CVE-2026-93319: A malicious frontend can cause a daemon panic
Published Oct 5, 2026
·Updated
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
Affected Software
1 affected component
Moby BuildKit
Event History
Oct 5, 2026
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionWeakness
Frequently Asked Questions
1
Which BuildKit deployments should be prioritized for triage?
Prioritize deployments that use external BuildKit frontends, particularly where a malicious or untrusted frontend could be supplied. The issue is associated with requests made through the internal API.
2
What does an attacker need to trigger the issue?
An attacker needs to control a malicious external BuildKit frontend and have it send requests using the internal API. Those requests can create a data-race condition that causes the BuildKit daemon to panic.