Skip to main content

Vendor archive

mobyproject CVEs

Beta · best-effort

37 CVEs tagged to vendor mobyproject2 Critical, 11 High, 21 Medium, 3 Low, 0 Unrated.

CVE-2026-15793

Published Jul 21, 2026

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15792

Published Jul 21, 2026

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15791

Published Jul 21, 2026

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the bui…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15789

Published Jul 21, 2026

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permis…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33748

Published Mar 27, 2026

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL…

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-33747

Published Mar 27, 2026

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit fronte…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-54410

Published Jul 30, 2025

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/product…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-54388

Published Jul 30, 2025

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/product…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36623

Published Nov 29, 2024

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corrupti…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36621

Published Nov 29, 2024

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36620

Published Nov 29, 2024

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32473

Published Apr 18, 2024

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is n…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29018

Published Mar 20, 2024

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking im…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24557

Published Feb 1, 2024

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scrat…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23653

Published Jan 31, 2024

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit a…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-23652

Published Jan 31, 2024

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --moun…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-23651

Published Jan 31, 2024

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the sa…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-23650

Published Jan 31, 2024

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a reques…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28842

Published Apr 4, 2023

Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28841

Published Apr 4, 2023

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28840

Published Apr 4, 2023

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26054

Published Mar 6, 2023

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request tha…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32847

Published Feb 20, 2023

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2