Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CVE-2026-93318: BuildKit and Docker may run attacker code from fake image
CVE-2026-93318 · published 5 days ago
Summary
BuildKit and Docker can be tricked by a malicious container image that pretends its layers are something else. When such an image is processed, later builds may unintentionally use the attacker’s code, potentially exposing secrets or altering the build output. Update to the latest versions or disable shared persistent caches until the fix is applied.
What to do
- Update moby buildkit to version 0.33.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | moby | buildkit | < 0.33.1 |
| Ubuntu:Pro:16.04:LTS | canonical | docker.io | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | docker.io-app | All versions |
Original advisory text
Cache poisoning via unvalidated image layer DiffIDs
A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents.
If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build.
The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.
If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build.
The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.
References
- https://github.com/moby/buildkit/releases/tag/v0.33.1
- https://github.com/moby/buildkit/security/advisories/GHSA-f2v9-hprr-32q3
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93318... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-93318 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-93318 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-93318 Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-354Improper Validation of Integrity Check Value
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen5 Oct 2026
Sources
CVE-2026-93318 · NVD
CVE-2026-93318 · MITRE
CVE-2026-93318 · OSV
GHSA-f2v9-hprr-32q3 · GHSA
UBUNTU-CVE-2026-93318 · OSV
Track software like this
Free during beta