CVE-2026-93315: Moby Buildkit
Medium severity, CVSS 5.8. EPSS: 0.1% chance of exploitation in the next 30 days.
When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.
Affected products
- Moby Buildkit: from 0.31.0, before 0.33.1 (fixed in 0.33.1)
Published 2026-10-05. Last modified 2026-10-06.