Containers Project has a narrowly scoped vulnerability footprint centered on its containers product, with observed disclosures reflecting memory-management issues such as double-free conditions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Containers Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25907CRITICAL An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed. | Jan 26, 2021 | 9.8 | 28 | NO | NO |
CVE-2026-35406HIGH Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to ent | Apr 7, 2026 | 7.5 | 27 | NO | NO |
CVE-2024-9341HIGH A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go l | Oct 1, 2024 | 8.2 | 26 | NO | NO |
CVE-2024-8418HIGH A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a | Sep 4, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Containers Project.
Media articles that mention a CVE ID that affects a product developed by Containers Project — matched by CVE ID, not by vendor name.