CVE-2026-93315
Received Received - Intake

Proxy Networking CA Injection in Docker Build

Vulnerability report for CVE-2026-93315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moby BuildKit 0.31.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs when proxy networking with CA injection is enabled in a build. The build can modify its CA bundle before cleanup, which may cause the cleanup process to block, operate outside the build rootfs, or fail without failing the build itself.

Impact Analysis

This vulnerability may lead to incomplete or improper cleanup of build environments, potentially leaving residual files or configurations outside the intended build directory. This could cause unintended side effects in subsequent builds or expose sensitive data.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to build system operations rather than data handling or security controls.

Mitigation Strategies

Disable proxy networking with CA injection in BuildKit configurations. Ensure CA bundle modifications are properly isolated and cleaned up after build operations to prevent blocking or unintended filesystem access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart