lowVulnerability
CVE-2026-61712
### Impact Maliciously crafted base image or build can cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the buildkitd process. ### Patches Issue is fixed in BuildKit v0.31.1+ ### Workarounds Use trusted build sources. ### References This is BuildKit variant of containerd advisory https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq
Properties
- ghsa_id
- GHSA-72x6-4j93-7w86
- severity
- low
- summary
- BuildKit has a possible runtime DoS via unbounded group parsing
- cve_id
- CVE-2026-61712
- is_ghsa_only
- false
- ghsa_published
- 2026-08-19T20:24:01Z
- source_url
- https://github.com/advisories/GHSA-72x6-4j93-7w86
- ghsa_updated
- 2026-08-19T20:24:59Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]go/github.com/moby/buildkit
AFFECTS (1)
→[Software]go/github.com/moby/buildkit
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph