Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Buildkit HIGH 7.5
CVE-2026-15792

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

Fix: 0.31.2+
Fix from $1,950 2026-07-21
Buildkit HIGH 7.5
CVE-2026-15793

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is …

Fix: 0.31.2+
Fix from $1,950 2026-07-21
Buildkit HIGH 7.5
CVE-2026-15789

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The cli…

Fix: 0.31.2+
Fix from $1,950 2026-07-21
Buildkit HIGH 7.5
CVE-2026-15791

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used …

Fix: 0.31.2+
Fix from $1,950 2026-07-21
Buildkit HIGH 7.5
CVE-2026-15788

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cac…

Fix: 0.31.2+
Fix from $1,950 2026-07-20
Buildkit HIGH 7.5
CVE-2026-33748

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insuf…

Fix: 0.28.1+
Fix from $1,950 2026-03-27
Buildkit CRITICAL 9.8
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when …

Fix: 0.28.1+
Fix from $2,300 2026-03-27
Moby MEDIUM 5.2
CVE-2025-54410

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various oth…

Fix: 25.0.13+
Fix from $1,600 2025-07-30
Moby HIGH 8.1
CVE-2024-36623

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operati…

Fix: after 25.0.3
Fix from $1,950 2024-11-29
Moby MEDIUM 6.5
CVE-2024-36620

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

Fix: after 26.0.2
Fix from $1,600 2024-11-29
Moby MEDIUM 6.5
CVE-2024-36621

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurren…

Patch available
Fix from $1,600 2024-11-29
Moby MEDIUM 6.5
CVE-2024-32473

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or …

Fix: 26.0.2+
Fix from $1,600 2024-04-18
Moby HIGH 7.5
CVE-2024-29018

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or …

Fix: 23.0.11 / 25.0.5+
Fix from $1,950 2024-03-20
Moby HIGH 7.8
CVE-2024-24557

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if…

Fix: 24.0.9 / 25.0.2+
Fix from $1,950 2024-02-01
Buildkit CRITICAL 9.8
CVE-2024-23653

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running contain…

Fix: 0.12.5+
Fix from $2,300 2024-01-31
Buildkit CRITICAL 9.1
CVE-2024-23652

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend …

Fix: 0.12.5+
Fix from $2,300 2024-01-31
Buildkit HIGH 7.4
CVE-2024-23651

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps runn…

Fix: 0.12.5+
Fix from $1,950 2024-01-31
Buildkit MEDIUM 5.3
CVE-2024-23650

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or…

Fix: 0.12.5+
Fix from $1,600 2024-01-31
Moby MEDIUM 6.8
CVE-2023-28842

Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other dow…

Fix: 20.10.24 / 23.0.3+
Fix from $1,600 2023-04-04
Moby HIGH 8.7
CVE-2023-28840

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other down…

Fix: 20.10.24 / 23.0.3+
Fix from $1,950 2023-04-04
Moby MEDIUM 6.8
CVE-2023-28841

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other down…

Fix: 20.10.24 / 23.0.3+
Fix from $1,600 2023-04-04
Buildkit MEDIUM 6.5
CVE-2023-26054

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the …

Fix: 0.11.4+
Fix from $1,600 2023-03-06
Hyperkit MEDIUM 6.5
CVE-2021-32847

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vuln…

Fix: after 0.20210107
Fix from $1,600 2023-02-20
Hyperkit HIGH 7.8
CVE-2021-32846

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock`…

Fix: after 0.20210107
Fix from $1,950 2023-02-17
Hyperkit HIGH 7.8
CVE-2021-32845

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `q…

Fix: after 0.20210107
Fix from $1,950 2023-02-17
Hyperkit MEDIUM 5.5
CVE-2021-32843

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, `virtio.c` has is a call…

Fix: after 0.20210107
Fix from $1,600 2023-02-17
Hyperkit MEDIUM 5.5
CVE-2021-32844

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, ` vi_pci_write` has is a…

Fix: after 0.20210107
Fix from $1,600 2023-02-17
Moby HIGH 7.5
CVE-2018-12608

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root …

Fix: 17.06.0+
Fix from $1,950 2018-09-10
Moby MEDIUM 5.9
CVE-2017-16539

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to tri…

Fix: after 17.03.2
Fix from $1,600 2017-11-04