Skip to content
COOEY

FAIL › dossier

containerd

PRODUCT

· dossier confidence 20%

containerd is an open-source container runtime with a critical security track record of unpatched vulnerabilities in the CRI checkpoint import and CDI annotation handling processes, requiring urgent patching to versions 2.3.2, 2.2.5, or 2.1.9.

PROFILE
Categorycontainer runtimeWhat they docontainerd is an open-source container runtime used to manage container lifecycles and orchestration. Websitehttps://containerd.io/ ↗
SECURITY POSTURE

The project has a critical track record of unpatched vulnerabilities in the CRI checkpoint import and CDI annotation handling processes, requiring urgent patching to versions 2.3.2, 2.2.5, or 2.1.9.

Notable failures
  • CVE-2026-50195 critical RCE0day in CRI checkpoint import
  • CVE-2026-53492 critical CDI annotation trust bypass
Patterns: repeated unpatched edge-device RCEs; improper trust of external annotations in CRI implementation
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-07-01 CVE-2026-50195 critical containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions
2026-07-01 CVE-2026-53492 critical containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a conta
Open questions: What is the exact patch version for CVE-2026-50195? · What is the exact patch version for CVE-2026-53492?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-20 19:16:38.905191+00:00