github.com/moby/buildkit
Go9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/moby/buildkitpage 1 of 1
- CVE-2023-26054MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.11.42023-03-06
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains credentials and the build…
- CVE-2024-23650MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. …
- CVE-2024-23651HIGHCVSS 8.7EG 8.7✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition t…
- CVE-2024-23652CRITICALCVSS 10.0EG 10.0✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created f…
- CVE-2024-23653CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based o…
- CVE-2026-33747CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.28.12026-03-27
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files …
- CVE-2026-33748HIGHCVSS 7.5EG 7.5✓ Fixed in 0.28.12026-03-27
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside…
- CVE-2026-61711MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.31.12026-08-19
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oc…
- CVE-2026-61712LOWCVSS 2.3EG 2.3✓ Fixed in 0.31.12026-08-19
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolvi…
Check whether github.com/moby/buildkit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/moby/buildkit CVEs against the assets you own.
Start Free Scan →