CVE-2026-53493: Uncontrolled Resource Consumption in containerd Image-Pull Descriptor Graph Resolution
Vulnerability ID: CVE-2026-53493
CVSS Score: 6.9
Published: 2026-09-25
containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. The vulnerability occurs because containerd's image-pull descriptor graph resolution handlers processed OCI image indices and manifests recursively without enforcing boundaries on traversal depth or breadth, and without maintaining a global visited registry to count duplicate references.
TL;DR
A crafted OCI index graph can force high CPU and memory usage during image pulls in containerd, leading to Denial of Service (DoS) and node instability.
⚠️ Exploit Status: POC
Technical Details
- Vulnerability ID: CVE-2026-53493
- CWE ID: CWE-400
- Attack Vector: Network
- Privileges Required: None
- CVSS Score: 6.9
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- containerd
-
containerd: < 1.7.36 (Fixed in:
1.7.36) -
containerd: >= 2.0.0, < 2.0.13 (Fixed in:
2.0.13) -
containerd: >= 2.2.0, < 2.2.9 (Fixed in:
2.2.9) -
containerd: >= 2.3.0, < 2.3.6 (Fixed in:
2.3.6) -
containerd: >= 2.4.0, < 2.4.1 (Fixed in:
2.4.1)
Mitigation Strategies
- Upgrade containerd to a patched release (1.7.36, 2.0.13, 2.2.9, 2.3.6, or 2.4.1).
- Configure private registries and restrict pulls to trusted image sources.
- Implement admission control mechanisms to block untrusted images.
Remediation Steps:
- Identify affected nodes running vulnerable versions of containerd.
- Apply the update package via the operating system package manager or cluster management manifests.
- Restart the containerd service to load the patched runtime.
- Verify the installation version by running 'containerd --version'.
References
Read the full report for CVE-2026-53493 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)