CVE-2026-93319
Received Received - Intake

BuildKit Daemon Panic via Malicious Frontend Request

Vulnerability report for CVE-2026-93319, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moby BuildKit 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-567 The product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A malicious external BuildKit frontend can send requests to the internal API, creating a data race condition that causes the BuildKit daemon to crash. This happens due to unsynchronized access to shared data in a multithreaded environment.

Detection Guidance

Detecting this vulnerability requires checking the BuildKit version in use. Run 'buildkitd --version' or check the version in Docker's buildx plugin output. If the version is below v0.33.1, the system is vulnerable.

Impact Analysis

The vulnerability can cause the BuildKit daemon to panic, leading to high availability loss. It requires low privileges and no user interaction, but only affects untrusted external BuildKit frontends.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it primarily causes daemon crashes and availability loss rather than data breaches or unauthorized access. However, repeated daemon crashes could impact system reliability and availability, which may indirectly affect compliance with availability requirements in some standards.

Mitigation Strategies

Upgrade BuildKit to version v0.33.1 or later. Avoid using untrusted external BuildKit frontends. Restart the BuildKit daemon after upgrading to apply fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93319. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart