Skip to content

x/vulndb: potential Go vuln in github.com/moby/buildkit: GHSA-72x6-4j93-7w86 #6256

Description

@GoVulnBot

Advisory GHSA-72x6-4j93-7w86 references a vulnerability in the following Go modules:

Module
github.com/moby/buildkit

Description:

Impact

Maliciously crafted base image or build can cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the buildkitd process.

Patches

Issue is fixed in BuildKit v0.31.1+

Workarounds

Use trusted build sources.

References

This is BuildKit variant of containerd advisory GHSA-jpcc-p29g-p8mq

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/moby/buildkit
      non_go_versions:
        - introduced: TODO (earliest fixed "0.31.1", vuln range "<= 0.31.0")
      vulnerable_at: 0.32.2
summary: BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit
cves:
    - CVE-2026-61712
ghsas:
    - GHSA-72x6-4j93-7w86
references:
    - advisory: https://github.com/advisories/GHSA-72x6-4j93-7w86
    - advisory: https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86
    - fix: https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1
    - fix: https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255
    - web: https://github.com/moby/buildkit/releases/tag/v0.31.1
source:
    id: GHSA-72x6-4j93-7w86
    created: 2026-08-19T21:01:42.45797316Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions