$ cat ./advisories
Advisories
Public GHSA and CVE records, plus the companion writeups when they are available in the current build.
-
containerd
4 ghsa- Checkpoint image config LABEL host RCE
Image config labels flow into container metadata and can trigger host root command execution through a label consuming containerd plugin.
- Checkpoint import tag poisoning
Checkpoint import can assign an attacker controlled digest to a local image tag, poisoning the node cache for later pods using that tag.
- Arbitrary host file read via symlink following
Checkpoint restore copies container.log without rejecting symlinks, allowing host file reads to surface through kubectl logs.
- CDI annotation smuggling
Untrusted checkpoint metadata can smuggle CDI annotations and bypass Kubernetes device allocation on nodes with matching CDI specs.
- Checkpoint image config LABEL host RCE
-
cilium
1 ghsa -
docker/mcp-gateway
1 ghsa -
cert-manager
1 ghsa