Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.15% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | |
| Pendiente de análisis | Media (6.8) | 0.11% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds… | |
| Pendiente de análisis | Media (6.9) | 0.13% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | |
| Pendiente de análisis | Media (6) | 0.11% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access. | |
| Pendiente de análisis | Media (5.7) | 0.09% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic. | |
| Pendiente de análisis | Alta (7.5) | 0.17% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent… | |
| Pendiente de análisis | Alta (7.1) | 0.24% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident. | |
| Aplazada | Media (6.2) | 0.21% | — | Mobyproject BuildkitAI | 2/10/2026 | 2/10/2026 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated… | |
| Aplazada | Alta (7.2) | 0.54% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid… | |
| Aplazada | Baja (2.3) | 0.40% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go… | |
| Aplazada | Media (5.3) | 0.36% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without… | |
| Pendiente de análisis | Alta (7.1) | 0.44% | — | Moby Go-archiveAI | 18/8/2026 | 28/8/2026 | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a… | |
| Analizada | Alta (7.3) | 0.20% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host. | |
| Analizada | Media (6) | 0.24% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | |
| Analizada | Baja (1.8) | 0.25% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. | |
| Analizada | Media (6.9) | 0.31% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. | |
| Analizada | Media (5.6) | 0.41% | — | Mobyproject Buildkit | 20/7/2026 | 5/8/2026 | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process. | |
| Analizada | Alta (7.2) | 0.10% | — | Docker EngineMobyproject MobyMobyproject Moby/v2 | 12/6/2026 | 17/6/2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path,… | |
| Analizada | Media (6.1) | 0.10% | — | Docker EngineMobyproject MobyMobyproject Moby/v2 | 12/6/2026 | 17/6/2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on… | |
| Pendiente de análisis | Alta (7.2) | 0.17% | — | MobyAIDocker EngineAI | 5/6/2026 | 9/9/2026 | Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the… | |
| Analizada | Alta (8.2) | 0.53% | — | Mobyproject Buildkit | 27/3/2026 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the… | |
| Analizada | Crítica (9.8) | 0.58% | — | Mobyproject Buildkit | 27/3/2026 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context.… | |
| Aplazada | Baja (1) | 0.18% | — | Mobywatel IOSAI | 3/2/2026 | 17/6/2026 | In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the last application view displayed before… | |
| Analizada | Media (5.2) | 0.15% | — | Mobyproject Moby | 30/7/2025 | 17/6/2026 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that… | |
| Analizada | Media (5.1) | 0.23% | — | Mobyproject Moby | 30/7/2025 | 17/6/2026 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by… |