CVE-2026-61711Medium▾ SunlitBuildKit: Custom frontend could bypass Seccomp/AppArmor
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.4%
Last analysed / modified upstream
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.
Problem has been fixed in versions v0.31.1+
Only use BuildKit frontends from trusted providers.
github.com/moby/buildkit < 0.31.1Upgrade to a patched release:
github.com/moby/buildkit 0.31.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61712LowBuildKit has a possible runtime DoS via unbounded group parsing
CVE-2026-33748High· 7.5BuildKit Git URL subdir component can cause access to restricted files
CVE-2024-23652Critical· 10.0BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities