Loading HuntDB...

GHSA-9p26-698r-w4hx

GitHub Security Advisory

BuildKit vulnerable to possible panic when incorrect parameters sent from frontend

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

### Patches
The issue has been fixed in v0.12.5

### Workarounds
Avoid using BuildKit frontends from untrusted sources. A frontend image is usually specified as the `#syntax` line on your Dockerfile, or with `--frontend` flag when using `buildctl build` command.

### References

Affected Packages

Go github.com/moby/buildkit
Affected versions: 0 (fixed in 0.12.5)

Related CVEs

Key Information

GHSA ID
GHSA-9p26-698r-w4hx
Published
January 31, 2024 10:43 PM
Last Modified
March 4, 2024 6:43 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/moby/buildkit
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.