PoC Archive PoC Archive

tag

Container-Escape

Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)
CVE-2026-53361 binary Patched
CVE-2026-53361binaryCRITICAL 9.8Patched2026-08-16Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106 binary Unverified
CVE-2026-17106binaryCRITICAL 9.8Unverified2026-08-15Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)
CVE-2026-43499 (aka "GhostLock") binary Patched
CVE-2026-43499binaryHIGH 7.8Patched2026-07-08OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw) cloud Patched
CVE-2026-41900cloudHIGH 8.6Patched2026-07-05Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413
CVE-2026-31413 binary Patched
CVE-2026-31413binaryCRITICALPatched2026-07-05Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680 cloud Patched
CVE-2026-46680cloudHIGHPatched2026-07-05Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudHIGHUnverified2026-07-03Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudMEDIUMUnverified2026-07-03Linux vsock Use-After-Free VM Escape (CVE-2025-21756)
CVE-2025-21756 binary Patched
CVE-2025-21756binaryHIGH 7.8Patched2026-05-17