CVE-2026-93326
Received Received - Intake

Git Build Step Policy Bypass via Malicious Remote URL

Vulnerability report for CVE-2026-93326, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Docker Inc.

Description

A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on commit SHA, commit data, or signatures, then all these validations still apply correctly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moby BuildKit 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-180 The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a build step for a Git source that can bypass policy validation rules. A malicious build definition can make a repository appear to come from a different remote URL than it actually is during Git clone operations. Stricter validations based on commit SHA, commit data, or signatures remain unaffected.

Detection Guidance

This vulnerability involves Git source build steps bypassing policy validation by manipulating repository URLs during Git clone. To detect it, inspect build definitions for unusual remote URLs or Git operations. Check logs for Git clone commands with unexpected repository paths or URLs. Validate commit SHAs and signatures against known trusted sources.

Impact Analysis

The impact includes potential unauthorized access or manipulation of repositories if policy validations are bypassed. Attackers could trick systems into accepting code from untrusted sources, leading to supply chain risks or compromised builds.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR or HIPAA if policy validation rules are bypassed during Git source builds. If stricter validations based on commit SHA, data, or signatures are not enforced, it may lead to unauthorized or unvalidated code being integrated, which could violate data protection or security requirements.

Mitigation Strategies

Update to the latest version of BuildKit to ensure policy validation rules are correctly enforced. Review build definitions for suspicious remote URLs or Git configurations. Validate commits using SHA, signatures, or other strict methods as per your policy.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93326. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart