CVE-2026-93315Medium· 5.8▾ SunlitWhen proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93321Medium· 6.9A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
CVE-2026-93326Medium· 6.0A build step for a Git source, crafted in a specific way, can bypass some policy validation rules
CVE-2026-93320Medium· 6.0BuildKit may be tricked into performing file actions with special file inodes where regular files are expected
CVE-2026-93322Medium· 6.9A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
CVE-2026-93323Medium· 6.8The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit
CVE-2026-93317Medium· 5.9An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest