| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7236-3392-c5c6 | BuildKit: Custom frontend could bypass Seccomp/AppArmor |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 20 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby buildkit |
|
| Vendors & Products |
Moby
Moby buildkit |
Wed, 19 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1. | |
| Title | BuildKit: Custom frontend could bypass Seccomp/AppArmor | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T13:19:05.458Z
Reserved: 2026-07-10T18:51:13.920Z
Link: CVE-2026-61711
Updated: 2026-08-20T13:18:55.856Z
Status : Received
Published: 2026-08-19T20:17:19.567
Modified: 2026-08-20T14:17:21.073
Link: CVE-2026-61711
No data.
OpenCVE Enrichment
Updated: 2026-08-20T12:00:04Z
Github GHSA