CVE-2026-33748
- EPSS 0.03%
- Veröffentlicht 27.03.2026 14:00:21
- Zuletzt bearbeitet 20.04.2026 12:37:46
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checke...
CVE-2026-33747
- EPSS 0.06%
- Veröffentlicht 27.03.2026 01:16:21
- Zuletzt bearbeitet 01.04.2026 14:34:48
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be writt...
CVE-2024-23651
- EPSS 0.55%
- Veröffentlicht 31.01.2024 22:15:54
- Zuletzt bearbeitet 21.11.2024 08:58:05
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lea...
CVE-2024-23652
- EPSS 5.7%
- Veröffentlicht 31.01.2024 22:15:54
- Zuletzt bearbeitet 21.11.2024 08:58:05
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the moun...
CVE-2024-23653
- EPSS 10.3%
- Veröffentlicht 31.01.2024 22:15:54
- Zuletzt bearbeitet 21.11.2024 08:58:05
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built ima...
CVE-2024-23650
- EPSS 0.11%
- Veröffentlicht 31.01.2024 22:15:53
- Zuletzt bearbeitet 21.11.2024 08:58:05
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue h...
CVE-2023-26054
- EPSS 1.03%
- Veröffentlicht 06.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:50:40
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains credentials and the build creates a ...