CVE-2026-53489: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
A bug was found in containerd where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-53489 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →