What is CVE-2026-61711?
In BuildKit versions prior to 0.31.1, a crafted build request from a custom frontend could provide an invalid `SecurityMode` value, which `executor/oci/spec_linux.go` improperly handled as a non-sandbox mode, potentially bypassing security sandboxing. Affected users should upgrade to version 0.31.1 or later as soon as possible.
Azərbaycanca: BuildKit-in stabil olmayan 0.31.1 versiyasından əvvəl, xüsusi frontend hazırlanmış build sorğusunda səhv `SecurityMode` dəyərinin yerləşdirilməsinə imkan verir ki, bu da `executor/oci/spec_linux.go` vasitəsilə sandbox təhlükəsizlik mexanizmlərinin keçilməsinə səbəb ola bilər. Təsirə məruz qalan sistemlər BuildKit istifadə edən build mühitləridir; dərhal 0.31.1 və ya daha yüksək versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of BuildKit are affected by CVE-2026-61711?
This vulnerability affects all unstable versions of BuildKit prior to version 0.31.1.
How can users protect themselves against CVE-2026-61711?
Users should upgrade BuildKit to version 0.31.1 or later as soon as possible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.