Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoid using build sources from untrusted locations. Only builds enabling proxy networking for exec steps (either via BuildKitd TOML config or Buildx Rego policy) are affected.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build. | |
| Title | BuildKit proxy CA cleanup can be disrupted by build steps | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T21:57:08.053Z
Reserved: 2026-09-17T17:17:25.321Z
Link: CVE-2026-93315
No data.
Status : Received
Published: 2026-10-05T22:16:58.820
Modified: 2026-10-05T22:16:58.820
Link: CVE-2026-93315
No data.
OpenCVE Enrichment
No data.
-
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition