CVE-2026-61711
BuildKit: Custom frontend could bypass Seccomp/AppArmor
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.
| CWE | CWE-20 |
| Vendor | moby |
| Product | buildkit |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for moby buildkit
Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
moby / buildkit
< 0.31.1
References
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6 github.com: https://github.com/moby/buildkit/commit/3ea6dd0ce7d269cdb8aa23348718e2c1bf64f109 github.com: https://github.com/moby/buildkit/commit/64bbec89ca43dd95b2853edeca240c33c6729910 github.com: https://github.com/moby/buildkit/releases/tag/v0.31.1