CVE-2026-93315

Summary

When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.

Affected Software

VendorProductVersion RangeStatus
mobyBuildKit0.31.0 < 0.33.1affected

Weaknesses

  • CWE-367: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition

Workarounds

Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected.

References