kata-containers

Direct Vulnerabilities

Known vulnerabilities in the kata-containers package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Validation of Unsafe Equivalence in Input

*
  • H
Arbitrary Code Injection

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Unchecked Input for Loop Condition

*
  • H
Arbitrary Argument Injection

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • H
Integer Overflow or Wraparound

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Improper Certificate Validation

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Input Validation

*
  • M
Misinterpretation of Input

*
  • M
Information Exposure

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • H
Improper Control of Dynamically-Identified Variables

*
  • H
Creation of Immutable Text Using String Concatenation

*
  • H
Unchecked Input for Loop Condition

*
  • M
Integer Overflow or Wraparound

*
  • H
CVE-2026-33811

*
  • M
Cross-site Scripting (XSS)

*
  • M
External Control of Assumed-Immutable Web Parameter

*
  • M
Improper Output Neutralization for Logs

*
  • H
Improper Validation of Unsafe Equivalence in Input

*
  • M
Off-by-one Error

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • H
Multiple Locks of a Critical Resource

*
  • M
HTTP Request Smuggling

*
  • L
Out-of-bounds Write

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • M
Cross-site Scripting (XSS)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
NULL Pointer Dereference

*
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Link Following

*
  • M
Improper Certificate Validation

*
  • L
Improper Validation of Syntactic Correctness of Input

*
  • H
Improper Certificate Validation

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • L
Improper Check or Handling of Exceptional Conditions

*
  • H
Uncaught Exception

*
  • M
Information Exposure

*
  • H
Improper Verification of Cryptographic Signature

*
  • H
Improper Certificate Validation

*
  • H
Improper Preservation of Permissions

*
  • M
CVE-2025-68121

*
  • M
Directory Traversal

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Reference to Active Allocated Resource

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Signed to Unsigned Conversion Error

*
  • M
Improper Certificate Validation

*
  • M
Resource Exhaustion

*
  • H
Incorrect Execution-Assigned Permissions

*
  • M
Creation of Immutable Text Using String Concatenation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Output Neutralization for Logs

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Expected Behavior Violation

*
  • M
Expected Behavior Violation

*
  • M
Directory Traversal

*
  • L
Improper Neutralization

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Encoding or Escaping of Output

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Buffer Over-read

*
  • L
Compiler Optimization Removal or Modification of Security-critical Code

*
  • M
CVE-2025-4673

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • M
Double Free

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Integer Overflow or Wraparound

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
Incorrect Authorization

*
  • L
Incorrect Authorization

*
  • M
Improper Input Validation

*
  • L
Use After Free

*
  • L
Improper Input Validation

*
  • M
Incorrect Default Permissions

*
  • L
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Race Condition

*
  • M
Improper Input Validation

*
  • M
Resource Exhaustion

*