Dockerfile Frontend Memory Exhaustion Issue in Moby BuildKit
CVE-2026-93323

6.8MEDIUM

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-93323?

A vulnerability in the Dockerfile frontend of Moby BuildKit allows the loading of Dockerfile and .dockerignore files from the build context into memory without any size limitations. If a build context contains a file that exceeds the size of 16 MiB, it can cause buildkitd to allocate memory proportional to that oversized file. This may result in memory exhaustion, leading to the termination of the daemon and interrupting active builds on the same instance, negatively impacting overall build performance.

Affected Version(s)

BuildKit 0 <= 0.33.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aqueel Ahmed (https://github.com/aqueel707)
.