HIGHCVSS 8.1EG 8.1fixed in 5.6.12025-09-05
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a…
- CVE-2026-19730MEDIUMCVSS 4.2EG 4.2fixed in 5.8.62026-08-13
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default…
- CVE-2026-33414HIGHCVSS 7.8EG 7.8fixed in 5.8.22026-04-14
Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerS…
- CVE-2026-55686MEDIUMCVSS 5.3EG 5.3fixed in 5.7.12026-06-18
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified owners…
- CVE-2026-57231HIGHCVSS 7.5EG 7.5fixed in 5.8.42026-06-26
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container…
Check whether github.com/containers/podman/v5 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/containers/podman/v5 CVEs against the assets you own.
Book a Demo →