CVE-2026-93317mediumCWE-354

CVE-2026-93317: medium-severity vulnerability in moby BuildKit

Container blob cache can accept unverified content

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
Affected products
moby · BuildKit