Input validation error in containerd - CVE-2026-53488
Published: June 19, 2026
containerd
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the host.
The vulnerability exists due to improper input validation in the containerd CRI plugin when propagating image configuration labels to containers. A remote attacker can supply a crafted image with malicious labels to execute arbitrary commands on the host.
Exploitation requires a plugin that consumes container labels for some operations.