CVE-2026-93319

NameCVE-2026-93319
DescriptionA malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1094971

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-moby-buildkitITP1094971

Notes

https://github.com/moby/buildkit/security/advisories/GHSA-4hgw-qrhw-fhg8
check security impact on docker.io

Search for package or bug name: Reporting problems