CVE-2026-53493
Containerd has image-pull DoS via crafted OCI index graph amplification
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
| CWE | CWE-400 CWE-770 CWE-834 |
| Vendor | containerd |
| Product | containerd |
| Published | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for containerd containerd
Be the first to know when new unknown vulnerabilities affecting containerd containerd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
containerd / containerd
>= 2.0.0, < 2.0.13 < 1.7.36 >= 2.1.0, < 2.2.9 >= 2.3.0, < 2.3.6 = 2.4.0