Docker BuildKit / Compose Vulnerabilities & Security Advisories
17 advisories tracked · Docker Security (security@docker.com CNA) + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Docker advisory that VulniPulse classified as BuildKit / Compose, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 high, 11 medium, 1 low.
Android app · Google Play
Monitor Docker CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Source
Docker Security (security@docker.com CNA) + NVD
Docker Inc. is its own CVE Numbering Authority. VulniPulse ingests Docker's CVEs from the NVD CNA feed (security@docker.com) — Docker Desktop, Docker CLI, Docker Model Runner and Docker Sandboxes — and merges in the open-source engine components that publish under their own project CNAs (Moby, the Docker Engine upstream; BuildKit; containerd) via a subject-anchored NVD keyword feed that drops the heavy 'third-party app runs in a Docker Compose stack' noise. Docker Desktop / Engine is a near-universal part of every developer and homelab stack.
Latest Docker BuildKit / Compose advisories
Medium [CVE-2026-93321] Docker: malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. Affected product named by the advisory: Docker.
Medium [CVE-2026-93315] Docker: When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup
When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build. Affected product named by the advisory: Docker. Affected product named by the advisory: BuildKit.
Medium [CVE-2026-103433] Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.
Medium [CVE-2026-93326] Docker: build step for a Git source, crafted in a specific way, can bypass some policy validation rules
A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on commit SHA, commit data, or signatures, then all these validations still apply correctly. Affected product named by the advisory: Docker. Affected product named by the advisory: BuildKit.
Medium [CVE-2026-93323] The Dockerfile frontend loaded the Dockerfile and.dockerignore files of a build context into memory without a size limit
The Dockerfile frontend loaded the Dockerfile and.dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.
Medium [CVE-2026-93320] BuildKit may be tricked into performing file actions with special file inodes where regular files are expected
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Medium [CVE-2026-93319] malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
Medium [CVE-2026-93317] Docker: unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest
An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity. Affected product named by the advisory: Docker. Affected product named by the advisory: BuildKit.
Medium [CVE-2026-15792] malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
Medium [CVE-2026-15789] custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
Medium [CVE-2026-15788] BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.