Guest Components Vulnerability in Confidential Containers by Confidential Containers
CVE-2026-47699

6.4MEDIUM

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-47699?

A vulnerability in Confidential Containers Guest Components allows crafted OCI image layers to exploit the image_rs::stream::unpack::unpack() function, enabling hardlinks to be created outside of the intended directory. This can lead to exposure of pod virtual machine capabilities under certain conditions, creating a potential pathway for untrusted content to be manipulated in ways that may compromise the integrity of the environment. The issue has been addressed in version 0.20.0, emphasizing the importance of updating to the latest version to mitigate risks.

Affected Version(s)

guest-components >= 0.16.0, < 0.20.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.