Skip to content
VulniPulse

Docker BuildKit / Compose Vulnerabilities & Security Advisories

5 advisories tracked · Docker Security (security@docker.com CNA) + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Docker advisory that VulniPulse classified as BuildKit / Compose, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 high, 3 medium, 1 low.

Android app · Google Play

Monitor Docker CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Docker Security (security@docker.com CNA) + NVD

Docker Inc. is its own CVE Numbering Authority. VulniPulse ingests Docker's CVEs from the NVD CNA feed (security@docker.com) — Docker Desktop, Docker CLI, Docker Model Runner and Docker Sandboxes — and merges in the open-source engine components that publish under their own project CNAs (Moby, the Docker Engine upstream; BuildKit; containerd) via a subject-anchored NVD keyword feed that drops the heavy 'third-party app runs in a Docker Compose stack' noise. Docker Desktop / Engine is a near-universal part of every developer and homelab stack.

Latest Docker BuildKit / Compose advisories

High7.3Docker Updated

High [CVE-2026-15793] BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

CVE-2026-15793
BuildKit / Compose
Jul 21, 2026
Medium6.0Docker Updated

Medium [CVE-2026-15792] malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

CVE-2026-15792
BuildKit / Compose
Jul 21, 2026
Medium6.9Docker Updated

Medium [CVE-2026-15789] custom client can produce such an upload request to the BuildKit daemon that files

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

CVE-2026-15789
BuildKit / Compose
Jul 21, 2026
Low1.8Docker Updated

Low [CVE-2026-15791] crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.

CVE-2026-15791
BuildKit / Compose
Jul 21, 2026
Medium5.6Docker

Medium [CVE-2026-15788] BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions…

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

CVE-2026-15788
BuildKit / Compose
Jul 20, 2026

← All Docker advisories