github.com/moby/buildkit is vulnerable to Denial of Service (DoS)
59
Medium Risk
The BuildKit daemon does not fully validate certain parameters received from a build frontend or client. A malicious frontend or client can craft a request with incorrect parameters that the daemon fails to handle safely. Processing the request triggers a panic that crashes the buildkitd process. The fix validates the incoming parameters before use.
You are affected if you are using a version that falls within the vulnerable range and you allow untrusted parties to supply BuildKit frontends or clients.
github.com/moby/buildkit is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.31.1.
Upgrade the github.com/moby/buildkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant