Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
The issue only affects the low-level LLB API with direct blob access from the registry. It can't be reached with Dockerfile builds.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby buildkit |
|
| Vendors & Products |
Moby
Moby buildkit |
Mon, 05 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity. | |
| Title | Container blob cache can accept unverified content | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T17:43:44.903Z
Reserved: 2026-09-17T17:17:43.718Z
Link: CVE-2026-93317
No data.
Status : Received
Published: 2026-10-05T18:17:37.923
Modified: 2026-10-05T18:17:37.923
Link: CVE-2026-93317
No data.
OpenCVE Enrichment
Updated: 2026-10-05T18:30:19Z