Affected by GO-2025-4100
and 9 other vulnerabilities
GO-2025-4100: containerd affected by a local privilege escalation via wide permissions on CRI directory in github.com/containerd/containerd
GO-2025-4108: containerd CRI server: Host memory exhaustion through Attach goroutine leak in github.com/containerd/containerd
GO-2026-5064: containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd
GO-2026-5338: containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd
GO-2026-5378: containerd user ID handling bypass allows runAsNonRoot evasion in github.com/containerd/containerd
GO-2026-5475: containerd image-triggered runtime DoS via unbounded group parsing in github.com/containerd/containerd
GO-2026-5622: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd
GO-2026-5758: containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull in github.com/containerd/containerd
GO-2026-6444: containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd
GO-2026-6597: Containerd has image-pull DoS via crafted OCI index graph amplification in github.com/containerd/containerd
Publish packages and sends an event. The caller will be considered the
initial publisher of the event. This means the timestamp will be calculated
at this point and this method may read from the calling context.
Subscribe to events on the exchange. Events are sent through the returned
channel ch. If an error is encountered, it will be sent on channel errs and
errs will be closed. To end the subscription, cancel the provided context.
Zero or more filters may be provided as strings. Only events that match
*any* of the provided filters will be sent on the channel. The filters use
the standard containerd filters package syntax.