Containers maintains a focused portfolio centered on container networking and DNS infrastructure, with observed vulnerabilities clustering around resource-consumption and file-access handling in components such as Aardvark DNS. The recurring weakness classes—uncontrolled resource consumption, improper link resolution, and infinite-loop conditions—reflect the parsing and path-traversal challenges inherent to networked container systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Containers over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25907CRITICAL An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed. | Jan 26, 2021 | 9.8 | 28 | NO | NO |
CVE-2024-9341HIGH A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go l | Oct 1, 2024 | 8.2 | 26 | NO | NO |
CVE-2026-35406HIGH Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to ent | Apr 7, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-8418HIGH A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a | Sep 4, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Containers.
Media articles that mention a CVE ID that affects a product developed by Containers — matched by CVE ID, not by vendor name.