Description
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
Published: 2026-10-05
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via daemon crash
Action: Limit Frontend Use
AI Analysis

Impact

A malicious BuildKit frontend can issue calls to the internal API, creating a data race that triggers a panic in the BuildKit daemon. The result is a crash that stops all ongoing builds and can potentially disrupt availability of the infrastructure that relies on BuildKit. The vulnerability is a CWE‑567 race condition that affects concurrency control within the daemon.

Affected Systems

The issue affects the moby BuildKit product, wherever it is deployed. Any installation that uses external frontends is vulnerable; Dockerfile builds that rely solely on the built‑in frontend remain unaffected. No specific version ranges are defined in the advisory, so all current builds that accept external frontends should be considered at risk.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker who can supply or influence an external frontend for the BuildKit daemon, making the threat primarily internal or supply‑chain oriented. Given the lack of public exploitation evidence and the moderate score, the overall risk is considered moderate but should be mitigated promptly.

Generated by OpenCVE AI on October 5, 2026 at 20:16 UTC.

Remediation

Vendor Workaround

Avoid using external BuildKit frontends from untrusted sources. Dockerfile builds are unaffected.


OpenCVE Recommended Actions

  • Avoid using external BuildKit frontends from untrusted sources; use only the built‑in Dockerfile frontend.
  • Restrict BuildKit daemon communication to trusted users or networks, for example by configuring firewall rules or operating within a sandboxed environment.
  • Set the daemon to a read‑only or restricted mode when interacting with unverified frontends, limiting the impact of a panic.
  • Monitor daemon logs for panic events and plan to upgrade to future BuildKit releases that address this issue.

Generated by OpenCVE AI on October 5, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
Title A malicious frontend can cause a daemon panic
Weaknesses CWE-567
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T19:07:12.038Z

Reserved: 2026-09-17T17:17:56.112Z

Link: CVE-2026-93319

cve-icon Vulnrichment

Updated: 2026-10-05T19:07:08.255Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:38.217

Modified: 2026-10-05T20:17:28.410

Link: CVE-2026-93319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses
  • CWE-567

    Unsynchronized Access to Shared Data in a Multithreaded Context