2026-10-05 21:57CVE-2026-93315Docker
PUBLISHED5.2CWE-367

BuildKit proxy CA cleanup can be disrupted by build steps

When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.

Problem type

Affected products

moby

BuildKit

< 0.33.1 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-93315
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-93315",
    "assignerOrgId": "686469e6-3ff6-451b-ab8b-cf5b9e89401e",
    "assignerShortName": "Docker",
    "dateUpdated": "2026-10-05T21:57:08.053Z",
    "dateReserved": "2026-09-17T17:17:25.321Z",
    "datePublished": "2026-10-05T21:57:08.053Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "686469e6-3ff6-451b-ab8b-cf5b9e89401e",
        "shortName": "Docker",
        "dateUpdated": "2026-10-05T21:57:08.053Z"
      },
      "title": "BuildKit proxy CA cleanup can be disrupted by build steps",
      "descriptions": [
        {
          "lang": "en",
          "value": "When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "moby",
          "product": "BuildKit",
          "packageName": "github.com/moby/buildkit",
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0.31.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "0.33.1"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition",
              "cweId": "CWE-367",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/moby/buildkit/releases/tag/v0.33.1",
          "tags": [
            "patch"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "workarounds": [
        {
          "lang": "en",
          "value": "Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected."
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Zhenchen Wang (Institute of Software, Chinese Academy of Sciences), Shuo Huai, Songlin Zhu, Weijie Liu, and Yan Jia (Nankai University)",
          "type": "finder"
        }
      ]
    }
  }
}