Bug 2503742 (CVE-2026-15789) - CVE-2026-15789 buildkit: github.com/moby/buildkit: BuildKit: File escape vulnerability
Summary: CVE-2026-15789 buildkit: github.com/moby/buildkit: BuildKit: File escape vuln...
Keywords:
Status: NEW
Alias: CVE-2026-15789
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2533585 2533586 2533587 2533588 2533590 2533591 2533592 2533594 2533589 2533593
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-21 17:01 UTC by OSIDB Bzimport
Modified: 2026-09-15 05:45 UTC (History)
126 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-21 17:01:59 UTC
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.


Note You need to log in before you can comment on or make changes to this bug.