CVE-2024-23650: Mobyproject Buildkit

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

Affected products

Published 2024-01-31. Last modified 2026-06-17.