CVE-2026-103433
Received Received - Intake

Docker Buildx Bake Filesystem Access Bypass

Vulnerability report for CVE-2026-103433, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Docker Docker Buildx 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Docker Buildx Bake fails to properly validate filesystem access for certain inputs. An attacker can craft a malicious Bake definition to read arbitrary files or access local OCI image layouts outside the project directory by exploiting path interpretation issues in secrets or entitlement checks.

Detection Guidance

This vulnerability affects Docker Buildx Bake when processing untrusted Bake definitions. To detect it, inspect Bake files for pathless secrets or OCI image layouts that may reference unintended filesystem paths. Check Docker Buildx logs for fs.read approval requests that seem unexpected or misaligned with intended operations.

Impact Analysis

If you run untrusted Bake definitions, this flaw could allow attackers to read sensitive files on your system or access restricted image layouts. This may lead to data leaks or unauthorized access to local resources.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data, potentially leading to data breaches. Organizations handling regulated data (e.g., personal health or financial information) may face penalties for failing to protect such data.

Mitigation Strategies

Avoid running untrusted Bake definitions. Review Docker Buildx configurations to ensure proper fs.read approvals are enforced. Update Docker Buildx to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103433. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart