github.com/moby/buildkit
concurrent, cache-efficient, and Dockerfile-agnostic builder toolkit
Activity
- Latest release
- 5d ago
- Total releases
- 50
- Cadence
- ~41 days
- Last 12 months
- 14
Reach
- Stars
- 10.2k
Details
- First release
- Oct 31, 2018
| Version | Released | |
|---|---|---|
v0.32.0
minor
|
v0.32.0
minor
Dependencies (113)
+ 105 more |
|
v0.32.0-rc2
pre
|
v0.32.0-rc2
pre
Dependencies (113)
+ 105 more |
|
v0.31.2
patch
|
v0.31.2
patch
Dependencies (113)
+ 105 more |
|
v0.31.0
minor
|
v0.31.0
minor
Dependencies (113)
+ 105 more |
|
v0.31.0-rc2
pre
|
v0.31.0-rc2
pre
Dependencies (113)
+ 105 more |
|
v0.31.0-rc1
pre
|
v0.31.0-rc1
pre
Dependencies (113)
+ 105 more |
|
v0.30.0
minor
|
v0.30.0
minor
Dependencies (112)
+ 104 more |
|
v0.30.0-rc2
pre
|
v0.30.0-rc2
pre
Dependencies (112)
+ 104 more |
|
v0.29.0
minor
|
v0.29.0
minor
Dependencies (110)
+ 102 more |
|
v0.28.0
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (110)
+ 102 more |
|
v0.28.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.28.0-rc2
pre
Dependencies (110)
+ 102 more |
|
v0.27.0-rc1
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.27.0-rc1
pre
Dependencies (110)
+ 102 more |
|
v0.26.2
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.26.2
minor
Dependencies (109)
+ 101 more |
|
v0.25.2
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.25.2
minor
Dependencies (106)
+ 98 more |
|
v0.24.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.24.0-rc2
pre
Dependencies (106)
+ 98 more |
|
v0.23.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.23.0-rc2
pre
Dependencies (108)
+ 100 more |
|
v0.23.0-rc1
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.23.0-rc1
pre
Dependencies (108)
+ 100 more |
|
v0.21.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.21.0-rc2
pre
Dependencies (107)
+ 99 more |
|
v0.20.0-rc3
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.20.0-rc3
pre
Dependencies (106)
+ 98 more |
|
v0.19.0-rc1
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.19.0-rc1
pre
Dependencies (104)
+ 96 more |
|
v0.17.2
patch
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.17.2
patch
Dependencies (102)
+ 94 more |
|
v0.18.0-rc1
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.18.0-rc1
pre
Dependencies (102)
+ 94 more |
|
v0.17.0
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (102)
+ 94 more |
|
v0.16.0
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (101)
+ 93 more |
|
v0.16.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.16.0-rc2
pre
Dependencies (101)
+ 93 more |
|
v0.15.1
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.15.1
minor
Dependencies (100)
+ 92 more |
|
v0.14.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.14.0-rc2
pre
Dependencies (97)
+ 89 more |
|
v0.13.0
minor
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (98)
+ 90 more |
|
v0.13.0-rc2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.13.0-rc2
pre
Dependencies (98)
+ 90 more |
|
v0.13.0-rc1
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.13.0-rc1
pre
Dependencies (97)
+ 89 more |
|
v0.13.0-beta3
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.13.0-beta3
pre
Dependencies (97)
+ 89 more |
|
v0.13.0-beta2
pre
2 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev |
v0.13.0-beta2
pre
Dependencies (97)
+ 89 more |
|
v0.12.4
patch
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.12.4
patch
Dependencies (87)
+ 79 more |
|
v0.12.1
minor
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.12.1
minor
Dependencies (87)
+ 79 more |
|
v0.11.4
patch
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.11.4
patch
Dependencies (84)
+ 76 more |
|
v0.11.3
patch
7 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-26054
GHSA-gc89-7gcr-jxqc
Mar 07, 2023
Buildkit credentials inlined to Git URLs could end up in provenance attestation
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
When the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways:
Equivalent in
Thanks to Oscar Alberto Tovar for discovering the issue. ImpactWhen a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in Note: Docker Build-push Github action builds from Git URLs by default but is not affected by this issue even when working with private repositories because the credentials are passed with build secrets and not with URLs. PatchesBug is fixed in v0.11.4 . WorkaroundsIt is recommended to pass credentials with build secrets when building directly from Git URL as a more secure alternative than modifying the URL. In Docker Buildx, VCS info hint can be disabled by setting References
Fixed in
0.11.4
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.11.3
patch
Dependencies (84)
+ 76 more |
|
v0.11.1
minor
7 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-26054
GHSA-gc89-7gcr-jxqc
Mar 07, 2023
Buildkit credentials inlined to Git URLs could end up in provenance attestation
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
When the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways:
Equivalent in
Thanks to Oscar Alberto Tovar for discovering the issue. ImpactWhen a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in Note: Docker Build-push Github action builds from Git URLs by default but is not affected by this issue even when working with private repositories because the credentials are passed with build secrets and not with URLs. PatchesBug is fixed in v0.11.4 . WorkaroundsIt is recommended to pass credentials with build secrets when building directly from Git URL as a more secure alternative than modifying the URL. In Docker Buildx, VCS info hint can be disabled by setting References
Fixed in
0.11.4
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.11.1
minor
Dependencies (84)
+ 76 more |
|
v0.11.0-rc4
pre
7 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-26054
GHSA-gc89-7gcr-jxqc
Mar 07, 2023
Buildkit credentials inlined to Git URLs could end up in provenance attestation
