MEDIUM 5.8 NVD
CVE-2026-93315
When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build
When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.
References
- https://github.com/moby/buildkit/releases/tag/v0.33.1
- https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.