CVE-2026-93317

moby BuildKit

Published 5 Oct 2026 · updated 5 Oct 2026 · Received

5.9 Medium · CVSS 4.0, docker.com

Description

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

References