Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby buildkit |
|
| Vendors & Products |
Moby
Moby buildkit |
Mon, 05 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build. | |
| Title | BuildKit proxy CA cleanup can be disrupted by build steps | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T21:57:08.053Z
Reserved: 2026-09-17T17:17:25.321Z
Link: CVE-2026-93315
No data.
Status : Received
Published: 2026-10-05T22:16:58.820
Modified: 2026-10-05T22:16:58.820
Link: CVE-2026-93315
No data.
OpenCVE Enrichment
Updated: 2026-10-05T23:30:14Z