BuildKit

Moby · 15 CVEs

CVE-2026-93321
MEDIUM

Malformed LLB file operation can crash buildkitd

Oct 5, 2026

CVE-2026-93315
MEDIUM

BuildKit proxy CA cleanup can be disrupted by build steps

Oct 5, 2026

CVE-2026-93326
MEDIUM

Crafted Git build source can bypass certain policy validation

Oct 5, 2026

CVE-2026-93323
MEDIUM

Oversized Dockerfile or .dockerignore can exhaust buildkitd memory

Oct 5, 2026

CVE-2026-93322
MEDIUM

Malformed MergeOp can crash the BuildKit daemon

Oct 5, 2026

CVE-2026-93320
MEDIUM

BuildKit improperly handles special files in build snapshots

Oct 5, 2026

CVE-2026-93319
MEDIUM

A malicious frontend can cause a daemon panic

Oct 5, 2026

CVE-2026-93318
HIGH

Cache poisoning via unvalidated image layer DiffIDs

Oct 5, 2026

CVE-2026-93317
MEDIUM

Container blob cache can accept unverified content

Oct 5, 2026

CVE-2026-93316
HIGH

Starting daemon with --cdi-disabled flag can lead to panic on specific builds

Oct 5, 2026

CVE-2026-75593
HIGH

BuildKit: Malicious client can bypass destination directory validation on local sources upload

Aug 19, 2026

CVE-2026-61711
MEDIUM

BuildKit: Custom frontend could bypass Seccomp/AppArmor

Aug 19, 2026

CVE-2026-61712
LOW

BuildKit: Possible runtime DoS via unbounded group parsing

Aug 19, 2026

CVE-2026-15793
HIGH

Git source checkout from a bundle file could lead to command injection

Jul 21, 2026

CVE-2026-15792
MEDIUM

Possible panic when incorrect parameters sent from frontend

Jul 21, 2026

CVE-2026-15791
LOW

LLB file operation can be tricked to remove /tmp directory contents

Jul 21, 2026

CVE-2026-15789
MEDIUM

Malicious client can bypass destination directory validation on local sources upload

Jul 21, 2026

CVE-2026-15788
MEDIUM

WCOW cache mount source selector resolves NTFS junctions outside of cache root

Jul 20, 2026

CVE-2026-33748
HIGH

BuildKit Git URL subdir component can cause access to restricted files

Mar 27, 2026

CVE-2026-33747
CRITICAL

BuildKit vulnerable to malicious frontend causing file escape outside of storage root

Mar 27, 2026

CVE-2024-23653
CRITICAL

BuildKit interactive containers API does not validate entitlements check

Jan 31, 2024

CVE-2024-23652
CRITICAL

BuildKit possible host system access from mount stub cleaner

Jan 31, 2024

CVE-2024-23651
HIGH

BuildKit possible race condition with accessing subpaths from cache mounts

Jan 31, 2024

CVE-2024-23650
MEDIUM

BuildKit possible panic when incorrect parameters sent from frontend

Jan 31, 2024

CVE-2023-26054
MEDIUM

Credentials inlined to Git URLs could end up in provenance attestation in BuildKit

Mar 6, 2023

Showing 1 to 15 of 15 CVEs