github.com/containers/podman/v2
Podman: A tool for managing OCI containers and pods.
Activity
- Latest release
- 5y ago
- Total releases
- 14
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- 32.8k
Details
- First release
- Jul 07, 2020
| Version | Released | |
|---|---|---|
v2.2.1
patch
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.1
patch
Dependencies (59)
+ 51 more |
|
v2.2.0
minor
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.0
minor
Dependencies (59)
+ 51 more |
|
v2.2.0-rc2
pre
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.0-rc2
pre
Dependencies (59)
+ 51 more |
|
v2.2.0-rc1
pre
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.0-rc1
pre
Dependencies (59)
+ 51 more |
|
v2.1.1
patch
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (60)
+ 52 more |
|
v2.1.0
minor
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (60)
+ 52 more |
|
v2.1.0-rc2
pre
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.0-rc2
pre
Dependencies (59)
+ 51 more |
|
v2.1.0-rc1
pre
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.0-rc1
pre
Dependencies (59)
+ 51 more |
|
v2.0.6
patch
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.6
patch
Dependencies (60)
+ 52 more |
|
v2.0.6-rc1
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-1726
GHSA-vmhj-p9hw-vgrf
GO-2023-1544
May 24, 2022
Podman has Files or Directories Accessible to External Parties
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0. Fixed in
2.0.6
References
Updated Aug 20, 2024 · Source: OSV.dev |
v2.0.6-rc1
pre
Dependencies (60)
+ 52 more |
|
v2.0.5
patch
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-1726
GHSA-vmhj-p9hw-vgrf
GO-2023-1544
May 24, 2022
Podman has Files or Directories Accessible to External Parties
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0. Fixed in
2.0.6
References
Updated Aug 20, 2024 · Source: OSV.dev |
v2.0.5
patch
Dependencies (60)
+ 52 more |
|
v2.0.4
patch
14 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-14370
GHSA-c3wv-qmjj-45r6
GO-2024-2766
Apr 24, 2024
Information disclosure in podman
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables. Fixed in
2.0.5
References
Updated Jun 04, 2024 · Source: OSV.dev
CVE-2020-1726
GHSA-vmhj-p9hw-vgrf
GO-2023-1544
May 24, 2022
Podman has Files or Directories Accessible to External Parties
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0. Fixed in
2.0.6
References
Updated Aug 20, 2024 · Source: OSV.dev |
v2.0.4
patch
Dependencies (61)
+ 53 more |
|
v2.0.3
patch
14 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-14370
GHSA-c3wv-qmjj-45r6
GO-2024-2766
Apr 24, 2024
Information disclosure in podman
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables. Fixed in
2.0.5
References
Updated Jun 04, 2024 · Source: OSV.dev
CVE-2020-1726
GHSA-vmhj-p9hw-vgrf
GO-2023-1544
May 24, 2022
Podman has Files or Directories Accessible to External Parties
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0. Fixed in
2.0.6
References
Updated Aug 20, 2024 · Source: OSV.dev |
v2.0.3
patch
Dependencies (61)
+ 53 more |
|
v2.0.2
initial
14 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-14370
GHSA-c3wv-qmjj-45r6
GO-2024-2766
Apr 24, 2024
Information disclosure in podman
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables. Fixed in
2.0.5
References
Updated Jun 04, 2024 · Source: OSV.dev
CVE-2020-1726
GHSA-vmhj-p9hw-vgrf
GO-2023-1544
May 24, 2022
Podman has Files or Directories Accessible to External Parties
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0. Fixed in
2.0.6
References
Updated Aug 20, 2024 · Source: OSV.dev |
v2.0.2
initial
Dependencies (61)
+ 53 more |