Skip to content
DockerCVE-2026-15791

Docker BuildKit: path traversal

Low1.8CVE-2026-15791 · Published Jul 21, 2026 · updated Jul 30, 2026

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.

Docker advisory

Affected versions

PackageAffectedFixed in
BuildKit
Product
>= 0.10.0, < 0.31.20.31.2
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More Docker advisories

All Docker
Advisory
Docker CLI: link following
High7.1Aug 18
Docker Sandboxes: improper authorization
Medium5.7Aug 12
Docker BuildKit: improper input validation
Medium6.0Jul 21
Docker BuildKit: argument injection
High7.3Jul 21
Docker BuildKit: authentication bypass
Medium6.9Jul 21
Docker BuildKit: link following
Medium5.6Jul 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.