CVE-2026-93318High· 7.5▾ TwilightA malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matc…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents.
If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build.
The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93317Medium· 5.9An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest
CVE-2026-93326Medium· 6.0A build step for a Git source, crafted in a specific way, can bypass some policy validation rules
CVE-2026-93320Medium· 6.0BuildKit may be tricked into performing file actions with special file inodes where regular files are expected
CVE-2026-93322Medium· 6.9A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
CVE-2026-93323Medium· 6.8The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit
CVE-2026-93319Medium· 5.7A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.