Data Race Vulnerability in BuildKit by Moby
CVE-2026-93319

5.7MEDIUM

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-93319?

A vulnerability exists in Moby's BuildKit that allows a malicious external BuildKit frontend to exploit the internal API. This exploitation can create conditions for a data race, potentially leading to instability and causing the BuildKit daemon to panic. It is crucial for users to be aware of this issue and update to the patched version to mitigate risks of operational disruptions.

Affected Version(s)

BuildKit 0 <= 0.33.0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Myungyong Lee (https://github.com/2peopledesu)
.