[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-75593":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":40,"aliases":41,"duplicate_of":9,"upstream":43,"downstream":47,"duplicates":53,"related":54,"reserved_at":9,"published_at":55,"modified_at":56,"state":57,"summary":58,"references_raw":67,"kevs":151,"epss":152,"epss_history":155,"metrics":247,"affected":259},"CVE-2026-75593","BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],[],[42],"RHSA-2026:50953",[44,46],{"_key":45},"CVE-2026-71556",{"_key":7},[48,49,51],{"_key":7},{"_key":50},"RHSA-2026:51065",{"_key":52},"CVE-2026-17106",[],[],"2026-08-19T20:06:54.924Z","2026-08-25T14:02:29.264Z","Deferred",{"cisa_kev":59,"cisa_ransomware":59,"cisa_vendor":9,"epss_severity":60,"epss_score":61,"severity":62,"severity_score":63,"severity_version":64,"severity_source":65,"severity_vector":66,"severity_status":57},false,"low",0.0054,"high",7.2,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",[68,76,81,86,90,95,99,103,107,111,115,119,123,127,131,135,139,143,147],{"url":69,"sources":70,"tags":73},"https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976",[65,71,72],"nvd","osv_red_hat",[74,75],"X Refsource CONFIRM","ARTICLE",{"url":77,"sources":78,"tags":79},"https://github.com/moby/buildkit/releases/tag/v0.31.2",[65,71,72],[80,75],"X Refsource MISC",{"url":82,"sources":83,"tags":84},"https://access.redhat.com/errata/RHSA-2026:50953",[72],[85],"Advisory",{"url":87,"sources":88,"tags":89},"https://images.redhat.com/",[72],[75],{"url":91,"sources":92,"tags":93},"https://access.redhat.com/security/cve/CVE-2026-75593",[72],[94],"REPORT",{"url":96,"sources":97,"tags":98},"https://access.redhat.com/security/updates/classification/",[72],[75],{"url":100,"sources":101,"tags":102},"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50953.json",[72],[85],{"url":104,"sources":105,"tags":106},"https://bugzilla.redhat.com/show_bug.cgi?id=2519913",[72],[94],{"url":108,"sources":109,"tags":110},"https://www.cve.org/CVERecord?id=CVE-2026-75593",[72],[85],{"url":112,"sources":113,"tags":114},"https://nvd.nist.gov/vuln/detail/CVE-2026-75593",[72],[85],{"url":116,"sources":117,"tags":118},"https://access.redhat.com/security/cve/CVE-2026-71556",[72],[94],{"url":120,"sources":121,"tags":122},"https://bugzilla.redhat.com/show_bug.cgi?id=2512562",[72],[94],{"url":124,"sources":125,"tags":126},"https://www.cve.org/CVERecord?id=CVE-2026-71556",[72],[85],{"url":128,"sources":129,"tags":130},"https://nvd.nist.gov/vuln/detail/CVE-2026-71556",[72],[85],{"url":132,"sources":133,"tags":134},"https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab",[72],[75],{"url":136,"sources":137,"tags":138},"https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac",[72],[75],{"url":140,"sources":141,"tags":142},"https://github.com/go-git/go-git/releases/tag/v5.19.2",[72],[75],{"url":144,"sources":145,"tags":146},"https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5",[72],[75],{"url":148,"sources":149,"tags":150},"https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm",[72],[75],[],{"date":153,"score":61,"percentile":154},"2026-09-19",0.44348,[156,159,162,165,168,171,174,177,180,183,186,189,192,195,198,201,204,207,210,213,216,219,222,225,228,231,234,237,240,243,246],{"date":157,"score":61,"percentile":158},"2026-08-20",0.43195,{"date":160,"score":61,"percentile":161},"2026-08-21",0.43245,{"date":163,"score":61,"percentile":164},"2026-08-22",0.43263,{"date":166,"score":61,"percentile":167},"2026-08-23",0.43081,{"date":169,"score":61,"percentile":170},"2026-08-24",0.43008,{"date":172,"score":61,"percentile":173},"2026-08-25",0.43045,{"date":175,"score":61,"percentile":176},"2026-08-26",0.43138,{"date":178,"score":61,"percentile":179},"2026-08-27",0.4319,{"date":181,"score":61,"percentile":182},"2026-08-28",0.43049,{"date":184,"score":61,"percentile":185},"2026-08-29",0.43088,{"date":187,"score":61,"percentile":188},"2026-08-30",0.43285,{"date":190,"score":61,"percentile":191},"2026-08-31",0.4329,{"date":193,"score":61,"percentile":194},"2026-09-01",0.43323,{"date":196,"score":61,"percentile":197},"2026-09-02",0.43372,{"date":199,"score":61,"percentile":200},"2026-09-03",0.43399,{"date":202,"score":61,"percentile":203},"2026-09-04",0.43438,{"date":205,"score":61,"percentile":206},"2026-09-05",0.43304,{"date":208,"score":61,"percentile":209},"2026-09-06",0.43507,{"date":211,"score":61,"percentile":212},"2026-09-07",0.43516,{"date":214,"score":61,"percentile":215},"2026-09-08",0.43537,{"date":217,"score":61,"percentile":218},"2026-09-09",0.43695,{"date":220,"score":61,"percentile":221},"2026-09-10",0.43716,{"date":223,"score":61,"percentile":224},"2026-09-11",0.43749,{"date":226,"score":61,"percentile":227},"2026-09-12",0.43832,{"date":229,"score":61,"percentile":230},"2026-09-13",0.43804,{"date":232,"score":61,"percentile":233},"2026-09-14",0.43833,{"date":235,"score":61,"percentile":236},"2026-09-15",0.43912,{"date":238,"score":61,"percentile":239},"2026-09-16",0.44101,{"date":241,"score":61,"percentile":242},"2026-09-17",0.44178,{"date":244,"score":61,"percentile":245},"2026-09-18",0.4432,{"date":153,"score":61,"percentile":154},[248,251,254],{"source":65,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":249},{"baseScore":63,"baseSeverity":250,"vectorString":66,"impactScore":9,"exploitabilityScore":9},"HIGH",{"source":71,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":252},{"baseScore":63,"baseSeverity":250,"vectorString":253,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",{"source":72,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":255,"cvss_v4_0":9},{"baseScore":256,"baseSeverity":9,"vectorString":257,"impactScore":258,"exploitabilityScore":63},7.1,"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L",7,[260,270],{"ecosystem":9,"name":261,"vendor":262,"product":261,"cpe_part":263,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":264},"buildkit","moby","a",[265],{"version":266,"is_range":267,"range_type":65,"version_start":9,"version_start_type":9,"version_end":268,"version_end_type":269,"fixed_in":9},"\u003C 0.31.2",true,"0.31.2","excluding",{"ecosystem":271,"name":272,"vendor":273,"product":272,"cpe_part":9,"purl_type":274,"purl_namespace":273,"purl_name":272,"source":9,"versions":275},"Red Hat","trivy","redhat","rpm",[276],{"version":277,"is_range":267,"range_type":278,"version_start":9,"version_start_type":9,"version_end":279,"version_end_type":269,"fixed_in":9},"lt0:0_73_0_0_1_hum1","ecosystem","0:0.73.0-0.1.hum1"]