Maliciously crafted base image or build can cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the buildkitd process.
Use trusted build sources.
id: GO-ID-PENDING
modules:
- module: github.com/moby/buildkit
non_go_versions:
- introduced: TODO (earliest fixed "0.31.1", vuln range "<= 0.31.0")
vulnerable_at: 0.32.2
summary: BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit
cves:
- CVE-2026-61712
ghsas:
- GHSA-72x6-4j93-7w86
references:
- advisory: https://github.com/advisories/GHSA-72x6-4j93-7w86
- advisory: https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86
- fix: https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1
- fix: https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255
- web: https://github.com/moby/buildkit/releases/tag/v0.31.1
source:
id: GHSA-72x6-4j93-7w86
created: 2026-08-19T21:01:42.45797316Z
review_status: UNREVIEWED
Advisory GHSA-72x6-4j93-7w86 references a vulnerability in the following Go modules:
Description:
Impact
Maliciously crafted base image or build can cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the buildkitd process.
Patches
Issue is fixed in BuildKit v0.31.1+
Workarounds
Use trusted build sources.
References
This is BuildKit variant of containerd advisory GHSA-jpcc-p29g-p8mq
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.