๐Ÿ” CVE Alert

CVE-2026-93318

UNKNOWN 0.0

Cache poisoning via unvalidated image layer DiffIDs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.

CWE CWE-354
Vendor moby
Product buildkit
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / BuildKit
0 < 0.33.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-f2v9-hprr-32q3 github.com: https://github.com/moby/buildkit/releases/tag/v0.33.1

Credits

Kohei Tokunaga (https://github.com/ktock)