Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Only use proper BuildKit clients (Docker Buildx, Buildctl) to issue builds. The issue only affects scenarios where you are running a BuildKit service with untrusted parties issuing builds.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. | |
| Title | Malicious client can bypass destination directory validation on local sources upload | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-07-21T17:13:36.248Z
Reserved: 2026-07-14T19:27:01.532Z
Link: CVE-2026-15789
Updated: 2026-07-21T17:11:15.383Z
No data.
No data.
OpenCVE Enrichment
No data.