---
id: CVE-2026-33747
title: >-
  BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code
  execution via untrusted frontend (CVE-2026-33747)
summary: >-
  A flaw was found in BuildKit, a toolkit for converting source code to build
  artifacts. An untrusted BuildKit frontend can be leveraged to craft a
  malicious API message, allowing files to be written outside of the designated
  BuildKit state …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Red Hat Openshift Data Foundation 4.22
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - confidential_compute_attestation
  - logging_subsystem_for_red_hat_openshift
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - multicluster_engine_for_kubernetes
  - openshift_developer_tools_and_services
  - openshift_serverless
  - pen_drive_powered_by_red_hat_lightspeed
  - build_of_podman_desktop
  - build_of_podman_desktop_tech_preview
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_gitops
  - quay 3
  - openshift_api_for_data_protection 1.3
  - openshift_api_for_data_protection 1.4
  - openshift_api_for_data_protection 1.5
  - openshift_ai 2.25
  - openshift_service_mesh 3.0
  - openshift_service_mesh 3.1
  - openshift_service_mesh 3.2
  - openshift_data_foundation 4.20
  - openshift_data_foundation 4.22
  - quay 3.14
  - quay 3.17
  - trusted_artifact_signer 1.3
  - multicluster_engine_for_kubernetes 2.1
  - multicluster_engine_for_kubernetes 2.8
patched:
  - openshift_api_for_data_protection 1.3
  - openshift_api_for_data_protection 1.4
  - openshift_api_for_data_protection 1.5
  - openshift_ai 2.25
  - openshift_service_mesh 3.0
  - openshift_service_mesh 3.1
  - openshift_service_mesh 3.2
  - openshift_data_foundation 4.20
  - openshift_data_foundation 4.22
  - quay 3.14
  - quay 3.17
  - trusted_artifact_signer 1.3
  - multicluster_engine_for_kubernetes 2.1
  - multicluster_engine_for_kubernetes 2.8
published: '2026-03-27'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:07:04+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33747.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33747.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-33747'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2452076'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-33747'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33747'
  - url: 'https://github.com/moby/buildkit/releases/tag/v0.28.1'
  - url: 'https://github.com/moby/buildkit/security/advisories/GHSA-4c29-8rgm-jvjj'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51033'
  - url: 'https://access.redhat.com/errata/RHSA-2026:29854'
  - url: 'https://access.redhat.com/errata/RHSA-2026:26568'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42644'
  - url: 'https://access.redhat.com/errata/RHSA-2026:9440'
  - url: 'https://access.redhat.com/errata/RHSA-2026:9448'
  - url: 'https://access.redhat.com/errata/RHSA-2026:9453'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57013'
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70267'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
  - url: 'https://access.redhat.com/errata/RHSA-2026:10125'
  - url: 'https://access.redhat.com/errata/RHSA-2026:46885'
  - url: 'https://access.redhat.com/errata/RHSA-2026:30650'
  - url: 'https://github.com/moby/buildkit'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00498
epssPercentile: 0.41774
aliases:
  - GHSA-4c29-8rgm-jvjj
  - GO-2026-4858
ecosystem: go
scores:
  vendor: 8.2
  osv: 8.4
ingestedAt: '2026-09-12T03:13:01.752Z'
---

## Overview

A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state directory. This vulnerability, which is a form of arbitrary file write, could enable an attacker to execute unauthorized code or escalate their privileges on the system. This issue arises when custom BuildKit frontends are used with specific configuration options.

## Vendor advisories

- **RHSA-2026:51033** · Red Hat · fixed in: OpenShift API for Data Protection 1.3 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51033)
- **RHSA-2026:29854** · Red Hat · fixed in: OpenShift API for Data Protection 1.4 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:29854)
- **RHSA-2026:26568** · Red Hat · fixed in: OpenShift API for Data Protection 1.5 · released 2026-06-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:26568)
- **RHSA-2026:42644** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42644)
- **RHSA-2026:9440** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.0 · released 2026-04-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:9440)
- **RHSA-2026:9448** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.1 · released 2026-04-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:9448)
- **RHSA-2026:9453** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.2 · released 2026-04-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:9453)
- **RHSA-2026:57013** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.20 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57013)
- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **RHSA-2026:70267** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70267)
- **RHSA-2026:22465** · Red Hat · fixed in: Red Hat Quay 3.17 · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22465)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Containers, Migration Toolkit for Virtualization, Multicluster Engine for Kubernetes, … · no fix planned: Confidential Compute Attestation, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Virtualization, Multicluster Engine for Kubernetes, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33747.json)
- **RHSA-2026:10125** · Red Hat · fixed in: Red Hat Trusted Artifact Signer 1.3 · released 2026-04-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:10125)

**BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend** — rated Moderate by Red Hat. Released 2026-03-27, updated 2026-09-22.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Confidential Compute Attestation
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat Build of Podman Desktop
- Red Hat Build of Podman Desktop - Tech Preview
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat Quay 3

Fixed:

- OpenShift API for Data Protection 1.3
- OpenShift API for Data Protection 1.4
- OpenShift API for Data Protection 1.5
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat Openshift Data Foundation 4.20
- Red Hat Openshift Data Foundation 4.22
- Red Hat Quay 3.14
- Red Hat Quay 3.17
- Red Hat Trusted Artifact Signer 1.3
- multicluster engine for Kubernetes 2.1
- multicluster engine for Kubernetes 2.8

No fix planned:

- Confidential Compute Attestation
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- OpenShift Serverless
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat Build of Podman Desktop
- Red Hat Build of Podman Desktop - Tech Preview
- Red Hat OpenShift Container Platform 4
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Migration Toolkit for Containers
- OpenShift Developer Tools and Services
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift GitOps
- Red Hat Quay 3

Not affected:

- OpenShift API for Data Protection 1.3
- OpenShift API for Data Protection 1.4
- OpenShift API for Data Protection 1.5
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat Openshift Data Foundation 4.20
- Red Hat Openshift Data Foundation 4.22
- Red Hat Quay 3.14

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:51033
Before applying this update, make sure all previously released errata
relevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:29854
Before applying this update, make sure all previously released errata
relevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:26568

Workarounds / mitigations:

- To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via `#syntax` or `--build-arg BUILDKIT_SYNTAX`.

## Package advisory (CVE-2026-33747)

Affected packages:

- `github.com/moby/buildkit < 0.28.1`

Patched in:

- `github.com/moby/buildkit 0.28.1`

Source: https://osv.dev/vulnerability/GHSA-4c29-8rgm-jvjj
