Registry and OCI-Layout Blob Source Vulnerability in Moby BuildKit
CVE-2026-93317

5.9MEDIUM

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-93317?

An unauthenticated attacker exploiting this vulnerability could manipulate a registry or OCI-layout blob source to provide blob contents that mismatch the claimed digest. This mismatch could potentially lead to a cached snapshot being reused in subsequent victim builds, thereby undermining the integrity of build inputs. This means that an attacker could subvert the build process without any credentials, posing a serious risk to systems relying on the integrity of their build environments. Users are strongly urged to update to the latest version of Moby BuildKit to mitigate this risk.

Affected Version(s)

BuildKit 0.28.0 < 0.33.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

He Wei (https://github.com/hewei-gikaku)
Haoxiang Yan (https://github.com/Yanhaoxi)
.