Gvisor
8 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Gvisor. Use it to gauge the current risk picture and drill into individual advisories.
Gvisor CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium5
Latest CVEs
The 8 most recently published vulnerabilities affecting Gvisor.
- CVE-2026-96812Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE—
- CVE-2025-2713Improper File Permission Handling in Google gVisor runsc7.8
- CVE-2024-10603Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.5.3
- CVE-2024-10026Improved Seeding and Hashing In gVisor5.3
- CVE-2023-7258Denial-of-Service in Gvisor4.8
- CVE-2018-20168Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" pan...5.5
- CVE-2018-19333pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RM...9.8
- CVE-2018-16359Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.6.8
Product grouping is registry-driven, with AI assist and human review. How it works