MEDIUM 5.7 NVD
CVE-2026-93319
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
References
- https://github.com/moby/buildkit/releases/tag/v0.33.1
- https://github.com/moby/buildkit/security/advisories/GHSA-4hgw-qrhw-fhg8
This medium severity vulnerability with a CVSS score of 5.7 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.