GHSA-7236-3392-c5c6

Suggest an improvement
Source
https://github.com/advisories/GHSA-7236-3392-c5c6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-7236-3392-c5c6/GHSA-7236-3392-c5c6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7236-3392-c5c6
Aliases
Downstream
Related
Published
2026-08-19T20:23:50Z
Modified
2026-08-20T15:59:01.303757581Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
BuildKit: Custom frontend could bypass Seccomp/AppArmor
Details

Impact

A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.

Patches

Problem has been fixed in versions v0.31.1+

Workarounds

Only use BuildKit frontends from trusted providers.

Database specific
{
    "severity": "MODERATE",
    "nvd_published_at": null,
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed_at": "2026-08-19T20:23:50Z"
}
References

Affected packages

Go / github.com/moby/buildkit

Package

Name
github.com/moby/buildkit
View open source insights on deps.dev
Purl
pkg:golang/github.com/moby/buildkit

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.31.1

Database specific

last_known_affected_version_range
"<= 0.31.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-7236-3392-c5c6/GHSA-7236-3392-c5c6.json"