Security: podman-container-tools/podman
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
podman quadlet install --replace does not fully replace the old fileGHSA-fx76-2j3w-2mx6 published
Aug 13, 2026 by Luap99Moderate -
The `podman run` command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotationGHSA-2cvf-wqm6-wr9g published
Sep 29, 2026 by mheonCritical -
Malformed Image can trick podman run into leaking host environment variables into the containerGHSA-4hq8-gpf5-8p68 published
Jun 24, 2026 by Luap99High -
WORKDIR symlink traversal vulnerabilityGHSA-q6r4-3wmg-fwcq published
Jun 17, 2026 by Luap99Moderate -
PowerShell Command Injection in Podman HyperV MachineGHSA-hc8w-h2mf-hp59 published
Apr 14, 2026 by Luap99Low -
podman kube play symlink traversal vulnerabilityGHSA-wp3j-xq48-xpjw published
Sep 4, 2025 by Luap99High -
podman machine missing TLS verificationGHSA-65gg-3w2w-hr4h published
Jun 24, 2025 by Luap99High -
Supply Chain vulnerability in containers/podman machine-os GitHub Actions workflowGHSA-34xh-hvp7-r2j7 published
May 12, 2025 by Luap99Moderate -
CVE-2024-1753 container escape at build timeGHSA-874v-pj72-92f3 published
Mar 18, 2024 by TomSweeneyRedHatHigh -
Default inheritable capabilities for linux container should be emptyGHSA-qvf8-p83w-v58j published
Apr 1, 2022 by giuseppeLow