GHSA-pg57-6jwg-q645

Suggest an improvement
Source
https://github.com/advisories/GHSA-pg57-6jwg-q645
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pg57-6jwg-q645/GHSA-pg57-6jwg-q645.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-pg57-6jwg-q645
Aliases
Downstream
CGA (241)
MINI (113)
Published
2026-09-25T19:27:59Z
Modified
2026-09-25T19:45:10Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Containerd has image-pull DoS via crafted OCI index graph amplification
Details

Impact

A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the PullImage operation, the recursive traversal and processing of child descriptors lack sufficient depth and breadth limits, and fail to adequately deduplicate identical descriptors. This unbounded traversal leads to excessive resource allocation.

Consequently, pulling a malicious image reference can result in prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution.

Patches

This bug has been fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.13, and 1.7.36. Users should update to these versions to resolve the issue.

Workarounds

There are no known workarounds for this issue. Users are advised to only pull trusted images from known registries until the patch can be applied.

Credits

The containerd project would like to thank Jakub Ciolek at ElevenLabs and @jlgore who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.

For more information

If you have any questions or comments about this advisory:

To report a security issue in containerd:

Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-770",
        "CWE-834"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-25T19:27:59Z",
    "nvd_published_at": "2026-09-25T01:16:48Z",
    "severity": "MODERATE"
}
References

Affected packages

Go
github.com/containerd/containerd/v2

Package

Name
github.com/containerd/containerd/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/containerd/containerd/v2

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.0.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pg57-6jwg-q645/GHSA-pg57-6jwg-q645.json"
github.com/containerd/containerd

Package

Name
github.com/containerd/containerd
View open source insights on deps.dev
Purl
pkg:golang/github.com/containerd/containerd

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.36

Database specific

last_known_affected_version_range
"<= 1.7.35"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pg57-6jwg-q645/GHSA-pg57-6jwg-q645.json"
github.com/containerd/containerd/v2

Package

Name
github.com/containerd/containerd/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/containerd/containerd/v2

Affected ranges

Type
SEMVER
Events
Introduced
2.1.0
Fixed
2.2.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pg57-6jwg-q645/GHSA-pg57-6jwg-q645.json"
github.com/containerd/containerd/v2

Package

Name
github.com/containerd/containerd/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/containerd/containerd/v2

Affected ranges

Type
SEMVER
Events
Introduced
2.3.0
Fixed
2.3.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pg57-6jwg-q645/GHSA-pg57-6jwg-q645.json"
github.com/containerd/containerd/v2

Package

Name
github.com/containerd/containerd/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/containerd/containerd/v2

Affected ranges

Type
SEMVER
Events
Introduced
2.4.0
Fixed
2.4.1

Affected versions

2.*
2.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pg57-6jwg-q645/GHSA-pg57-6jwg-q645.json"