CVE-2026-103433

MEDIUM CVSS 4.0: 6.9 EPSS 0.29%
Updated Oct 06, 2026
Docker
Parameter Value
CVSS 6.9 (MEDIUM)
Type CWE-862 (Missing Authorization)
Vendor Docker
Public PoC No

Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

docker:docker buildx