netavark
Container network stack
Activity
- Latest release
- 1mo ago
- Total releases
- 30
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Downloads
- 42.8k
- Stars
- 778
Details
- License
- Apache-2.0
- First release
- Jul 04, 2022
| Version | Released | |
|---|---|---|
2.1.0
minor
|
2.1.0
minor
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
2.0.0
unknown
|
2.0.0
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.17.2
unknown
|
1.17.2
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
1.17.1
unknown
|
1.17.1
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
1.17.0
unknown
1 CVE
CVE-2026-35406
GHSA-hfpq-x728-986j
Apr 07, 2026
netavark has incorrect error handling for malformed tcp packets
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactA truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. Patcheshttps://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1 WorkaroundsNone CreditsThanks to @dkane01 for reporting this Fixed in
1.17.1
References
Updated Apr 24, 2026 · Source: OSV.dev |
1.17.0
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
1.16.1
unknown
1 CVE
CVE-2026-35406
GHSA-hfpq-x728-986j
Apr 07, 2026
netavark has incorrect error handling for malformed tcp packets
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactA truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. Patcheshttps://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1 WorkaroundsNone CreditsThanks to @dkane01 for reporting this Fixed in
1.17.1
References
Updated Apr 24, 2026 · Source: OSV.dev |
1.16.1
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
1.16.0
unknown
1 CVE
CVE-2026-35406
GHSA-hfpq-x728-986j
Apr 07, 2026
netavark has incorrect error handling for malformed tcp packets
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactA truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. Patcheshttps://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1 WorkaroundsNone CreditsThanks to @dkane01 for reporting this Fixed in
1.17.1
References
Updated Apr 24, 2026 · Source: OSV.dev |
1.16.0
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
1.15.2
unknown
|
1.15.2
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
1.15.1
unknown
|
1.15.1
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
1.15.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.15.0
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
1.14.1
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.14.1
unknown
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.14.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.14.0
unknown
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.13.1
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.13.1
unknown
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.13.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.13.0
unknown
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.12.2
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.12.2
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.12.1
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.12.1
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.11.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.11.0
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.10.3
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.10.3
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.10.2
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.10.2
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.10.1
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.10.1
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.9.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.9.0
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
1.8.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.8.0
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
1.7.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.7.0
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
1.6.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.6.0
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
1.4.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev | ||
1.3.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.3.0
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
1.2.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.2.0
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
1.1.0
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.1.0
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
1.0.3
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
1.0.3
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
1.0.4-dev
unknown
1 CVE
CVE-2025-8283
GHSA-rpcf-rmh6-42xr
Jul 28, 2025
Netavark Has Possible DNS Resolve Confusion
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. Fixed in
1.15.1
References
Updated Jun 04, 2026 · Source: OSV.dev |