Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/kata-containers/kata-containers
  4. ›
  5. CVE-2026-41326

CVE-2026-41326: Kata Container has CopyFile Policy Subversion via Symlinks

May 4, 2026 (updated May 8, 2026)

An oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs.

References

  • github.com/advisories/GHSA-q49m-57vm-c8cc
  • github.com/kata-containers/kata-containers/commit/1b9e49eb2763aa6ea6a99b276d3ff5e2c7f658f2
  • github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc
  • nvd.nist.gov/vuln/detail/CVE-2026-41326

Code Behaviors & Features

Detect and mitigate CVE-2026-41326 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20260422180503-1b9e49eb2763

Fixed versions

  • 0.0.0-20260422180503-1b9e49eb2763

Solution

Upgrade to version 0.0.0-20260422180503-1b9e49eb2763 or above.

Impact 9 CRITICAL

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-61: UNIX Symbolic Link (Symlink) Following

Source file

go/github.com/kata-containers/kata-containers/CVE-2026-41326.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 18 May 2026 00:18:08 +0000.