Proxy Networking Vulnerability in BuildKit by Moby
CVE-2026-93315
5.8MEDIUM
What is CVE-2026-93315?
This vulnerability arises when proxy networking capabilities are enabled alongside CA injection, allowing builds to manipulate their CA bundle prior to the necessary cleanup. As a result, this situation may cause the cleanup process to hang, operate outside of the intended build root file system, or fail without an associated failure notification for the build itself. It is imperative for users to be aware of this issue to mitigate potential risks to their build processes.
Affected Version(s)
BuildKit Linux 0.31.0 < 0.33.1
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhenchen Wang (Institute of Software, Chinese Academy of Sciences), Shuo Huai, Songlin Zhu, Weijie Liu, and Yan Jia (Nankai University)
