CVE-2026-93315 PUBLISHED

BuildKit proxy CA cleanup can be disrupted by build steps

Assigner: Docker
Reserved: 17.09.2026 Published: 05.10.2026 Updated: 06.10.2026

When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:N
CVSS Score: 5.8

Product Status

Vendor moby
Product BuildKit
Versions Default: unaffected
  • affected from 0.31.0 to 0.33.1 (excl.)

Workarounds

Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected.

Credits

  • Zhenchen Wang (Institute of Software, Chinese Academy of Sciences), Shuo Huai, Songlin Zhu, Weijie Liu, and Yan Jia (Nankai University) finder

References

Problem Types

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition CWE