Libpod is a container runtime library with a narrow product footprint, where its vulnerability profile centers on access-control and path-handling weaknesses in the core libpod runtime itself. The recurring exposure reflects the security-sensitive nature of container isolation: vulnerabilities cluster around improper link resolution, execution-privilege escalation, path traversal, and inadequate file and directory access restrictions—all of which threaten the boundary between containerized workloads and the host system. Current severity, exploitation activity, and disclosure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libpod Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10856HIGH It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being grant | Jul 3, 2018 | 8.8 | 25 | NO | NO |
CVE-2019-10214MEDIUM The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enfor | Nov 25, 2019 | 5.9 | 22 | NO | NO |
CVE-2019-10152HIGH A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing cont | Jul 30, 2019 | 7.2 | 22 | NO | NO |
CVE-2019-18466MEDIUM An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glo | Oct 28, 2019 | 5.5 | 20 | NO | NO |
CVE-2020-1726MEDIUM A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs | Feb 11, 2020 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libpod Project.
Media articles that mention a CVE ID that affects a product developed by Libpod Project — matched by CVE ID, not by vendor name.