
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93320 is a vulnerability in Moby BuildKit (the build toolkit underlying Docker) where BuildKit improperly handles special file inodes in build snapshots, allowing it to be tricked into performing file actions with special files where regular files are expected. Affected versions are all releases up to and including v0.33.0; the issue was patched in v0.33.1. It was published on October 5, 2026, with the security advisory authored by maintainer tonistiigi and credited to researcher dzonerzy. The CVSS v4.0 base score is 6.0 (Medium), while the CVSS v3.1 base score is 8.2 (High) (GitHub Advisory, Red Hat CVE).
The root cause is classified under CWE-441 (Unintended Proxy or Intermediary / Confused Deputy) and CWE-66 (Improper Handling of File Names that Identify Virtual Resources). BuildKit fails to properly validate file inode types during snapshot reads and LLB mkfile operations, allowing an attacker to supply a malicious build context containing special files (e.g., device nodes, FIFOs, or sockets) in place of expected regular files. On rootful BuildKit workers, this can cause the daemon to access host device files; on any worker configuration, special files can block or stall file operations, leading to denial of service. The fix in v0.33.1 explicitly rejects special files in daemon-side snapshot reads and safely replaces existing special files in LLB mkfile operations (GitHub Advisory, BuildKit v0.33.1 Release).
On rootful BuildKit workers, successful exploitation can result in unintended access to host device files, enabling high integrity and availability impact on the subsequent (host) system. On all worker configurations, an attacker can supply special files that block file operations, causing denial of service to the build daemon. Confidentiality impact is assessed as none, as the vulnerability does not directly expose sensitive data, but the ability to access host devices on rootful workers could facilitate further privilege escalation or host compromise (GitHub Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, reflecting very low current exploitation probability (Red Hat CVE). The vulnerability requires user interaction (a build must be triggered using a malicious build context) and is not automatable, which limits opportunistic exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability was reported by researcher dzonerzy (GitHub Advisory).
docker build, the BuildKit API, or a CI/CD pipeline that uses BuildKit as its build backend./dev/* device paths from within build processes on rootful workers./dev/sda, /dev/mem) outside of expected container device mappings; build processes hanging indefinitely on file I/O operations.The issue is fixed in BuildKit v0.33.1; all users should upgrade immediately from any version ≤ v0.33.0 (BuildKit v0.33.1 Release). As a workaround, avoid running untrusted builds on vulnerable instances. Running BuildKit in rootless mode mitigates the host device access risk but does not prevent denial-of-service via special file blocking (GitHub Advisory). Additionally, restricting build context sources to trusted inputs and implementing filesystem isolation for build workers reduces the attack surface.
The advisory was published by BuildKit maintainer tonistiigi on September 30, 2026, as part of a broader v0.33.1 security release that addressed nine separate vulnerabilities (BuildKit v0.33.1 Release). Red Hat tracked the issue via Bugzilla (bug #2546036) and published a corresponding CVE advisory (Red Hat CVE). No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."