CVE-2026-93323: 
Docker vulnerability analysis and mitigation

Overview

CVE-2026-93323 is a memory exhaustion vulnerability in the Dockerfile frontend of moby/buildkit, where Dockerfile and .dockerignore files are loaded into memory without a size limit. An attacker with local access who can supply a malicious build context containing an oversized file can cause buildkitd to allocate unbounded memory, potentially crashing the daemon and interrupting all other builds on the same instance. All versions of github.com/moby/buildkit up to and including v0.33.0 are affected. The vulnerability was published on October 5, 2026, with a fix released in v0.33.1. It carries a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-789 (Memory Allocation with Excessive Size Value): the Dockerfile frontend reads Dockerfile and .dockerignore files from a build context into memory without enforcing any upper bound on file size. An attacker with low privileges who can submit a build context (e.g., via docker build) can craft an oversized Dockerfile or .dockerignore — potentially hundreds of megabytes or larger — causing buildkitd to allocate memory proportional to the file size. The fix enforces a 16 MiB rejection threshold for these files. No public proof-of-concept exploit code has been identified (GitHub Advisory, BuildKit v0.33.1 Release).

Impact

Successful exploitation results in a denial-of-service condition: buildkitd exhausts available memory and terminates, interrupting all concurrent builds on the same daemon instance. There is no impact on confidentiality or integrity — the vulnerability is limited to availability of the build service. In shared CI/CD environments where multiple teams or pipelines rely on a single buildkitd instance, a single malicious or misconfigured build context could disrupt all ongoing build operations (GitHub Advisory).

Exploitability

No in-the-wild exploitation has been reported, and no proof-of-concept code is publicly available. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and low privileges (the ability to submit a build context), and the NVD SSVC assessment classifies it as non-automatable with no known exploitation (GitHub Advisory).

Exploitation steps

  1. Gain build access: Obtain low-privileged access to a system or CI/CD pipeline that submits build contexts to a vulnerable buildkitd instance (v0.33.0 or earlier).
  2. Craft oversized file: Create a Dockerfile or .dockerignore file significantly larger than normal — e.g., a file padded to hundreds of megabytes or gigabytes using tools like dd or a script that generates a large valid Dockerfile.
  3. Submit the build context: Trigger a build using the malicious context, e.g., docker build -f oversized_Dockerfile . or by pushing the context to a CI/CD system that invokes buildkitd.
  4. Exhaust daemon memory: buildkitd reads the oversized file into memory without bounds checking, causing memory allocation to grow proportionally until the system runs out of memory and the daemon is terminated.
  5. Achieve denial of service: All other builds running on the same buildkitd instance are interrupted as the daemon crashes (GitHub Advisory).

Indicators of compromise

  • Logs: buildkitd process logs showing out-of-memory (OOM) errors or unexpected daemon termination; kernel OOM killer logs (dmesg or /var/log/syslog) referencing the buildkitd process.
  • Process: Sudden termination of the buildkitd daemon process; rapid memory growth visible in system monitoring tools (e.g., top, htop, cgroups memory stats) correlated with a build submission.
  • File System: Presence of unusually large Dockerfile or .dockerignore files (>16 MiB) in build context directories or CI/CD artifact storage.
  • Network/Build System: Build jobs submitted by an unexpected or low-privileged user that reference abnormally large build context archives.

Mitigation and workarounds

Upgrade moby/buildkit to v0.33.1 or later, which rejects Dockerfile and .dockerignore files exceeding 16 MiB. As interim workarounds, restrict build context submissions to trusted sources only, and run buildkitd under a cgroup or container memory limit to contain the impact of memory exhaustion to the daemon itself without affecting the host system. Docker Engine users should also check for the corresponding Docker release (docker-v29.8.2) which incorporates this fix (GitHub Advisory, BuildKit v0.33.1 Release).

Community reactions

The advisory was published by maintainer tonistiigi and credited reporter aqueel707 for discovery. The fix was bundled with a broader v0.33.1 security release addressing multiple other vulnerabilities in buildkitd. No significant public commentary or media coverage beyond standard vulnerability tracking sites has been identified (GitHub Advisory, BuildKit v0.33.1 Release).

Additional resources


Source: This report was generated using AI

Related Docker vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93318HIGH7.5
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93322MEDIUM6.9
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93323MEDIUM6.8
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93320MEDIUM6
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026
CVE-2026-93319MEDIUM5.7
  • Docker logoDocker
  • docker.io
NoNoOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management