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
When the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways:
Equivalent in
Thanks to Oscar Alberto Tovar for discovering the issue. ImpactWhen a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in Note: Docker Build-push Github action builds from Git URLs by default but is not affected by this issue even when working with private repositories because the credentials are passed with build secrets and not with URLs. PatchesBug is fixed in v0.11.4 . WorkaroundsIt is recommended to pass credentials with build secrets when building directly from Git URL as a more secure alternative than modifying the URL. In Docker Buildx, VCS info hint can be disabled by setting References
Fixed in
0.11.4
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.11.0-rc4
pre
Dependencies (84)
+ 76 more |
|
v0.11.0-rc2
pre
7 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-26054
GHSA-gc89-7gcr-jxqc
Mar 07, 2023
Buildkit credentials inlined to Git URLs could end up in provenance attestation
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
When the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways:
Equivalent in
Thanks to Oscar Alberto Tovar for discovering the issue. ImpactWhen a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in Note: Docker Build-push Github action builds from Git URLs by default but is not affected by this issue even when working with private repositories because the credentials are passed with build secrets and not with URLs. PatchesBug is fixed in v0.11.4 . WorkaroundsIt is recommended to pass credentials with build secrets when building directly from Git URL as a more secure alternative than modifying the URL. In Docker Buildx, VCS info hint can be disabled by setting References
Fixed in
0.11.4
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.11.0-rc2
pre
Dependencies (84)
+ 76 more |
|
v0.10.6
patch
7 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-26054
GHSA-gc89-7gcr-jxqc
Mar 07, 2023
Buildkit credentials inlined to Git URLs could end up in provenance attestation
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
When the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways:
Equivalent in
Thanks to Oscar Alberto Tovar for discovering the issue. ImpactWhen a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in Note: Docker Build-push Github action builds from Git URLs by default but is not affected by this issue even when working with private repositories because the credentials are passed with build secrets and not with URLs. PatchesBug is fixed in v0.11.4 . WorkaroundsIt is recommended to pass credentials with build secrets when building directly from Git URL as a more secure alternative than modifying the URL. In Docker Buildx, VCS info hint can be disabled by setting References
Fixed in
0.11.4
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.10.6
patch
Dependencies (71)
+ 63 more |
|
v0.10.4
minor
7 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-26054
GHSA-gc89-7gcr-jxqc
Mar 07, 2023
Buildkit credentials inlined to Git URLs could end up in provenance attestation
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
When the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways:
Equivalent in
Thanks to Oscar Alberto Tovar for discovering the issue. ImpactWhen a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in Note: Docker Build-push Github action builds from Git URLs by default but is not affected by this issue even when working with private repositories because the credentials are passed with build secrets and not with URLs. PatchesBug is fixed in v0.11.4 . WorkaroundsIt is recommended to pass credentials with build secrets when building directly from Git URL as a more secure alternative than modifying the URL. In Docker Buildx, VCS info hint can be disabled by setting References
Fixed in
0.11.4
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.10.4
minor
Dependencies (71)
+ 63 more |
|
v0.10.0-rc1
pre
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.10.0-rc1
pre
Dependencies (70)
+ 62 more |
|
v0.9.1
minor
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.9.1
minor
Dependencies (63)
+ 55 more |
|
v0.9.0-rc2
pre
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.9.0-rc2
pre
Dependencies (63)
+ 55 more |
|
v0.8.2
minor
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.8.2
minor
Dependencies (55)
+ 47 more |
|
v0.8.0-rc3
pre
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.8.0-rc3
pre
Dependencies (54)
+ 46 more |
|
v0.7.1
minor
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.7.1
minor
Dependencies (50)
+ 42 more |
|
v0.6.4
patch
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.4
patch
Dependencies (49)
+ 41 more |
|
v0.6.3
minor
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.3
minor
Dependencies (49)
+ 41 more |
|
v0.3.2
initial
6 CVEs
CVE-2026-33747
GO-2026-4858
GHSA-4c29-8rgm-jvjj
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2026-33748
GO-2026-4859
GHSA-4vrq-3vrq-g6gg
Mar 27, 2026
BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit Fixed in
0.28.1
References Updated Mar 28, 2026 · Source: OSV.dev
CVE-2024-23651
GO-2024-2493
GHSA-m3r6-h7wv-7xxv
Feb 13, 2024
Host system file access in github.com/moby/buildkit Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23650
GO-2024-2492
GHSA-9p26-698r-w4hx
Feb 12, 2024
Panic in github.com/moby/buildkit A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic. Fixed in
0.12.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23652
GO-2024-2494
GHSA-4v98-7qmw-rqr8
Feb 12, 2024
Host system modification in github.com/moby/buildkit A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-23653
GO-2024-2497
GHSA-wr6v-9f75-vh2g
Feb 07, 2024
Privilege escalation in github.com/moby/buildkit BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. Fixed in
0.12.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.3.2
initial
|