github.com/containers/podman/v3
Podman: A tool for managing OCI containers and pods.
Activity
- Latest release
- 4y ago
- Total releases
- 20
- Cadence
- ~10 days
- Last 12 months
- 0
Reach
- Stars
- 32.8k
Details
- First release
- May 26, 2021
| Version | Released | |
|---|---|---|
v3.4.7
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.7
patch
Dependencies (66)
+ 58 more |
|
v3.4.6
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.6
patch
Dependencies (66)
+ 58 more |
|
v3.4.5
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.5
patch
Dependencies (66)
+ 58 more |
|
v3.4.4
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.4
patch
Dependencies (66)
+ 58 more |
|
v3.4.3
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.3
patch
Dependencies (66)
+ 58 more |
|
v3.4.2
patch
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.2
patch
Dependencies (66)
+ 58 more |
|
v3.4.1
patch
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.1
patch
Dependencies (66)
+ 58 more |
|
v3.4.0
minor
12 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev |
v3.4.0
minor
Dependencies (66)
+ 58 more |
|
v3.4.0-rc2
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.4.0-rc2
pre
Dependencies (66)
+ 58 more |
|
v3.4.0-rc1
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.4.0-rc1
pre
Dependencies (66)
+ 58 more |
|
v3.3.1
patch
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.1
patch
Dependencies (64)
+ 56 more |
|
v3.3.0
minor
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.0
minor
Dependencies (64)
+ 56 more |
|
v3.3.0-rc3
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.0-rc3
pre
Dependencies (64)
+ 56 more |
|
v3.3.0-rc2
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.0-rc2
pre
Dependencies (64)
+ 56 more |
|
v3.3.0-rc1
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.3.0-rc1
pre
Dependencies (64)
+ 56 more |
|
v3.2.3
patch
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.2.3
patch
Dependencies (64)
+ 56 more |
|
v3.2.2
patch
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.2.2
patch
Dependencies (64)
+ 56 more |
|
v3.2.1
patch
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.2.1
patch
Dependencies (64)
+ 56 more |
|
v3.2.0
initial
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.2.0
initial
Dependencies (64)
+ 56 more |
|
v3.2.0-rc3
pre
13 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4122
GO-2022-1151
GHSA-4crw-w8pw-2hmf
Aug 21, 2024
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-27649
GO-2022-0416
GHSA-qvf8-p83w-v58j
Aug 21, 2024
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-4024
GO-2022-0281
GHSA-3cf2-x423-x582
Aug 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman Fixed in
3.4.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-1227
GHSA-66vw-v2x9-hw75
GO-2022-0558
Apr 30, 2022
Podman publishes a malicious image to public registries
High
Network
Low
None
Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. Fixed in
3.4
References
Updated Sep 10, 2026 · Source: OSV.dev |
v3.2.0-rc3
pre
Dependencies (64)
+ 56 more |