{"id":"CVE-2026-61712","aliases":["GHSA-72x6-4j93-7w86","GO-2026-6256"],"title":"BuildKit has a possible runtime DoS via unbounded group parsing","summary":"BuildKit has a possible runtime DoS via unbounded group parsing","severity":"low","vendor":"moby","product":"github.com/moby/buildkit","ecosystem":"go","affected":["github.com/moby/buildkit < 0.31.1"],"patched":["github.com/moby/buildkit 0.31.1"],"published":"2026-08-19","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:51:13.226978985Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-72x6-4j93-7w86","references":[{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86"},{"url":"https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1"},{"url":"https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255"},{"url":"https://github.com/moby/buildkit"},{"url":"https://github.com/moby/buildkit/releases/tag/v0.31.1"},{"url":"https://github.com/advisories/GHSA-72x6-4j93-7w86"}],"tags":["osv","go","nvd","ghsa"],"epss":0.00404,"epssPercentile":0.34472,"cwe":["CWE-770"],"ingestedAt":"2026-08-19T20:44:41.424Z","slug":"CVE-2026-61712","body":"## Overview\n\n### Impact\nMaliciously crafted base image or build can cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the buildkitd process.\n\n### Patches\nIssue is fixed in BuildKit v0.31.1+\n\n### Workarounds\nUse trusted build sources.\n\n### References\nThis is BuildKit variant of containerd advisory https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq\n\n## Affected packages\n\n- `github.com/moby/buildkit < 0.31.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/moby/buildkit 0.31.1`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}