CVE-2026-93317
Received Received - Intake

Unauthenticated Registry Blob Digest Mismatch in Docker Build

Vulnerability report for CVE-2026-93317, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moby BuildKit 0.28.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker controlling a registry or OCI-layout blob source to provide blob contents that do not match the claimed digest. The build system caches these blobs under the incorrect digest, which can then be reused in later builds, compromising the integrity of the build inputs.

Detection Guidance

This vulnerability is specific to BuildKit versions v0.28.0 through v0.33.0 and requires low-level LLB API access with direct blob access from a registry. Detection involves checking the BuildKit version in use. Run: docker buildx version or buildctl --version. If the version is between v0.28.0 and v0.33.0, the system is potentially vulnerable.

Impact Analysis

An attacker could inject malicious or incorrect data into your build process by providing unverified blobs. This could lead to compromised builds, data integrity issues, or potential security risks if the malicious data affects the final output or subsequent builds.

Compliance Impact

This vulnerability could impact compliance by undermining data integrity in build processes. For GDPR, it may affect the integrity of processed data. For HIPAA, it could compromise the integrity of healthcare-related builds. Organizations must ensure build integrity to meet compliance requirements for data protection and auditability.

Mitigation Strategies

Upgrade BuildKit to version v0.32.3 or later. For Docker Desktop users, ensure you are on the latest version. For manual installations, update via package manager or download from official releases. Verify the upgrade with docker buildx version or buildctl --version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93317. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart