CVE-2026-61711
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a cu
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 19, 2026 · Last modified: Aug 20, 2026 · CWE-20
Not enough EPSS history yet.
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.
- github.comhttps://github.com/moby/buildkit/commit/3ea6dd0ce7d269cdb8aa23348718e2c1bf64f109
- github.comhttps://github.com/moby/buildkit/commit/64bbec89ca43dd95b2853edeca240c33c6729910
- github.comhttps://github.com/moby/buildkit/releases/tag/v0.31.1
- github.comhttps://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6