Feed/CVE-2026-61711
CVE-2026-61711MEDIUMCVSS 0.0

BuildKit: Custom frontend could bypass Seccomp/AppArmor

Published Aug 19, 2026·Updated Aug 19, 2026

NVD Description

### Impact A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the `security.insecure` entitlement. Other security measures, like Linux capabilities were still applied to these containers. ### Patches Problem has been fixed in versions v0.31.1+ ### Workarounds Only use BuildKit frontends from trusted providers.

Affected Packages (1)

github.com/moby/buildkitGO
Fixed in = 0.31.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free