---
id: CVE-2026-93323
title: >-
  The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a
  build context into memory without a size limit
summary: >-
  The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a
  build context into memory without a size limit. A build context containing an
  oversized file could make buildkitd allocate memory proportional to that file,
  poten…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-789
vendor: moby
product: github.com/moby/buildkit
affected:
  - github.com/moby/buildkit <= 0.33.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:17:26.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93323'
references:
  - url: 'https://github.com/moby/buildkit/releases/tag/v0.33.1'
    label: security@docker.com
  - url: 'https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp'
    label: security@docker.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T18:47:20.730540Z'
cvssSource: cna
ingestedAt: '2026-10-05T18:29:11.203Z'
---

## Overview

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
