CVE-2026-93318: Cache poisoning via unvalidated image layer DiffIDs

Published Oct 5, 2026
·
Updated

A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents.

If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build.

The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.

Affected Software

1 affected component
Docker BuildKit

Event History

Oct 5, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which BuildKit deployments are most exposed to this issue?

BuildKit daemons that retain or share cache and snapshots across builds are exposed when they process images from different trust contexts. A malicious image must be processed before a later build uses the victim image.

2

What must an attacker be able to do to trigger the cache collision?

The attacker needs to supply an image whose advertised DiffIDs match another image's DiffIDs while its actual layer contents differ. BuildKit must process that malicious image first so its attacker-controlled contents are associated with the derived cache or snapshot identity.

3

Does the issue depend on the snapshotter type?

No. The issue affects regular snapshotters and lazy-pulling snapshotters, including stargz.

4

What is the potential impact on a victim build?

A victim build can mount attacker-controlled layer contents as its base image, potentially causing attacker code to run through a replaced commonly executed path such as /bin/sh. That code may read mounted build secrets, access build resources, modify output artifacts, or hang the build.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203