Moby / BuildKit
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-75593 | BuildKit: Malicious client can bypass destination directory validation on local sources upload | HIGH | 7.2 | Aug 19, 2026 |
| CVE-2026-61711 | BuildKit: Custom frontend could bypass Seccomp/AppArmor | MEDIUM | 5.3 | Aug 19, 2026 |
| CVE-2026-61712 | BuildKit: Possible runtime DoS via unbounded group parsing | LOW | 2.3 | Aug 19, 2026 |
| CVE-2026-15793 | Git source checkout from a bundle file could lead to command injection | HIGH | 7.3 | Jul 21, 2026 |
| CVE-2026-15792 | Possible panic when incorrect parameters sent from frontend | MEDIUM | 6.3 | Jul 21, 2026 |
| CVE-2026-15791 | LLB file operation can be tricked to remove /tmp directory contents | LOW | 3.3 | Jul 21, 2026 |
| CVE-2026-15789 | Malicious client can bypass destination directory validation on local sources upload | MEDIUM | 6.9 | Jul 21, 2026 |
| CVE-2026-15788 | WCOW cache mount source selector resolves NTFS junctions outside of cache root | MEDIUM | 5.6 | Jul 20, 2026 |
| CVE-2026-33748 | BuildKit Git URL subdir component can cause access to restricted files | HIGH | 8.2 | Mar 27, 2026 |
| CVE-2026-33747 | BuildKit vulnerable to malicious frontend causing file escape outside of storage root | CRITICAL | 9.8 | Mar 27, 2026 |
| CVE-2024-23653 | BuildKit interactive containers API does not validate entitlements check | CRITICAL | 9.8 | Jan 31, 2024 |
| CVE-2024-23652 | BuildKit possible host system access from mount stub cleaner | CRITICAL | 10.0 | Jan 31, 2024 |
| CVE-2024-23651 | BuildKit possible race condition with accessing subpaths from cache mounts | HIGH | 8.7 | Jan 31, 2024 |
| CVE-2024-23650 | BuildKit possible panic when incorrect parameters sent from frontend | MEDIUM | 5.3 | Jan 31, 2024 |
| CVE-2023-26054 | Credentials inlined to Git URLs could end up in provenance attestation in BuildKit | MEDIUM | 6.5 | Mar 6, 2023 |
Showing 1 to 10 of 10 CVEs