BuildKit
Moby · 15 CVEs
Malformed LLB file operation can crash buildkitd
Oct 5, 2026
BuildKit proxy CA cleanup can be disrupted by build steps
Oct 5, 2026
Crafted Git build source can bypass certain policy validation
Oct 5, 2026
Oversized Dockerfile or .dockerignore can exhaust buildkitd memory
Oct 5, 2026
Malformed MergeOp can crash the BuildKit daemon
Oct 5, 2026
BuildKit improperly handles special files in build snapshots
Oct 5, 2026
A malicious frontend can cause a daemon panic
Oct 5, 2026
Cache poisoning via unvalidated image layer DiffIDs
Oct 5, 2026
Container blob cache can accept unverified content
Oct 5, 2026
Starting daemon with --cdi-disabled flag can lead to panic on specific builds
Oct 5, 2026
BuildKit: Malicious client can bypass destination directory validation on local sources upload
Aug 19, 2026
BuildKit: Custom frontend could bypass Seccomp/AppArmor
Aug 19, 2026
BuildKit: Possible runtime DoS via unbounded group parsing
Aug 19, 2026
Git source checkout from a bundle file could lead to command injection
Jul 21, 2026
Possible panic when incorrect parameters sent from frontend
Jul 21, 2026
LLB file operation can be tricked to remove /tmp directory contents
Jul 21, 2026
Malicious client can bypass destination directory validation on local sources upload
Jul 21, 2026
WCOW cache mount source selector resolves NTFS junctions outside of cache root
Jul 20, 2026
BuildKit Git URL subdir component can cause access to restricted files
Mar 27, 2026
BuildKit vulnerable to malicious frontend causing file escape outside of storage root
Mar 27, 2026
BuildKit interactive containers API does not validate entitlements check
Jan 31, 2024
BuildKit possible host system access from mount stub cleaner
Jan 31, 2024
BuildKit possible race condition with accessing subpaths from cache mounts
Jan 31, 2024
BuildKit possible panic when incorrect parameters sent from frontend
Jan 31, 2024
Credentials inlined to Git URLs could end up in provenance attestation in BuildKit
Mar 6, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-93321 | Malformed LLB file operation can crash buildkitd | MEDIUM | 0.15% | Oct 5, 2026 |
| CVE-2026-93315 | BuildKit proxy CA cleanup can be disrupted by build steps | MEDIUM | 0.10% | Oct 5, 2026 |
| CVE-2026-93326 | Crafted Git build source can bypass certain policy validation | MEDIUM | 0.25% | Oct 5, 2026 |
| CVE-2026-93323 | Oversized Dockerfile or .dockerignore can exhaust buildkitd memory | MEDIUM | 0.11% | Oct 5, 2026 |
| CVE-2026-93322 | Malformed MergeOp can crash the BuildKit daemon | MEDIUM | 0.13% | Oct 5, 2026 |
| CVE-2026-93320 | BuildKit improperly handles special files in build snapshots | MEDIUM | 0.11% | Oct 5, 2026 |
| CVE-2026-93319 | A malicious frontend can cause a daemon panic | MEDIUM | 0.09% | Oct 5, 2026 |
| CVE-2026-93318 | Cache poisoning via unvalidated image layer DiffIDs | HIGH | 0.17% | Oct 5, 2026 |
| CVE-2026-93317 | Container blob cache can accept unverified content | MEDIUM | 0.16% | Oct 5, 2026 |
| CVE-2026-93316 | Starting daemon with --cdi-disabled flag can lead to panic on specific builds | HIGH | 0.24% | Oct 5, 2026 |
| CVE-2026-75593 | BuildKit: Malicious client can bypass destination directory validation on local sources upload | HIGH | 0.54% | Aug 19, 2026 |
| CVE-2026-61711 | BuildKit: Custom frontend could bypass Seccomp/AppArmor | MEDIUM | 0.36% | Aug 19, 2026 |
| CVE-2026-61712 | BuildKit: Possible runtime DoS via unbounded group parsing | LOW | 0.40% | Aug 19, 2026 |
| CVE-2026-15793 | Git source checkout from a bundle file could lead to command injection | HIGH | 0.20% | Jul 21, 2026 |
| CVE-2026-15792 | Possible panic when incorrect parameters sent from frontend | MEDIUM | 0.24% | Jul 21, 2026 |
| CVE-2026-15791 | LLB file operation can be tricked to remove /tmp directory contents | LOW | 0.25% | Jul 21, 2026 |
| CVE-2026-15789 | Malicious client can bypass destination directory validation on local sources upload | MEDIUM | 0.31% | Jul 21, 2026 |
| CVE-2026-15788 | WCOW cache mount source selector resolves NTFS junctions outside of cache root | MEDIUM | 0.41% | Jul 20, 2026 |
| CVE-2026-33748 | BuildKit Git URL subdir component can cause access to restricted files | HIGH | 0.53% | Mar 27, 2026 |
| CVE-2026-33747 | BuildKit vulnerable to malicious frontend causing file escape outside of storage root | CRITICAL | 0.58% | Mar 27, 2026 |
| CVE-2024-23653 | BuildKit interactive containers API does not validate entitlements check | CRITICAL | 3.45% | Jan 31, 2024 |
| CVE-2024-23652 | BuildKit possible host system access from mount stub cleaner | CRITICAL | 2.46% | Jan 31, 2024 |
| CVE-2024-23651 | BuildKit possible race condition with accessing subpaths from cache mounts | HIGH | 0.91% | Jan 31, 2024 |
| CVE-2024-23650 | BuildKit possible panic when incorrect parameters sent from frontend | MEDIUM | 1.14% | Jan 31, 2024 |
| CVE-2023-26054 | Credentials inlined to Git URLs could end up in provenance attestation in BuildKit | MEDIUM | 1.03% | Mar 6, 2023 |
Showing 1 to 15 of 15 CVEs