
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Peirates - Kubernetes Penetration Testing tool

CLI tool and library for generating a Software Bill of Materials from container images and filesystems


PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Proof-of-concept exploit for CVE-2026-5555, demonstrating container escape via /proc/self/fd symlink in rshared volumes to overwrite host files and…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

POCs and Tetragon Rules for CVE-2024-21626 and CVE-2025-31133

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection,…

Docker Container Escape POC via mlx-metal importlib

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

Container escape on any docker container with healthcheck enabled via CVE-2026-31431