github.com/moby/buildkit
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/moby/buildkitpage 1 of 1
- CVE-2023-26054MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.11.42023-03-06
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains credentials and the build…
- CVE-2024-23650MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. …
- CVE-2024-23651HIGHCVSS 8.7EG 8.7✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition t…
- CVE-2024-23652CRITICALCVSS 10.0EG 10.0✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created f…
- CVE-2024-23653CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.12.52024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based o…
- CVE-2026-33748HIGHCVSS 7.5EG 7.5✓ Fixed in 0.28.12026-03-27
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside…
Check whether github.com/moby/buildkit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/moby/buildkit CVEs against the assets you own.
Start Free Scan →