
🚨High - BuildKit Cache Poisoning via Unvalidated Image DiffIDs (CVE-2026-93318) In http://github.com/moby/buildkit, a malicious image can spoof DiffIDs for layers while serving different contents; BuildKit may key cache/snapshot identity off DiffIDs without verifying layer data. If a shared/persistent cache ingests the malicious image first, later builds of the victim image can mount attacker-controlled layers (e.g., replace /bin/sh), enabling code execution, secret theft, or artifact tampering. Both regular and lazy-pulling snapshotters (stargz) are impacted. 👉Affected: http://github.com/moby/buildkit (versions TBD)

