Containers
– Getty Images

Developers are uneasy about container security, with almost one in four having experienced a container-breached incident in the last year.

According to a Bellsoft survey of more than 400 developers, the problem is exacerbated by the gap between vulnerability disclosure and remediation, with organizations often left exposed for weeks or months.

Human error was identified as the leading cause of container security issues, cited by 62% of respondents. Developers also reported relying heavily on shells (54%) and package managers (39%) within container images, which can expand the attack surface and allow unnecessary components to be installed at runtime.

Of currently applied container security mechanisms, 45% work with trusted image registries, followed by 43% relying on vulnerability scanning. More than one-third of developers used only standard Docker/Kubernetes tools in their workflow.

The survey highlighted that pre-hardened, vendor-maintained base images would be the most helpful mitigation, with 48% of developers indicating this approach helped reduce operational strain, human error, and exposure to vulnerabilities. Such solutions are offered by the likes of Red Hat, which recently launched a catalog of minimal, hardened container images to help address the need for "zero-CVE" applications.

Dubbed Project Hummingbird, the offering intends to shrink attack surfaces and bolster supply chain confidence by closing the gap between accelerating deployment and improving application security.

Notable container breaches in the recent past have included a critical vulnerability in Docker Desktop for Windows and macOS, which allowed a malicious container to reach the Docker Engine API without authentication.

Cloud security vendor Wiz, meanwhile, discovered a breach in the Nvidia Container Toolkit (NCT). As revealed in July, the flaw allowed a malicious container to bypass isolation measures and gain full root access to the host machine.