Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

buildkit — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in buildkit, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for BuildKit, a container image build system developed by Docker Inc. It collects security advisories related to build execution, registry access, and plugin handling, covering findings reported between 2020 and 2024. Readers can track the vendor's advisory history, analyze the frequency of specific weakness types such as remote code execution or buffer overflow issues, and review the product's overall vulnerability trends over time. The dataset focuses on implementation flaws within the buildkit repository, including its core components and integration points with container runtimes.

Vendor: moby

CVE ID Title CVSS Severity Published
CVE-2026-75593 BuildKit: Malicious client can bypass destination directory validation on local sources upload CWE-22 7.2 High 2026-08-19
CVE-2026-61711 BuildKit: Custom frontend could bypass Seccomp/AppArmor CWE-20 5.3 Medium 2026-08-19
CVE-2026-61712 BuildKit: Possible runtime DoS via unbounded group parsing CWE-770 2.3 Low 2026-08-19
CVE-2026-15793 Git source checkout from a bundle file could lead to command injection CWE-88 - - 2026-07-21
CVE-2026-15792 Possible panic when incorrect parameters sent from frontend CWE-20 - - 2026-07-21
CVE-2026-15791 LLB file operation can be tricked to remove /tmp directory contents CWE-22 - - 2026-07-21
CVE-2026-15789 Malicious client can bypass destination directory validation on local sources upload CWE-22 - - 2026-07-21
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root CWE-59 - - 2026-07-20
CVE-2026-33748 BuildKit Git URL subdir component can cause access to restricted files CWE-22 7.5 - 2026-03-27
CVE-2026-33747 BuildKit vulnerable to malicious frontend causing file escape outside of storage root CWE-22 8.4 High 2026-03-27
CVE-2024-23653 BuildKit interactive containers API does not validate entitlements check CWE-863 9.8 Critical 2024-01-31
CVE-2024-23652 BuildKit possible host system access from mount stub cleaner CWE-22 10.0 Critical 2024-01-31
CVE-2024-23651 BuildKit possible race condition with accessing subpaths from cache mounts CWE-362 8.7 High 2024-01-31
CVE-2024-23650 BuildKit possible panic when incorrect parameters sent from frontend CWE-754 5.3 Medium 2024-01-31
CVE-2023-26054 Credentials inlined to Git URLs could end up in provenance attestation in BuildKit CWE-200 6.5 Medium 2023-03-06

All 15 known CVE vulnerabilities affecting buildkit with full Chinese analysis, references, and POCs where available.