CVE-2026-53488: Linuxfoundation Containerd
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Affected products
- Linuxfoundation Containerd: from 1.7.0, before 1.7.33 (fixed in 1.7.33); from 2.0.0, before 2.0.10 (fixed in 2.0.10); from 2.1.0, before 2.1.9 (fixed in 2.1.9); from 2.2.0, before 2.2.5 (fixed in 2.2.5); from 2.3.0, before 2.3.2 (fixed in 2.3.2)
Published 2026-07-01. Last modified 2026-07-03.