CVE-2026-93322: Malformed MergeOp can crash the BuildKit daemon
Published Oct 5, 2026
·Updated
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
Affected Software
1 affected component
Docker BuildKit
Event History
Oct 5, 2026
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs to be able to submit a malicious LLB definition through a BuildKit frontend. The described impact is a panic that terminates buildkitd and interrupts all builds running on that daemon.
2
What is the operational impact if exploitation succeeds?
The BuildKit daemon crashes and terminates. Any builds running on that same daemon are interrupted.
3
Which release addresses the issue?
The provided release reference identifies BuildKit v0.33.1.