15 entries matching containerd — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-56852 | Infinite loop on invalid input in golang.org/x/text | HIGH | 7.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-10722 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow | LOW | 3.3 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-39824 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | MEDIUM | 6.5 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-27136 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-35469 | SpdyStream: DOS on CRI | HIGH | 8.1 | 48%ile | Microsoft | 2026-04-14 |
| CVE-2026-29181 | OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | HIGH | 7.5 | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-39882 | OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies | MEDIUM | 5.3 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2025-47291 | containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods. | HIGH | 7.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2023-45288 | HTTP/2 CONTINUATION flood in net/http | HIGH | 7.5 | 100%ile | Microsoft | 2024-04-09 |