Input validation error in BuildKit - CVE-2026-33748

 

Input validation error in BuildKit - CVE-2026-33748

Published: April 28, 2026


Vulnerability identifier: #VU128395
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33748
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in Git URL fragment subdir handling when processing Git URLs with a subdir component. A remote attacker can supply a crafted Git URL subdir component to disclose sensitive information.

Possible access is limited to files on the same mounted filesystem.


Affected software

BuildKit
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Containers Module
Ubuntu
Fedora
doctl
docker-compose
docker-stable-zsh-completion
docker-stable-bash-completion
docker-stable-debuginfo
docker-stable
docker.io-app (Ubuntu package)

How to mitigate CVE-2026-33748

Install security update from vendor's website.

BuildKit - update to 0.28.1
doctl - update to 1.154.0-1.fc44
docker-compose - addressed in versions 5.1.3-1.fc42, 5.1.3-1.fc43, 5.1.3-1.fc44, 5.1.3-1.fc45, 5.1.4-1.fc42, 5.1.4-1.fc43, 5.1.4-1.fc44
docker-stable-zsh-completion - update to 24.0.9_ce-150000.1.42.1
docker-stable-bash-completion - update to 24.0.9_ce-150000.1.42.1
docker-stable-debuginfo - update to 24.0.9_ce-150000.1.42.1
docker-stable - update to 24.0.9_ce-150000.1.42.1
docker.io-app (Ubuntu package) - addressed in versions 26.1.3-0ubuntu1~20.04.1+esm2, 29.1.3-0ubuntu3~22.04.2, 29.1.3-0ubuntu3~24.04.2, 29.1.3-0ubuntu4.1

External References

Related Security Bulletins