CVE-2026-61711
ADVISORY - githubSummary
Impact
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.
Patches
Problem has been fixed in versions v0.31.1+
Workarounds
Only use BuildKit frontends from trusted providers.
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in