CVE-2026-93323
Received Received - Intake

Dockerfile Build Context Memory Exhaustion in BuildKit

Vulnerability report for CVE-2026-93323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moby BuildKit 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-93323 is a vulnerability in BuildKit where Dockerfile and .dockerignore files in a build context are loaded into memory without size limits. An oversized file can cause buildkitd to allocate excessive memory, leading to memory exhaustion and daemon termination, disrupting other builds on the same instance.

Detection Guidance

To detect this vulnerability, check the version of BuildKit installed on your system. Run: docker buildx version. If the version is below 0.33.1, the system is vulnerable. Additionally, monitor buildkitd memory usage for unexpected spikes during builds.

Impact Analysis

This vulnerability can cause system downtime by crashing the buildkitd daemon, interrupting ongoing builds, and potentially affecting other services relying on the same instance. It may also lead to denial-of-service conditions if exploited with large files.

Compliance Impact

This vulnerability primarily impacts system availability by causing memory exhaustion in the buildkitd daemon, which could disrupt other builds on the same instance. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, service disruptions could indirectly impact compliance if they affect critical operations.

Mitigation Strategies

Upgrade BuildKit to version 0.33.1 or later. If upgrading is not immediately possible, restrict builds to trusted build contexts and configure buildkitd with memory limits to prevent exhaustion. Avoid using untrusted Dockerfiles or .dockerignore files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93323. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart