Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Podman Project

First CVE: Sep 23, 2020Active for: 6 yearsTotal CVEs: 17
38.2
VTI Score
Medium

Podman Project maintains a container-management platform that has become prominent in containerized deployment and orchestration, particularly as an alternative to Docker in environments where daemonless operation is prioritized. The recurring vulnerability exposure centers on access-control and information-disclosure weaknesses—including authorization flaws, path traversal, and sensitive-information handling—that arise from the complexities of managing container isolation, privileged operations, and filesystem interactions. Defenders should monitor Podman releases for patches affecting container-escape and privilege-escalation vectors; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Podman Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2020
5 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-57231HIGH
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman
Jun 26, 20267.536NONO
CVE-2026-33414HIGH
Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/st
Apr 14, 20267.829NONO
CVE-2019-25067HIGH
A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privil
Jun 9, 20228.828NONO
CVE-2026-55686MEDIUM
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory
Jun 26, 20265.326NONO
CVE-2022-2738HIGH
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which
Sep 1, 20227.525NONO
CVE-2022-1227HIGH
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim
Apr 29, 20228.825NONO
CVE-2022-2989HIGH
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has
Sep 13, 20227.124NONO
CVE-2024-3056HIGH
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container,
Aug 2, 20247.721NONO
CVE-2023-0778MEDIUM
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume,
Mar 27, 20236.821NONO
CVE-2022-4122MEDIUM
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Dec 8, 20225.321NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
41%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (23.5%)
Network13 (76.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (47.1%)
High9 (52.9%)
Unknown0 (0.0%)
User Interaction
None14 (82.4%)
Unknown0 (0.0%)
Required3 (17.6%)
Privileges Required
Low10 (58.8%)
High0 (0.0%)
None7 (41.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Podman Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Podman Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Podman Project's Products

View all 3 CNAs →

Top CWEs