$ cat ./advisories
Advisories
Public GHSA and CVE records, plus the companion writeups when they are available in the current build.
-
containerd
4 ghsa- Checkpoint image-config LABEL host RCE
Image config labels flow into container metadata and can trigger host-root command execution through a label-consuming containerd plugin.
- Checkpoint import tag poisoning
Checkpoint import can assign an attacker-controlled digest to a local image tag, poisoning the node cache for later pods using that tag.
- Arbitrary host file read via symlink following
Checkpoint restore copies container.log without rejecting symlinks, allowing host-file reads to surface through kubectl logs.
- CDI annotation smuggling
Untrusted checkpoint metadata can smuggle CDI annotations and bypass Kubernetes device allocation on nodes with matching CDI specs.
- Checkpoint image-config LABEL host RCE
-
cilium
1 ghsa -
docker/mcp-gateway
1 ghsa -
cert-manager
1 ghsa