Security: moby/buildkit
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Git source checkout from a bundle file could lead to command injectionGHSA-hw3h-2gp9-cxpv published
Jul 16, 2026 by tonistiigiModerate -
Possible panic when incorrect parameters sent from frontendGHSA-qx3x-mv6r-52p6 published
Jul 16, 2026 by tonistiigiModerate -
LLB file operation can be tricked to remove /tmp directory contentsGHSA-32pv-7hq5-qhwq published
Jul 16, 2026 by tonistiigiLow -
Malicious client can bypass destination directory validation on local sources uploadGHSA-g2h8-426c-7976 published
Jul 16, 2026 by tonistiigiModerate -
WCOW cache mount source selector resolves NTFS junctions outside of cache rootGHSA-388v-wmr2-g2v2 published
Jul 16, 2026 by tonistiigiModerate -
Possible runtime DoS via unbounded group parsingGHSA-72x6-4j93-7w86 published
Jun 24, 2026 by tonistiigiLow -
Custom frontend could bypass Seccomp/AppArmorGHSA-7236-3392-c5c6 published
Jun 24, 2026 by tonistiigiLow -
Git URL subdir component can cause access to restricted filesGHSA-4vrq-3vrq-g6gg published
Mar 25, 2026 by tonistiigiHigh -
Malicious frontend can cause file escape outside of storage rootGHSA-4c29-8rgm-jvjj published
Mar 25, 2026 by tonistiigiHigh -
Possible race condition with accessing subpaths from cache mountsGHSA-m3r6-h7wv-7xxv published
Jan 31, 2024 by tonistiigiHigh