Input validation error in BuildKit - CVE-2026-33748
Published: April 28, 2026
BuildKit
Moby project
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in Git URL fragment subdir handling when processing Git URLs with a subdir component. A remote attacker can supply a crafted Git URL subdir component to disclose sensitive information.
Possible access is limited to files on the same mounted filesystem.