CVE-2026-93317

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,9
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

354

Improper Validation of Integrity Check Value

Draft
Common Consequences
Security Scopes Affected:
Integrity Other Non-Repudiation
Potential Impacts:
Modify Application Data Other Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/moby/buildkit/releases/tag/v0.33.1
https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv