CVE-2026-93317
Container blob cache can accept unverified content
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
| CWE | CWE-354 |
| Vendor | moby |
| Product | buildkit |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for moby buildkit
Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
moby / BuildKit
0.28.0 < 0.33.1
References
Credits
He Wei (https://github.com/hewei-gikaku) Haoxiang Yan (https://github.com/Yanhaoxi)