CVE-2026-93316: Moby Buildkit
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
Affected products
- Moby Buildkit: before 0.33.1 (fixed in 0.33.1)
Published 2026-10-05. Last modified 2026-10-06.