CVE-2026-93315: Moby Buildkit

Medium severity, CVSS 5.8. EPSS: 0.1% chance of exploitation in the next 30 days.

When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.

Affected products

  • Moby Buildkit: from 0.31.0, before 0.33.1 (fixed in 0.33.1)

Published 2026-10-05. Last modified 2026-10-06.