{"id":"CVE-2026-93315","title":"When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup","summary":"When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.","severity":"medium","cvss":5.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:N","cwe":["CWE-367"],"vendor":"moby","product":"github.com/moby/buildkit","affected":["github.com/moby/buildkit >= 0.31.0 < 0.33.1"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T22:16:58.820","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93315","references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","label":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x","label":"security@docker.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-05T22:35:24.740Z","slug":"CVE-2026-93315","body":"## Overview\n\nWhen proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}