CVE-2026-93319: Moby Buildkit

Medium severity, CVSS 5.7. EPSS: 0.1% chance of exploitation in the next 30 days.

A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.

Affected products

  • Moby Buildkit: up to and including 0.33.0

Published 2026-10-05. Last modified 2026-10-06.