CVE-2026-53493: Containerd
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
Affected products
- Containerd Containerd: from 2.0.0, before 2.0.13 (fixed in 2.0.13); before 1.7.36 (fixed in 1.7.36); from 2.1.0, before 2.2.9 (fixed in 2.2.9); from 2.3.0, before 2.3.6 (fixed in 2.3.6); version 2.4.0 only
Published 2026-09-25. Last modified 2026-09-28.