Resource Exhaustion Vulnerability in containerd by Docker
CVE-2026-53493

6.9MEDIUM

Key Information:

Vendor

Containerd

Vendor
CVE Published:
25 September 2026

What is CVE-2026-53493?

A resource exhaustion vulnerability exists in containerd, an open-source container runtime, that can be exploited through a specially crafted OCI index graph. This flaw results in excessive CPU and memory consumption during the PullImage operation, leading to prolonged container creation delays and potential instability of the node or runtime at larger image sizes. Users are encouraged to upgrade to the patched versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

containerd >= 2.0.0, < 2.0.13 < 2.0.0, 2.0.13

containerd < 1.7.36 < 1.7.36

containerd >= 2.1.0, < 2.2.9 < 2.1.0, 2.2.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.