Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-33747

4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
EPSS: Низкий
redhat логотип

CVE-2026-33747

4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-33747

4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
EPSS: Низкий
debian логотип

CVE-2026-33747

4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in ...

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4c29-8rgm-jvjj

4 месяца назад

BuildKit's Malicious frontend can cause file escape outside of storage root

CVSS3: 8.4
EPSS: Низкий
fstec логотип

BDU:2026-07149

4 месяца назад

Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20814-1

2 месяца назад

Security update for docker-stable

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2120-1

2 месяца назад

Security update for docker-stable

EPSS: Низкий
redos логотип

ROS-20260430-73-0004

3 месяца назад

Уязвимость buildkit

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2578-1

около 1 месяца назад

Security update for docker-stable

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20702-1

3 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20809-1

3 месяца назад

Security update for trivy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.2
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in ...

CVSS3: 8.4
0%
Низкий
4 месяца назад
github логотип
GHSA-4c29-8rgm-jvjj

BuildKit's Malicious frontend can cause file escape outside of storage root

CVSS3: 8.4
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07149

Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20814-1

Security update for docker-stable

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2120-1

Security update for docker-stable

2 месяца назад
redos логотип
ROS-20260430-73-0004

Уязвимость buildkit

CVSS3: 9.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2578-1

Security update for docker-stable

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20702-1

Security update for trivy

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20809-1

Security update for trivy

3 месяца назад

Уязвимостей на страницу