# containerd v2.0.12

> Kubernetes Core · 2026-09-04

A security-focused maintenance release fixes two disclosed vulnerabilities, changes the Windows logging default, and hardens registry fetching. It also includes correctness and performance fixes.

## Action needed
- **[security]** `CVE-2026-53495` and `GHSA-7jxh-36q5-gcqv` security fix
  - This release fixes the disclosed vulnerability identified by `CVE-2026-53495` and `GHSA-7jxh-36q5-gcqv`.
- **[security]** `GHSA-rp3h-jf77-q9p4` security fix
  - This release fixes the disclosed vulnerability identified by `GHSA-rp3h-jf77-q9p4`.

## Check if affected
- **[breaking]** The `ScrubLogs` Windows default
  - Applies if you run containerd on Windows.
  - `ScrubLogs` is used by default on Windows.

## Other recorded changes
- 6 (value_changed 5, added 1)

[Full analysis](https://ratatosk.io/en/releases/containerd/v2.0.12)

[Original release notes](https://github.com/containerd/containerd/releases/tag/v2.0.12)
