CVE-2026-64777: Container vulnerability
Published Aug 20, 2026
·Updated
A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.
Affected Software
1 affected component
container=1.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.0
Event History
Aug 20, 2026
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs to act as a malicious builder peer and request a file by name from the host during a build.
2
What data could be exposed?
The builder peer may receive the contents of a host file when the requested name resolves outside the intended build context.
3
Which version addresses the issue?
The issue is addressed in container version 1.2.0.