mediumVulnerability

CVE-2026-61711

### Impact A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the `security.insecure` entitlement. Other security measures, like Linux capabilities were still applied to these containers. ### Patches Problem has been fixed in versions v0.31.1+ ### Workarounds Only use BuildKit frontends from trusted providers.

Properties

ghsa_id
GHSA-7236-3392-c5c6
severity
medium
summary
BuildKit: Custom frontend could bypass Seccomp/AppArmor
cve_id
CVE-2026-61711
is_ghsa_only
false
ghsa_published
2026-08-19T20:23:50Z
source_url
https://github.com/advisories/GHSA-7236-3392-c5c6
ghsa_updated
2026-08-19T20:23:52Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/moby/buildkit

AFFECTS (1)

[Software]go/github.com/moby/buildkit

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-61711 — Ninja Signal Threat Intelligence | Ninja Signal