
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93322 is a Denial of Service vulnerability in Moby BuildKit (buildkitd) where a malicious frontend can submit a crafted LLB (Low-Level Build) definition containing a malformed MergeOp that causes the daemon to panic and terminate, interrupting all active builds. It affects all versions of github.com/moby/buildkit up to and including v0.33.0, and was patched in v0.33.1. The vulnerability was published on October 5, 2026, with the security advisory authored by maintainer tonistiigi and credited to reporter Yanhaoxi. It carries a CVSS v3.1 score of 6.2 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Red Hat).
The root cause is classified under CWE-129 (Improper Validation of Array Index) and CWE-248 (Uncaught Exception): the buildkitd daemon fails to validate array index bounds when processing MergeOp inputs in a submitted LLB definition, leading to an unhandled panic and process termination. Specifically, the daemon does not reject malformed LLB merge operations with mismatched input counts, allowing an attacker-controlled frontend to trigger the crash via a crafted LLB payload submitted over the local BuildKit API. Dockerfile builds are explicitly noted as unaffected, as the vulnerability is only reachable through external (potentially untrusted) BuildKit frontends (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation results in a complete Denial of Service of the buildkitd daemon — all builds currently running on the affected daemon are immediately interrupted and terminated. There is no impact to confidentiality or integrity; the vulnerability is availability-only. In CI/CD environments where a single buildkitd instance serves multiple concurrent builds or teams, a single malicious or compromised frontend could disrupt the entire build pipeline (GitHub Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack vector is local (AV:L), requiring the attacker to have access to submit an LLB definition to the buildkitd daemon, which limits the attack surface to users or processes with local access to the daemon socket (GitHub Advisory, Feedly).
/run/buildkit/buildkitd.sock).buildctl CLI or a custom Go client targeting the daemon socket).panic stack traces in buildkitd logs (e.g., journalctl -u buildkitd or container logs) referencing MergeOp or array index operations; log entries showing abrupt daemon termination without a graceful shutdown message./run/buildkit/buildkitd.sock); client-side errors such as connection refused or transport is closing immediately following a build submission from an external frontend.Upgrade buildkit to v0.33.1 or later, which rejects malformed LLB merge operations with mismatched input counts instead of allowing a daemon panic (BuildKit v0.33.1 Release). As a workaround, avoid using external BuildKit frontends from untrusted sources; Dockerfile builds are unaffected by this vulnerability. Additionally, restrict local access to the buildkitd daemon socket to trusted users only, and monitor buildkitd for unexpected crashes (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."