Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/github.com/moby/buildkit

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-93321 is a medium severity vulnerability in moby BuildKit where improper validation of an array index allows a malicious frontend to submit a crafted LLB definition that causes the buildkitd daemon to panic and terminate. This results in interruption of all builds running on that daemon.

Join the discussion

CVE-2026-93315 is a medium severity vulnerability in moby BuildKit affecting versions from 0.31.0 up to but not including 0.33.1. It involves a time-of-check to time-of-use (TOCTOU) race condition when proxy networking with CA injection is enabled. This flaw allows a build process to modify its CA bundle before cleanup, potentially causing the cleanup operation to block, execute outside the intended build root filesystem, or fail without causing the build itself to fail.

Join the discussion

CVE-2026-93326 is a medium severity vulnerability in moby BuildKit where a specially crafted Git build step can bypass some policy validation rules by making the repository appear to come from a different remote URL during Git clone. However, stricter validations based on commit SHA, commit data, or signatures remain effective.

Join the discussion

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

Join the discussion

A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.

Join the discussion

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

Join the discussion

A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.

Join the discussion

A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.

Join the discussion

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

Join the discussion

If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.

Join the discussion

Showing 1 to 10 of 19 results

Filters:Package: pkg:github/github.com/moby/buildkit
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses