Search CVE reports


Toggle filters

1 – 10 of 28 results


CVE-2026-27141

Medium priority
Needs evaluation

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2025-58190

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Not affected Not affected Not affected Not affected
containerd Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Not affected Not affected Not affected
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2025-47911

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Not affected Not affected Not affected Not affected
containerd Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Not affected Not affected Not affected
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2025-64329

Medium priority

Some fixes available 10 of 12

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed
Show less packages

CVE-2024-25621

Medium priority

Some fixes available 10 of 12

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability....

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed
Show less packages

CVE-2025-47291

Medium priority

Some fixes available 1 of 4

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected
containerd-app Not affected Not affected Not affected
Show less packages

CVE-2025-47290

Medium priority
Not affected

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected
containerd-app Not affected Not affected Not affected
Show less packages

CVE-2025-22872

Medium priority
Needs evaluation

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing,...

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation Not in release Not in release
google-guest-agent Not affected Not affected Not affected Not affected
containerd Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Not affected Not affected Not affected
juju-core
lxd Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2024-40635

Medium priority

Some fixes available 11 of 13

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed
Show less packages

CVE-2024-45338

Medium priority

Some fixes available 12 of 15

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

7 affected packages

lxd, adsys, golang-golang-x-net, golang-golang-x-net-dev, juju-core...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not affected Not affected
adsys Fixed Fixed Fixed
golang-golang-x-net Fixed Fixed Not in release
golang-golang-x-net-dev Not in release Not in release Fixed Fixed
juju-core Not in release Not in release Not in release
containerd Not affected Not affected Not affected Not affected
google-guest-agent Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages