CVE-2026-93322: 
Docker vulnerability analysis and mitigation

Overview

CVE-2026-93322 is a Denial of Service vulnerability in Moby BuildKit (buildkitd) where a malicious frontend can submit a crafted LLB (Low-Level Build) definition containing a malformed MergeOp that causes the daemon to panic and terminate, interrupting all active builds. It affects all versions of github.com/moby/buildkit up to and including v0.33.0, and was patched in v0.33.1. The vulnerability was published on October 5, 2026, with the security advisory authored by maintainer tonistiigi and credited to reporter Yanhaoxi. It carries a CVSS v3.1 score of 6.2 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified under CWE-129 (Improper Validation of Array Index) and CWE-248 (Uncaught Exception): the buildkitd daemon fails to validate array index bounds when processing MergeOp inputs in a submitted LLB definition, leading to an unhandled panic and process termination. Specifically, the daemon does not reject malformed LLB merge operations with mismatched input counts, allowing an attacker-controlled frontend to trigger the crash via a crafted LLB payload submitted over the local BuildKit API. Dockerfile builds are explicitly noted as unaffected, as the vulnerability is only reachable through external (potentially untrusted) BuildKit frontends (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation results in a complete Denial of Service of the buildkitd daemon — all builds currently running on the affected daemon are immediately interrupted and terminated. There is no impact to confidentiality or integrity; the vulnerability is availability-only. In CI/CD environments where a single buildkitd instance serves multiple concurrent builds or teams, a single malicious or compromised frontend could disrupt the entire build pipeline (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack vector is local (AV:L), requiring the attacker to have access to submit an LLB definition to the buildkitd daemon, which limits the attack surface to users or processes with local access to the daemon socket (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate a system running buildkitd v0.33.0 or earlier with access to the BuildKit daemon socket (typically /run/buildkit/buildkitd.sock).
  2. Craft malicious LLB definition: Construct a malformed LLB (Low-Level Build) definition containing a MergeOp with mismatched input counts — specifically, an array index that falls outside the expected bounds during MergeOp processing.
  3. Submit via external frontend: Use a custom or malicious BuildKit frontend to submit the crafted LLB definition to the buildkitd daemon via the BuildKit gRPC API (e.g., using the buildctl CLI or a custom Go client targeting the daemon socket).
  4. Trigger daemon panic: The daemon processes the malformed MergeOp, encounters an out-of-bounds array access, and panics, causing buildkitd to terminate and interrupting all active builds on that daemon (GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected panic stack traces in buildkitd logs (e.g., journalctl -u buildkitd or container logs) referencing MergeOp or array index operations; log entries showing abrupt daemon termination without a graceful shutdown message.
  • Process: buildkitd process exiting unexpectedly with a non-zero exit code; all child build processes terminating simultaneously without normal completion.
  • Network/Socket: Sudden loss of connectivity to the BuildKit daemon socket (/run/buildkit/buildkitd.sock); client-side errors such as connection refused or transport is closing immediately following a build submission from an external frontend.
  • Build System: Multiple concurrent builds failing simultaneously with daemon-side errors rather than build-logic errors, particularly after a new or external frontend was used (GitHub Advisory, Red Hat Bugzilla).

Mitigation and workarounds

Upgrade buildkit to v0.33.1 or later, which rejects malformed LLB merge operations with mismatched input counts instead of allowing a daemon panic (BuildKit v0.33.1 Release). As a workaround, avoid using external BuildKit frontends from untrusted sources; Dockerfile builds are unaffected by this vulnerability. Additionally, restrict local access to the buildkitd daemon socket to trusted users only, and monitor buildkitd for unexpected crashes (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Docker vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93318HIGH7.5
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93322MEDIUM6.9
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93323MEDIUM6.8
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93320MEDIUM6
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93319MEDIUM5.7
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management