Linuxfoundation Containerd — CVE-2026-50195 (Critical)
Summary
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknow
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.9) in Linuxfoundation Containerd. Patch or mitigate promptly. EPSS percentile: 27%.
Operator check
Review CVE-2026-50195 in your asset inventory. Apply patches per vendor guidance and verify Containerd is not exposed. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 27%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.