{"id":"CVE-2026-93317","summary":"Container blob cache can accept unverified content","details":"An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.","aliases":["GHSA-p3rc-w3hc-pqvv"],"modified":"2026-10-06T10:30:49.111552129Z","published":"2026-10-05T17:43:44.903Z","database_specific":{"cna_assigner":"Docker","cwe_ids":["CWE-354"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93317.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93317.json"},{"type":"FIX","url":"https://github.com/moby/buildkit/releases/tag/v0.33.1"},{"type":"ADVISORY","url":"https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93317"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moby/buildkit","events":[{"introduced":"5245d869d85d9c98f986b600584c332a3b001986"},{"fixed":"8c91502cf280bd70a0c50912ce251c46a8881d9f"}],"database_specific":{"extracted_events":[{"introduced":"0.28.0"},{"fixed":"0.33.1"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93317.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N"}]}