Database/Container, Kubernetes & orchestration
Docker Buildx Bake: untrusted Bake definition reads files outside the project without approval
Impact
Bake fails to request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable client-side file through a pathless secret whose ID is treated as a pathname, or consume a local OCI image layout outside the project because entitlement validation checks a different representation of the path than the one that gets used. On a CI runner or an operator workstation that builds container images for a GPU fleet, that means a pull-request-supplied Bake file can read registry credentials, kubeconfigs or cloud tokens off the build host without the confirmation prompt that is supposed to gate it. Only users who run untrusted Bake definitions are affected.
Who can reach it
Anyone who can supply the Bake definition a user or CI job then builds - typically a repository contributor. Requires the victim to run the build; no privileges on the host are needed.
What to do
Upgrade Docker Buildx to v0.37.2. Until then, do not run bake on definitions from untrusted sources, and run builds that must handle untrusted definitions on a throwaway runner with no credentials on disk.
References
Related entries
- Crossplane runtime: time-of-check/time-of-use in xpkg ImageConfig resolutionCVE-2026-105163 · Crossplane crossplane-runtime (xpkg client ImageConfig lookup)Medium
- BuildKit: Crafted upload request lets files escape the BuildKit state directory onto the hostCVE-2026-15789 · BuildKitMedium
- Istio: Envoy RBAC header matching flaw bypasses header-based authorization policyCVE-2026-31838 · IstioMedium
- containerd: crafted OCI image index exhausts node CPU and memory during image pullCVE-2026-53493 · containerd (OCI index graph handling in PullImage)Medium
- Kyverno: unvalidated ServiceCall URL turns the cluster-wide ServiceAccount into a confused deputyCVE-2026-84199 · Kyverno admission controller (APICall ServiceCall URL field)Medium
- NGINX: HTTP/3 handshake can overflow a heap buffer in the worker, restarting it or corrupting dataCVE-2026-90439 · NGINX ngx_http_v3_module (HTTP/3 TLS handshake with OpenSSL <= 3.5.0)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.