CVE-2026-93317

Summary

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

Affected Software

VendorProductVersion RangeStatus
mobyBuildKit0.28.0 < 0.33.1affected

Weaknesses

  • CWE-354: CWE-354: Improper Validation of Integrity Check Value

Workarounds

The issue only affects the low-level LLB API with direct blob access from the registry. It can't be reached with Dockerfile builds.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References