恶意的外部 BuildKit 前端可以使用内部 API 发送请求,从而创建可能导致数据竞争的条件,使 BuildKit 守护进程发生恐慌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93318 | 7.5 HIGH | Cache poisoning via unvalidated image layer DiffIDs |
| CVE-2026-93316 | 7.1 HIGH | Starting daemon with --cdi-disabled flag can lead to panic on specific builds |
| CVE-2026-93322 | 6.9 MEDIUM | Malformed MergeOp can crash the BuildKit daemon |
| CVE-2026-93323 | 6.8 MEDIUM | Oversized Dockerfile or .dockerignore can exhaust buildkitd memory |
| CVE-2026-93320 | 6.0 MEDIUM | BuildKit improperly handles special files in build snapshots |
| CVE-2026-93326 | 6.0 MEDIUM | Crafted Git build source can bypass certain policy validation |
| CVE-2026-93317 | 5.9 MEDIUM | Container blob cache can accept unverified content |
| CVE-2026-93315 | 5.8 MEDIUM | BuildKit proxy CA cleanup can be disrupted by build steps |
No comments yet