Database/Container, Kubernetes & orchestration
BuildKit: Crafted upload request lets files escape the BuildKit state directory onto the host
CVSS 6.9CVE-2026-15789Container, Kubernetes & orchestrationcurated
Impact
Crafted upload request lets files escape the BuildKit state directory onto the host
Who can reach it
Anyone with build control API access
What to do
Upgrade BuildKit
References
Related entries
- BuildKit: Git URL credentials in a build request are persisted into the build cache and can be read by other buildsCVE-2023-26054 · BuildKitMedium
- BuildKit: Malicious client or frontend panics the BuildKit daemonCVE-2026-15792 · BuildKitMedium
- BuildKit: NTFS junctions inside the cache root escape the cache mount on Windows container workersCVE-2026-15788 · BuildKitMedium
- BuildKit: Malicious client or frontend crashes the BuildKit daemonCVE-2024-23650 · BuildKitMedium
- BuildKit: Crafted low-level API message deletes the contents of the host /tmpCVE-2026-15791 · BuildKitLow
- BuildKit: "Leaky Vessels": RUN --mount empty-file removal can delete arbitrary host filesCVE-2024-23652 · BuildKitCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.