
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93323 is a memory exhaustion vulnerability in the Dockerfile frontend of moby/buildkit, where Dockerfile and .dockerignore files are loaded into memory without a size limit. An attacker with local access who can supply a malicious build context containing an oversized file can cause buildkitd to allocate unbounded memory, potentially crashing the daemon and interrupting all other builds on the same instance. All versions of github.com/moby/buildkit up to and including v0.33.0 are affected. The vulnerability was published on October 5, 2026, with a fix released in v0.33.1. It carries a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory).
The root cause is classified as CWE-789 (Memory Allocation with Excessive Size Value): the Dockerfile frontend reads Dockerfile and .dockerignore files from a build context into memory without enforcing any upper bound on file size. An attacker with low privileges who can submit a build context (e.g., via docker build) can craft an oversized Dockerfile or .dockerignore — potentially hundreds of megabytes or larger — causing buildkitd to allocate memory proportional to the file size. The fix enforces a 16 MiB rejection threshold for these files. No public proof-of-concept exploit code has been identified (GitHub Advisory, BuildKit v0.33.1 Release).
Successful exploitation results in a denial-of-service condition: buildkitd exhausts available memory and terminates, interrupting all concurrent builds on the same daemon instance. There is no impact on confidentiality or integrity — the vulnerability is limited to availability of the build service. In shared CI/CD environments where multiple teams or pipelines rely on a single buildkitd instance, a single malicious or misconfigured build context could disrupt all ongoing build operations (GitHub Advisory).
No in-the-wild exploitation has been reported, and no proof-of-concept code is publicly available. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and low privileges (the ability to submit a build context), and the NVD SSVC assessment classifies it as non-automatable with no known exploitation (GitHub Advisory).
buildkitd instance (v0.33.0 or earlier)..dockerignore file significantly larger than normal — e.g., a file padded to hundreds of megabytes or gigabytes using tools like dd or a script that generates a large valid Dockerfile.docker build -f oversized_Dockerfile . or by pushing the context to a CI/CD system that invokes buildkitd.buildkitd reads the oversized file into memory without bounds checking, causing memory allocation to grow proportionally until the system runs out of memory and the daemon is terminated.buildkitd instance are interrupted as the daemon crashes (GitHub Advisory).buildkitd process logs showing out-of-memory (OOM) errors or unexpected daemon termination; kernel OOM killer logs (dmesg or /var/log/syslog) referencing the buildkitd process.buildkitd daemon process; rapid memory growth visible in system monitoring tools (e.g., top, htop, cgroups memory stats) correlated with a build submission..dockerignore files (>16 MiB) in build context directories or CI/CD artifact storage.Upgrade moby/buildkit to v0.33.1 or later, which rejects Dockerfile and .dockerignore files exceeding 16 MiB. As interim workarounds, restrict build context submissions to trusted sources only, and run buildkitd under a cgroup or container memory limit to contain the impact of memory exhaustion to the daemon itself without affecting the host system. Docker Engine users should also check for the corresponding Docker release (docker-v29.8.2) which incorporates this fix (GitHub Advisory, BuildKit v0.33.1 Release).
The advisory was published by maintainer tonistiigi and credited reporter aqueel707 for discovery. The fix was bundled with a broader v0.33.1 security release addressing multiple other vulnerabilities in buildkitd. No significant public commentary or media coverage beyond standard vulnerability tracking sites has been identified (GitHub Advisory, BuildKit v0.33.1 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."