๐Ÿ” CVE Alert

CVE-2026-61712

UNKNOWN 0.0

BuildKit: Possible runtime DoS via unbounded group parsing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1.

CWE CWE-770
Vendor moby
Product buildkit
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / buildkit
< 0.31.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86 github.com: https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1 github.com: https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255 github.com: https://github.com/moby/buildkit/releases/tag/v0.31.1