go

github.com/containers/podman/v5

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/containers/podman/v5 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
Go

CVE-2026-57231

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

MEDIUM 4.2
Go

CVE-2026-19730

podman quadlet install --replace does not fully replace the old file

HIGH 8.1
Go

CVE-2025-9566

podman kube play symlink traversal vulnerability

HIGH 7.8
Go

CVE-2026-33414

PowerShell Command Injection in Podman HyperV Machine

MEDIUM 4.8
Go

CVE-2024-3056

Podman vulnerable to memory-based denial of service

HIGH 7.4
Go

CVE-2025-4953

Podman Creates Temporary File with Insecure Permissions

HIGH 8.3
Go

CVE-2025-6032

Podman Improper Certificate Validation; machine missing TLS verification

MEDIUM 4.7
Go

CVE-2024-9407

Improper Input Validation in Buildah and Podman

HIGH 8.6
Go

CVE-2024-1753

Podman affected by CVE-2024-1753 container escape at build time

MEDIUM 5.3
Go

CVE-2026-55686

Podman: WORKDIR symlink traversal vulnerability

UNKNOWN
Go

CVE-2026-55686

Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman

UNKNOWN
Go

CVE-2026-33414

PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman

UNKNOWN
Go

CVE-2025-9566

podman kube play symlink traversal vulnerability in github.com/containers/podman

UNKNOWN
Go

CVE-2025-4953

Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman

UNKNOWN
Go

CVE-2024-3056

Podman vulnerable to memory-based denial of service in github.com/containers/podman

UNKNOWN
Go

CVE-2024-9407

Improper Input Validation in Buildah and Podman in github.com/containers/buildah

UNKNOWN
Go

CVE-2025-6032

Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes