TL;DR
A Podman vulnerability, CVE-2026-94603, rated CVSS 10.0, lets a container image switch off nearly all sandboxing when started with podman run. It even overrides restrictions the user asked for. Podman 6.1.3 and 5.8.8 fix the flaw by removing the feature behind it.
- CVE: CVE-2026-94603 R
- CVSS: 10.0 (Critical · CVSSv3)
- Summary: podman-container-tools/podman repository advisory GHSA-2cvf-wqm6-wr9g
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Tired of noisy Microsoft CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy This Podman Vulnerability Matters
Podman is a widely used container engine on Linux, with Mac and Windows support through a managed virtual machine. Teams often pull images from public registries and rely on flags like –cap-drop to limit them. This flaw means a hostile image can quietly undo those limits.
How the Attack Works
Podman 4.4.0 added a way to share container checkpoints through OCI registries and restore them with podman run. However, a checkpoint defines exactly how its container is created, including its capabilities.
Podman treats any image carrying a specific checkpoint annotation as a checkpoint. In that case, the advisory says, “it will silently ignore all user input regarding how the container should be created.” For example, a request to drop all capabilities is ignored, and the image’s own settings apply instead. Those settings could grant every capability. As the maintainers put it, “the image can now control how it is executed.”
Affected Versions and Exploitation Status
The feature dates back to Podman 4.4.0, so releases from that version onward are affected until patched. The advisory does not report exploitation in the wild, and no public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to Podman 6.1.3 or Podman 5.8.8. The maintainers reverted the feature, so podman run no longer supports checkpoint images. The 6.1.3 release notes list this as a breaking change.
If you cannot upgrade, scan pulled images for the io.podman.annotations.checkpoint.runtime.name annotation and reject any that carry it. Podman cannot do this check automatically. Given the maximum score, treat this Podman vulnerability as urgent on any host that runs untrusted images.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!