CVE-2026-93315
5.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:N
Summary
When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| moby | BuildKit | 0.31.0 < 0.33.1 | affected |
Weaknesses
- CWE-367: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
Workarounds
Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected.
References
- https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x
- https://github.com/moby/buildkit/releases/tag/v0.33.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.