CVE-2026-93316: Moby Buildkit

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.

Affected products

  • Moby Buildkit: before 0.33.1 (fixed in 0.33.1)

Published 2026-10-05. Last modified 2026-10-06.