CVE & Vulnerabilities · September 27, 2026
A newly disclosed flaw in containerd, the widely used open-source container runtime, lets a maliciously crafted OCI image index drive CPU and memory usage through the roof during the image-pull step, before a container even starts. On affected clusters this can leave pods stuck in ContainerCreating for a long time and, with large enough images, destabilize the node or runtime entirely. The issue is fixed in containerd 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, so operators should upgrade to one of those releases.
// source: nvd.nist.gov ↗