go

github.com/opencontainers/runc

View on go registry
36 Total advisories
36 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/opencontainers/runc is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-41579

Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc

MEDIUM 6.0
Go

CVE-2021-43784

Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC

HIGH 7.6
Go

CVE-2021-30465

mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs

LOW 3.3
Go

CVE-2026-41579

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

UNKNOWN
Go

GHSA-g54h-m393-cpwq

Devices resource list treated as a blacklist by default in github.com/opencontainers/runc

MEDIUM 5.9
Go

CVE-2022-29162

Default inheritable capabilities for linux container should be empty

UNKNOWN
Go

GO-2022-0396

devices resource list treated as a blacklist by default

UNKNOWN
Go

CVE-2023-28642

AppArmor bypass with symlinked /proc in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2023-27561

Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-31133

runc container escape via "masked path" abuse due to mount race conditions

HIGH 7.2
Go

GHSA-c5pj-mqfh-rvc3

Withdrawn: Runc allows an arbitrary systemd property to be injected

LOW 2.5
Go

CVE-2023-25809

rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc

UNKNOWN
Go

CVE-2016-3697

Privilege escalation in github.com/opencontainers/runc

HIGH 7.5
Go

CVE-2019-16884

Incorrect Authorization in runc

HIGH 7.8
Go

CVE-2016-3697

Privilege Elevation in runc

MEDIUM 5.9
Go

CVE-2019-19921

opencontainers runc contains procfs race condition with a shared volume mount

HIGH 8.6
Go

CVE-2024-21626

runc vulnerable to container breakout through process.cwd trickery and leaked fds

UNKNOWN
Go

CVE-2022-29162

Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2016-9962

Information Exposure in RunC in github.com/opencontainers/runc

MEDIUM 6.4
Go

CVE-2016-9962

Information Exposure in RunC

LOW 3.6
Go

CVE-2024-45310

runc can be confused to create empty files/directories on the host

UNKNOWN
Go

CVE-2025-31133

Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2019-19921

Race condition in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-52565

Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2023-25809

Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc

HIGH 7.0
Go

CVE-2023-27561

Opencontainers runc Incorrect Authorization vulnerability

UNKNOWN
Go

CVE-2025-52881

Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-52881

runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects

MEDIUM 6.1
Go

CVE-2023-28642

runc AppArmor bypass with symlinked /proc

UNKNOWN
Go

CVE-2019-16884

Authorization bypass in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2024-21626

Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2021-43784

Namespace restriction bypass in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2024-45310

Can be confused to create empty files/directories on the host in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2021-30465

Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-52565

runc container escape with malicious config due to /dev/console mount and related races

UNKNOWN
Go

CVE-2025-27612

WITHDRAWN: Libcontainer is affected by capabilities elevation in github.com/opencontainers/runc

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes