CVE-2026-64773: Container container vulnerability

Published Aug 20, 2026
·
Updated

An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.

Affected Software

1 affected component
container container<=1.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade container to a version that resolves this vulnerability.

    Fixed in 1.2.0

Event History

Aug 20, 2026
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Hosts running affected container versions are exposed when they publish a container TCP port that an attacker can reach. The attacker does not need direct access to the host if they can connect to that published port.

2

What does an attacker need to do to exploit it?

The attacker needs network reachability to a published TCP port and can send data while the backend container connection is still completing. The forwarding process may then retain the client data in host memory without a size or time limit.

3

What is the practical impact?

An attacker may cause unbounded memory consumption in the host forwarding process by extending the time before the backend container connection completes. This can create a denial-of-service condition on the host.

4

What version addresses the vulnerability?

The issue is addressed in container version 1.2.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203