Dependency scanning
Check whether github.com/opencontainers/runc is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-41579
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc
CVE-2021-43784
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
CVE-2021-30465
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
CVE-2026-41579
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
GHSA-g54h-m393-cpwq
Devices resource list treated as a blacklist by default in github.com/opencontainers/runc
CVE-2022-29162
Default inheritable capabilities for linux container should be empty
GO-2022-0396
devices resource list treated as a blacklist by default
CVE-2023-28642
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc
CVE-2023-27561
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc
CVE-2025-31133
runc container escape via "masked path" abuse due to mount race conditions
GHSA-c5pj-mqfh-rvc3
Withdrawn: Runc allows an arbitrary systemd property to be injected
CVE-2023-25809
rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc
CVE-2016-3697
Privilege escalation in github.com/opencontainers/runc
CVE-2019-16884
Incorrect Authorization in runc
CVE-2016-3697
Privilege Elevation in runc
CVE-2019-19921
opencontainers runc contains procfs race condition with a shared volume mount
CVE-2024-21626
runc vulnerable to container breakout through process.cwd trickery and leaked fds
CVE-2022-29162
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc
CVE-2016-9962
Information Exposure in RunC in github.com/opencontainers/runc
CVE-2016-9962
Information Exposure in RunC
CVE-2024-45310
runc can be confused to create empty files/directories on the host
CVE-2025-31133
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc
CVE-2019-19921
Race condition in github.com/opencontainers/runc
CVE-2025-52565
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc
CVE-2023-25809
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc
CVE-2023-27561
Opencontainers runc Incorrect Authorization vulnerability
CVE-2025-52881
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc
CVE-2025-52881
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
CVE-2023-28642
runc AppArmor bypass with symlinked /proc
CVE-2019-16884
Authorization bypass in github.com/opencontainers/runc
CVE-2024-21626
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc
CVE-2021-43784
Namespace restriction bypass in github.com/opencontainers/runc
CVE-2024-45310
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc
CVE-2021-30465
Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc
CVE-2025-52565
runc container escape with malicious config due to /dev/console mount and related races
CVE-2025-27612
WITHDRAWN: Libcontainer is affected by capabilities elevation in github.com/opencontainers/runc
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes