๐Ÿ” CVE Alert

CVE-2026-93317

UNKNOWN 0.0

Container blob cache can accept unverified content

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

CWE CWE-354
Vendor moby
Product buildkit
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / BuildKit
0.28.0 < 0.33.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv github.com: https://github.com/moby/buildkit/releases/tag/v0.33.1

Credits

He Wei (https://github.com/hewei-gikaku) Haoxiang Yan (https://github.com/Yanhaoxi)