BuildKit User ID Resolution Vulnerability in Moby
CVE-2026-61712

2.3LOW

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-61712?

BuildKit, a Moby toolkit for converting source code to build artifacts, is susceptible to a vulnerability that allows reading of attacker-controlled /etc/passwd and /etc/group files without limits. This flaw occurs during the user ID resolution process, whereby a malicious base image or build can supply oversized files. This behavior leads to excessive memory consumption and can ultimately terminate the BuildKit daemon (buildkitd) due to out-of-memory errors. The issue has been rectified in version 0.31.1.

Affected Version(s)

buildkit < 0.31.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.