๐Ÿ” CVE Alert

CVE-2026-103433

UNKNOWN 0.0

Bake filesystem entitlement consent is skipped for certain secret and oci-layout definitions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.

CWE CWE-862
Vendor docker
Product docker buildx
Ecosystems
Industries
Technology
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker buildx

Be the first to know when new unknown vulnerabilities affecting docker docker buildx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Buildx
0 < 0.37.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/docker/buildx/security/advisories/GHSA-p54p-jq4x-rc28 github.com: https://github.com/docker/buildx/releases/tag/v0.37.2 github.com: https://github.com/docker/buildx docs.docker.com: https://docs.docker.com/build/bake/reference/#targetentitlements

Credits

Artem Lytkin