CVE-2026-15792: Possible panic when incorrect parameters sent from frontend
Published Jul 21, 2026
·Updated
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
Affected Software
2 affected components
Moby BuildKit
Mobyproject Buildkit<0.31.2
Event History
Jul 21, 2026
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15792?
The severity of CVE-2026-15792 is medium with a CVSS score of 4.0.
2
How do I fix CVE-2026-15792?
To fix CVE-2026-15792, ensure that you are using the latest version of Moby BuildKit, which includes the necessary input validation improvements.
3
What are the potential risks of CVE-2026-15792?
The risks of CVE-2026-15792 include the possibility of the BuildKit daemon crashing if it receives crafted input from a malicious client.
4
When was CVE-2026-15792 published?
CVE-2026-15792 was published on July 21, 2026.
5
What type of vulnerability is CVE-2026-15792 classified as?
CVE-2026-15792 is classified as an input validation vulnerability.