CVE Tools

Container Toolkit

6 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Container Toolkit, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Container Toolkit CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Container Toolkit CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-072
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-071
2026-080
2026-090

Severity

How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical233%
  • High350%
  • Medium117%

Latest CVEs

The 6 most recently published vulnerabilities affecting Container Toolkit.

  1. CVE-2026-24260NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code e...8.5
  2. CVE-2025-23267NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A succes...8.5
  3. CVE-2025-23266NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A succe...9.0
  4. CVE-2025-23359NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host fi...8.3
  5. CVE-2024-0133NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This...4.1
  6. CVE-2024-0132NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain acc...9.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store