Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-15789

Опубликовано: 21 июл. 2026
Источник: debian
EPSS Низкий

Описание

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-moby-buildkititppackage

EPSS

Процентиль: 24%
0.00314
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

EPSS

Процентиль: 24%
0.00314
Низкий