CVE-2024-23650

MEDIUM

BuildKit < 0.12.5 - Denial of Service via Crafted Frontend Request

Title source: llm
STIX 2.1

Description

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
https://github.com/moby/buildkit/pull/4601
Patch, Release Notes x_refsource_misc
https://github.com/moby/buildkit/releases/tag/v0.12.5

Scores

CVSS v3 5.3
EPSS 0.0096
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (2)
moby/buildkit 0 - 0.12.5Go
mobyproject/buildkit < 0.12.5
Published Jan 31, 2024
Tracked Since Feb 18, 2026