{"id":"AZL-104081","summary":"CVE-2026-53493 affecting package moby-containerd-cc 1.7.7-17","details":"containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.","modified":"2026-09-25T14:16:09.010854718Z","published":"2026-09-25T01:16:48Z","upstream":["CVE-2026-53493"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53493"}],"affected":[{"package":{"name":"moby-containerd-cc","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/moby-containerd-cc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.7.7-17"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104081.json"}}],"schema_version":"1.9.0"}