Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.15% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | |
| Aplazada | Media (5.3) | 0.19% | — | Villatheme BuildkitAI | 5/10/2026 | 6/10/2026 | Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | |
| Pendiente de análisis | Media (6.8) | 0.11% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds… | |
| Pendiente de análisis | Media (6.9) | 0.13% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | |
| Pendiente de análisis | Media (6) | 0.11% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access. | |
| Pendiente de análisis | Media (5.7) | 0.09% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic. | |
| Pendiente de análisis | Alta (7.5) | 0.17% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent… | |
| Pendiente de análisis | Alta (7.1) | 0.24% | — | Moby BuildkitAI | 5/10/2026 | 6/10/2026 | If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident. | |
| Aplazada | Media (6.2) | 0.21% | — | Mobyproject BuildkitAI | 2/10/2026 | 2/10/2026 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated… | |
| Aplazada | Alta (7.2) | 0.54% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid… | |
| Aplazada | Baja (2.3) | 0.40% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go… | |
| Aplazada | Media (5.3) | 0.36% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without… | |
| Analizada | Alta (7.3) | 0.20% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host. | |
| Analizada | Media (6) | 0.24% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | |
| Analizada | Baja (1.8) | 0.25% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. | |
| Analizada | Media (6.9) | 0.31% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. | |
| Analizada | Media (5.6) | 0.41% | — | Mobyproject Buildkit | 20/7/2026 | 5/8/2026 | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process. | |
| Analizada | Alta (8.2) | 0.53% | — | Mobyproject Buildkit | 27/3/2026 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the… | |
| Analizada | Crítica (9.8) | 0.58% | — | Mobyproject Buildkit | 27/3/2026 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context.… | |
| Aplazada | Media (4.1) | 0.19% | — | Docker BuildxAIMoby BuildkitAIOpentelemetry Open TelemetryAI | 17/3/2025 | 17/6/2026 | Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the… | |
| Modificada | Crítica (9.8) | 3.4% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a… | |
| Modificada | Crítica (9.1) | 2.5% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host… | |
| Modificada | Alta (7.4) | 0.91% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build… | |
| Modificada | Media (5.3) | 1.1% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit… | |
| Modificada | Alta (7) | 0.19% | — | Buildkite Elastic CI Stack | 22/12/2023 | 17/6/2026 | A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic link check for the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script. |