BuildKit User ID Resolution Vulnerability in Moby
CVE-2026-61712
2.3LOW
What is CVE-2026-61712?
BuildKit, a Moby toolkit for converting source code to build artifacts, is susceptible to a vulnerability that allows reading of attacker-controlled /etc/passwd and /etc/group files without limits. This flaw occurs during the user ID resolution process, whereby a malicious base image or build can supply oversized files. This behavior leads to excessive memory consumption and can ultimately terminate the BuildKit daemon (buildkitd) due to out-of-memory errors. The issue has been rectified in version 0.31.1.
Affected Version(s)
buildkit < 0.31.1
