Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q49m-57vm-c8cc | Kata Container has CopyFile Policy Subversion via Symlinks |
Thu, 14 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Katacontainers confidential Containers
Katacontainers kata Containers |
|
| CPEs | cpe:2.3:a:katacontainers:confidential_containers:*:*:*:*:*:*:*:* cpe:2.3:a:katacontainers:kata_containers:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Katacontainers confidential Containers
Katacontainers kata Containers |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 13 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 07 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1220 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 04 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 27 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Katacontainers
Katacontainers kata-containers |
|
| Vendors & Products |
Katacontainers
Katacontainers kata-containers |
Mon, 27 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0. | |
| Title | Kata Containers: CopyFile Policy Subversion via Symlinks | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T05:17:44.571Z
Reserved: 2026-04-20T14:01:46.672Z
Link: CVE-2026-41326
Updated: 2026-05-13T05:17:44.571Z
Status : Analyzed
Published: 2026-04-24T19:17:12.253
Modified: 2026-05-14T16:33:30.310
Link: CVE-2026-41326
OpenCVE Enrichment
Updated: 2026-05-07T01:30:17Z
Github GHSA