CVE-2026-93317: Moby Buildkit
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
Affected products
- Moby Buildkit: from 0.28.0, before 0.33.1 (fixed in 0.33.1)
Published 2026-10-05. Last modified 2026-10-06.