Registry and OCI-Layout Blob Source Vulnerability in Moby BuildKit
CVE-2026-93317
5.9MEDIUM
What is CVE-2026-93317?
An unauthenticated attacker exploiting this vulnerability could manipulate a registry or OCI-layout blob source to provide blob contents that mismatch the claimed digest. This mismatch could potentially lead to a cached snapshot being reused in subsequent victim builds, thereby undermining the integrity of build inputs. This means that an attacker could subvert the build process without any credentials, posing a serious risk to systems relying on the integrity of their build environments. Users are strongly urged to update to the latest version of Moby BuildKit to mitigate this risk.
Affected Version(s)
BuildKit 0.28.0 < 0.33.1
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
He Wei (https://github.com/hewei-gikaku)
Haoxiang Yan (https://github.com/Yanhaoxi)
