PODMAN has a critical vulnerability, CVE-2026-94603, that can let a container image disable or override sandboxing when started with podman run. The advisory assigns a CVSSv3 score of 10.0 and notes that the issue stems from a checkpoint annotation carried by OCI images.
In practice, if an image is marked as a checkpoint, Podman will silently ignore user-specified container creation restrictions (for example, a request to drop capabilities), allowing the image’s own settings to dictate how the container is executed. The advisory describes this as effectively giving the image control over execution and sandboxing, potentially broadening access rights inside the container.
The flaw affects Podman releases dating back to 4.4.0, with affected versions continuing until patched. There is no public confirmation of exploitation in the wild at the time of the report. The maintainers have addressed the issue in Podman 6.1.3 and Podman 5.8.8 by removing the checkpoint feature behind the vulnerability; Podman run no longer supports checkpoint images.
If upgrading is not possible, the suggested mitigation is to scan pulled images for the io.podman.annotations.checkpoint.runtime[.]name annotation and reject any images that carry it, since Podman cannot automate this check. The advisory also provides the GHSA reference GHSA-2cvf-wqm6-wr9g and emphasizes treating the vulnerability as urgent on hosts that run untrusted images.