Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97035.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97035
Upstream
Published
2026-08-19T20:17:23Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-75593 affecting package moby-engine 25.0.3-19
Details

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

References

Affected packages

Azure Linux:3 / moby-engine

Package

Name
moby-engine
Purl
pkg:rpm/azure-linux/moby-engine

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
25.0.3-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97035.json"