CVE security advisories and vulnerability history for runc by opencontainers.
14
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
1
Public exploits
With known exploit
6.5
Avg CVSS
2019–2025
Last updated
Overview
opencontainers runc has 14 published CVE records since 2019, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 1 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting opencontainers runc, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of opencontainers runc's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical0
High5
Medium4
Low1
4 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of opencontainers runc's CVEs are currently listed in CISA's KEV catalog.
Public exploits
1
One of opencontainers runc's CVEs has a known public exploit available.
Affected versions and CVEs
Browse every opencontainers runc version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about opencontainers runc vulnerabilities.
How many CVEs does opencontainers runc have?
opencontainers runc has 14 published CVE records since 2019.
How many opencontainers runc CVEs are in CISA KEV?
None of opencontainers runc's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for opencontainers runc vulnerabilities?
Yes — 1 of opencontainers runc's CVEs have a known public exploit.
Which versions of opencontainers runc are affected?
103 distinct opencontainers runc versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in opencontainers runc CVEs?
opencontainers runc's CVEs most often map to these CWE weakness types: CWE-363 (Race Condition Enabling Link Following), CWE-281 (Improper Preservation of Permissions), CWE-276 (Incorrect Default Permissions), CWE-190 (Integer Overflow or Wraparound).
What is the average severity of opencontainers runc CVEs?
The average CVSS base score across opencontainers runc's scored CVEs is 6.5.