CVE-2026-93320
Received Received - Intake

BuildKit Special File Inode Handling Vulnerability

Vulnerability report for CVE-2026-93320, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moby BuildKit 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. This can block operations or, on rootful workers, allow unintended host device access. The issue affects versions up to v0.33.0 and is patched in v0.33.1 and later.

Detection Guidance

Check BuildKit version with 'buildkitd --version' or 'docker buildx version'. If version is below v0.33.1, the system is vulnerable. Inspect build snapshots for unusual file operations or blocked actions.

Impact Analysis

It may cause blocked operations or unintended host device access if running in rootful mode. Rootless mode reduces device access risks but does not prevent denial of service attacks.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA by potentially allowing unauthorized access to host devices or sensitive data during build processes. Rootful workers are particularly at risk of unintended host device access, which could violate data protection requirements. Rootless mode reduces but does not eliminate risks, as denial of service remains possible.

Mitigation Strategies

Upgrade BuildKit to v0.33.1 or later. If using Docker, update to a patched version. Avoid rootful mode if possible. Monitor for blocked operations or unexpected device access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93320. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart