Skip to content
DockerCVE-2026-15789

Docker BuildKit: authentication bypass

Medium6.9CVE-2026-15789 · Published Jul 21, 2026 · updated Jul 30, 2026

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

Docker advisory

Affected versions

PackageAffectedFixed in
BuildKit
Product
< 0.31.20.31.2
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More Docker advisories

All Docker
Advisory
Docker CLI: link following
High7.1Aug 18
Docker Sandboxes: improper authorization
Medium5.7Aug 12
Docker BuildKit: improper input validation
Medium6.0Jul 21
Docker BuildKit: argument injection
High7.3Jul 21
Docker BuildKit: path traversal
Low1.8Jul 21
Docker BuildKit: link following
Medium5.6Jul 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.