Skip to main content
Vulnerability Database/CVE-2026-53493

CVE-2026-53493: containerd DOS Vulnerability

CVE-2026-53493 is a denial of service vulnerability in containerd that allows crafted OCI index graphs to cause extreme CPU and memory usage during image pulls. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2026-53493 Overview

CVE-2026-53493 is a resource exhaustion vulnerability [CWE-400] in containerd, an open-source container runtime used by Kubernetes and other container orchestration platforms. A crafted Open Container Initiative (OCI) index graph can force high CPU and memory consumption during the PullImage operation, before any container starts. The condition causes prolonged ContainerCreating stalls and, at larger input sizes, degrades node or runtime stability. The issue is fixed in containerd versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1.

Critical Impact

A remote adversary who can influence image pulls can trigger denial-of-service conditions on container hosts, impacting workload scheduling and node availability.

Affected Products

  • containerd versions prior to 1.7.36
  • containerd 2.x versions prior to 2.0.13, 2.2.9, 2.3.6, and 2.4.1
  • Downstream platforms embedding affected containerd releases (Kubernetes nodes, Docker, managed container services)

Discovery Timeline

  • 2026-09-25 - CVE-2026-53493 published to the National Vulnerability Database (NVD)
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-53493

Vulnerability Analysis

The vulnerability resides in the image pull pipeline of containerd. When processing an OCI image, containerd parses the image index, a JSON manifest that can reference additional manifests, forming a directed graph of descriptors. A specially constructed index graph forces the runtime to perform disproportionate work during resolution and traversal before the container is created.

The amplification occurs entirely within the PullImage phase. As a result, operators observe prolonged ContainerCreating states in Kubernetes while the runtime consumes CPU cycles and allocates memory parsing the malicious graph. At sufficient scale, the workload starves other processes on the same node.

Root Cause

The root cause is uncontrolled resource consumption during OCI index graph processing. The runtime lacks sufficient bounds on the size, depth, or fan-out of referenced descriptors in an image index. See the containerd GitHub Security Advisory GHSA-pg57-6jwg-q645 for details on the fixed parsing logic.

Attack Vector

An attacker publishes or supplies a malicious container image to a registry pulled by a target environment. When a node attempts to pull the image, containerd parses the crafted index and exhausts local resources. The attack requires no authentication to the runtime itself and no user interaction on the target node. Any workflow that pulls untrusted images, including CI/CD runners, multi-tenant clusters, and public registry mirrors, is exposed.

No verified public exploitation code is available at the time of publication.

Detection Methods for CVE-2026-53493

Indicators of Compromise

  • Pods stuck in ContainerCreating state for extended durations without obvious scheduling or networking causes
  • Sustained high CPU utilization attributed to the containerd process coincident with image pull activity
  • Memory pressure or Out-Of-Memory (OOM) events on nodes shortly after PullImage requests for new or unusual images

Detection Strategies

  • Correlate kubelet events for Failed to pull image or long Pulling image durations with containerd process resource metrics
  • Alert on anomalous image pull latency against baselines per node and per registry
  • Review audit logs for image references originating from untrusted or newly introduced registries

Monitoring Recommendations

  • Instrument node-level telemetry for containerd CPU and resident memory with per-process granularity
  • Track pull-time duration metrics exposed by containerd and the Container Runtime Interface (CRI)
  • Forward kubelet and runtime logs to a centralized data lake for cross-node correlation of pull-time anomalies

How to Mitigate CVE-2026-53493

Immediate Actions Required

  • Upgrade containerd to 1.7.36, 2.0.13, 2.2.9, 2.3.6, or 2.4.1 or later as appropriate for your release branch
  • Restrict image pulls to trusted registries using admission controllers or runtime policy
  • Enable image signature verification to block unsigned or untrusted OCI artifacts

Patch Information

The containerd maintainers released fixed versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 that bound the work performed during OCI index graph processing. Patch details and backport guidance are published in the containerd GitHub Security Advisory.

Workarounds

  • Enforce registry allow-lists at the cluster level to prevent pulls from arbitrary sources
  • Apply resource limits and QoS policies on nodes so a stalled PullImage cannot starve critical system services
  • Use image pre-pull workflows in controlled pipelines rather than ad-hoc pulls from workload specifications
bash
# Verify installed containerd version
containerd --version

# Example: pin containerd image in Kubernetes node management
# Replace with the fixed patch version appropriate to your branch
apt-get install --only-upgrade containerd.io=1.7.36-1

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.