Description
An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
Published: 2026-10-05
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

The issue only affects the low-level LLB API with direct blob access from the registry. It can't be reached with Dockerfile builds.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

threat_severity

Moderate


Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Moby
Moby buildkit
Vendors & Products Moby
Moby buildkit

Mon, 05 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
Title Container blob cache can accept unverified content
Weaknesses CWE-354
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T19:06:09.645Z

Reserved: 2026-09-17T17:17:43.718Z

Link: CVE-2026-93317

cve-icon Vulnrichment

Updated: 2026-10-05T19:06:05.861Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-05T18:17:37.923

Modified: 2026-10-06T15:08:38.397

Link: CVE-2026-93317

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-05T17:43:44Z

Links: CVE-2026-93317 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:00:15Z

Weaknesses