CVE-2026-46680
HighAdvisory
Published 21 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.002
- 6th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 83
- of 17,781 indexed, latest versions
- Container images
- 85
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
containerd user ID handling bypass allows runAsNonRoot evasion
Carried by container images the latest versions of 83 of 17,781 indexed charts deploy, on 85 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v1.7.27, v1.7.28, v1.7.29, v1.7.30+1 more | 1.7.32 | 69 |
| github.com/ | v2.0.4, v2.1.1, v2.1.3, v2.1.4+6 more | 2.0.9, 2.2.4, 2.3.1 | 19 |
| containerddeb | 1.6.20~ds1-1+deb12u3 | no fix listed | 1 |
- OSV records
- DEBIAN-CVE-2026-46680GHSA-fqw6-gf59-qr4w
- Also known as
- GO-2026-5378
Charts affected
83 by stars
Container images carrying it
85 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 60566529446a | github.com/ | 1.7.32 | 3 |
| quay.io/ | 721b5c9634d4 | github.com/ | 1.7.32 | 3 |
| quay.io/ | 9d25865295af | github.com/ | 1.7.32 | 3 |
| quay.io/ | ea6dd1e4ce71 | github.com/ | 1.7.32 | 3 |
| alpine/ | 048f8d9c8cc7 | github.com/ | 1.7.32 | 2 |
| netapp/ | cd0c18d8f9ec | github.com/ | 1.7.32 | 2 |
| uselagoon/ | 2c89ed939b8b | github.com/ | 2.2.4 | 2 |
| ghcr.io/ | 82d0b161161d | github.com/ | 1.7.32 | 2 |
| registry.gitlab.com/ | b1198ea741d1 | github.com/ | 1.7.32 | 2 |
| 1dev/ | cd5b12fe5471 | github.com/ | 2.0.9 | 1 |
| alpine/ | 44ef4942e171 | github.com/ | 1.7.32 | 1 |
| alpine/ | 6dbe6f391eda | github.com/ | 1.7.32 | 1 |
| alpine/ | 7a319b15cfc9 | github.com/ | 1.7.32 | 1 |
| alpine/ | 7e1e7d5b7a96 | github.com/ | 1.7.32 | 1 |
| alpine/ | b7a12c5ddf26 | github.com/ | 1.7.32 | 1 |
| alpine/ | d870622d0040 | github.com/ | 1.7.32 | 1 |
| apecloud/ | 98abc64aa985 | github.com/ | 1.7.32 | 1 |
| appwrite/ | 1aaa70127114 | github.com/ | 2.2.4 | 1 |
| appwrite/ | adc7d0e7ec23 | github.com/ | 2.2.4 | 1 |
| aquasec/ | cfbbfee972e6 | github.com/ | 1.7.32 | 1 |
| aquasec/ | bcc376de8d77 | github.com/ github.com/ | 1.7.32 2.2.4 | 1 |
| artifacthub/ | 2d8365601f0e | github.com/ github.com/ | 1.7.32 2.2.4 | 1 |
| artifacthub/ | 5368d21a6e5c | github.com/ | 1.7.32 | 1 |
| drone/ | 55897c8fb22d | github.com/ | 1.7.32 | 1 |
| falcosecurity/ | d0cfe422d6ac | github.com/ | 2.2.4 | 1 |
| falcosecurity/ | 7df783d5269a | github.com/ | 2.2.4 | 1 |
| flanksource/ | 689687a7cf95 | github.com/ | 1.7.32 | 1 |
| gitea/ | 7940221bcfc9 | github.com/ | 1.7.32 | 1 |
| gitea/ | c2a169c5e998 | github.com/ | 1.7.32 | 1 |
| goharbor/ | 5c6f7162804c | github.com/ github.com/ | 1.7.32 2.2.4 | 1 |
| hiversh/ | b0b85f8942c7 | containerd | no fix listed | 1 |
| kenchrcum/ | c326e28a8f5f | github.com/ | 1.7.32 | 1 |
| kubeovn/ | 6722b54eb5c0 | github.com/ | 2.2.4 | 1 |
| layer5/ | 78a8be21bef3 | github.com/ | 1.7.32 | 1 |
| library/ | 2a232a42256f | github.com/ | 2.2.4 | 1 |
| mavrick1/ | 45ca0429a1d4 | github.com/ | 1.7.32 | 1 |
| newrelic/ | 1a448492b55a | github.com/ | 1.7.32 | 1 |
| platzio/ | d5e5972f344b | github.com/ | 1.7.32 | 1 |
| pnnlmiscscripts/ | 8af4b7551d40 | github.com/ | 1.7.32 | 1 |
| gcr.io/ | 4e7a52dd1f14 | github.com/ github.com/ | 1.7.32 2.2.4 | 1 |
| ghcr.io/ | 4c708ecf7dc4 | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | 2cef2a3f97da | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | e02a8bd9e2c3 | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | 3ee1b62aa111 | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | fb609bc264d9 | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | e7f9e8f1d565 | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | 091b906a0b13 | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | 00984ba0f0eb | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | 2ce077d3d02d | github.com/ | 1.7.32 | 1 |
| ghcr.io/ | 59f75504c5d4 | github.com/ | 1.7.32 | 1 |