๐Ÿ” CVE Alert

CVE-2026-93320

UNKNOWN 0.0

BuildKit improperly handles special files in build snapshots

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

CWE CWE-441
Vendor moby
Product buildkit
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / BuildKit
0 โ‰ค 0.33.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2 github.com: https://github.com/moby/buildkit/releases/tag/v0.33.1

Credits

Daniele Linguaglossa (https://github.com/dzonerzy)