CVE-2026-53488

Source
https://cve.org/CVERecord?id=CVE-2026-53488
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53488.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53488
Aliases
Downstream
AZL (3)
BELL (1)
CGA (603)
CLEANSTART (17)
DEBIAN (1)
MINI (214)
OESA (5)
openSUSE (5)
RHSA (1)
ROOT (1)
UBUNTU (1)
Related
Published
2026-07-01T00:11:20Z
Modified
2026-08-12T03:51:31Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
Details

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-20"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53488.json"
}
References

Affected packages

Git / github.com/containerd/containerd

Affected ranges

Type
GIT
Repo
https://github.com/containerd/containerd
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "1.7.0"
        },
        {
            "fixed":  "1.7.33"
        },
        {
            "introduced":  "2.0.0"
        },
        {
            "fixed":  "2.0.10"
        },
        {
            "introduced":  "2.1.0"
        },
        {
            "fixed":  "2.1.9"
        },
        {
            "introduced":  "2.2.0"
        },
        {
            "fixed":  "2.2.5"
        },
        {
            "introduced":  "2.3.0"
        },
        {
            "fixed":  "2.3.2"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

api/v1.*
api/v1.11.1
api/v1.7.19
v1.*
v1.7.0
v1.7.1
v1.7.10
v1.7.11
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.17
v1.7.18
v1.7.19
v1.7.2
v1.7.20
v1.7.21
v1.7.22
v1.7.23
v1.7.24
v1.7.25
v1.7.26
v1.7.27
v1.7.28
v1.7.29
v1.7.3
v1.7.30
v1.7.31
v1.7.32
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53488.json"