GHSA-9p26-698r-w4hx
GitHub Security Advisory
BuildKit vulnerable to possible panic when incorrect parameters sent from frontend
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
### Impact
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
### Patches
The issue has been fixed in v0.12.5
### Workarounds
Avoid using BuildKit frontends from untrusted sources. A frontend image is usually specified as the `#syntax` line on your Dockerfile, or with `--frontend` flag when using `buildctl build` command.
### References
Affected Packages
Go
github.com/moby/buildkit
Affected versions:
0
(fixed in 0.12.5)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.