Bypass of Policy Validation in Moby BuildKit
CVE-2026-93326

6MEDIUM

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-93326?

A specific configuration of a Git source in Moby BuildKit can circumvent established policy validation rules. This vulnerability allows an attacker to craft a malicious build definition that misrepresents the origin of a repository during the cloning process. Despite this bypass, additional policy checks—such as those based on commit SHA, commit data, or signatures—remain effective and protect against certain malicious actions.

Affected Version(s)

BuildKit 0 <= 0.33.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.