github.com/containers/podman/v4
Podman: A tool for managing OCI containers and pods.
Activity
- Latest release
- 2y ago
- Total releases
- 20
- Cadence
- ~11 days
- Last 12 months
- 0
Reach
- Stars
- 32.8k
Details
- First release
- Jul 03, 2023
| Version | Released | |
|---|---|---|
v4.9.5
patch
10 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.9.5
patch
Dependencies (75)
+ 67 more |
|
v4.9.4
patch
10 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.9.4
patch
Dependencies (75)
+ 67 more |
|
v4.9.3
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.9.3
patch
Dependencies (75)
+ 67 more |
|
v4.9.2
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.9.2
patch
Dependencies (75)
+ 67 more |
|
v4.9.1
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.9.1
patch
Dependencies (75)
+ 67 more |
|
v4.9.0
minor
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.9.0
minor
Dependencies (75)
+ 67 more |
|
v4.8.3
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.8.3
patch
Dependencies (75)
+ 67 more |
|
v4.8.2
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.8.2
patch
Dependencies (75)
+ 67 more |
|
v4.8.1
patch
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.8.1
patch
Dependencies (75)
+ 67 more |
|
v4.8.0
minor
11 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33414
GO-2026-5421
GHSA-hc8w-h2mf-hp59
Jun 25, 2026
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6032
GO-2025-3777
GHSA-65gg-3w2w-hr4h
Jul 28, 2025
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.8.0
minor
Dependencies (75)
+ 67 more |
|
v4.8.0-rc1
pre
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.8.0-rc1
pre
Dependencies (75)
+ 67 more |
|
v4.7.2
patch
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.7.2
patch
Dependencies (70)
+ 62 more |
|
v4.7.1
patch
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.7.1
patch
Dependencies (70)
+ 62 more |
|
v4.7.0
minor
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.7.0
minor
Dependencies (70)
+ 62 more |
|
v4.7.0-rc1
pre
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.7.0-rc1
pre
Dependencies (70)
+ 62 more |
|
v4.6.2
patch
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.6.2
patch
Dependencies (69)
+ 61 more |
|
v4.6.1
patch
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.6.1
patch
Dependencies (69)
+ 61 more |
|
v4.6.0
initial
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.6.0
initial
Dependencies (69)
+ 61 more |
|
v4.6.0-rc2
pre
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.6.0-rc2
pre
Dependencies (68)
+ 60 more |
|
v4.6.0-rc1
pre
9 CVEs
CVE-2026-55686
GO-2026-5568
GHSA-q6r4-3wmg-fwcq
Jun 25, 2026
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-4953
GO-2025-3961
GHSA-m68q-4hqr-mc6f
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-9566
GO-2025-3935
GHSA-wp3j-xq48-xpjw
Sep 08, 2025
podman kube play symlink traversal vulnerability in github.com/containers/podman podman kube play symlink traversal vulnerability in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9407
GO-2024-3169
GHSA-fhqq-8f65-5xfc
Oct 09, 2024
Improper Input Validation in Buildah and Podman in github.com/containers/buildah Improper Input Validation in Buildah and Podman in github.com/containers/buildah References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2018-10856
GO-2023-1962
GHSA-wp7w-vx86-vj9h
Aug 20, 2024
Podman Elevated Container Privileges in github.com/containers/podman Podman Elevated Container Privileges in github.com/containers/podman References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-18466
GO-2023-1942
GHSA-r34v-gqmw-qvgj
Aug 20, 2024
Podman Symlink Vulnerability in github.com/containers/libpod Podman Symlink Vulnerability in github.com/containers/libpod References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3056
GO-2024-3042
GHSA-rpcc-p8xm-rc6p
Aug 06, 2024
Podman vulnerable to memory-based denial of service in github.com/containers/podman Podman vulnerable to memory-based denial of service in github.com/containers/podman References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-1753
GHSA-874v-pj72-92f3
GHSA-pmf3-c36m-g5cf
GO-2024-2658
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Medium
Local
Low
None
ImpactWhat kind of vulnerability is it? Who is impacted? Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed. PatchesFrom @nalind . This is a patch for Buildah (https://github.com/containers/buildah). Once fixed there, Buildah will be vendored into Podman.
ReproducerPrior to testing, as root, add a memorable username to Use the following Containerfile
To TestTesting with an older version of Podman with the issue
As part of the printout from the build, you should be able to see the contents of the
Neither the However, the files in both the Testing with the patchUse the same commands as testing with an older version of Podman. When running using the patched version of Podman, regardless of the NOTE: With the fix, the contents of the WorkaroundsEnsure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, which is not at all advised, the root file system is open for modification with this exploit. With "setenfoce 1" set, which is the recommendation, files can not be changed. However, the contents of the ReferencesUnknown. Fixed in
4.9.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-4123
GO-2022-1159
GHSA-rprg-4v7q-87v7
Dec 22, 2022
Path traversal in github.com/containers/podman/v4 The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. References Updated May 20, 2024 · Source: OSV.dev |
v4.6.0-rc1
pre
Dependencies (68)
+ 60 more |