Hi,
The following vulnerability was published for docker-buildx.
CVE-2026-103433[0]:
| Docker Buildx Bake does not request the expected fs.read approval
| for certain filesystem inputs. An untrusted Bake definition can
| expose a readable file through a pathless secret whose ID is
| interpreted as a client-side pathname, or consume a local OCI image
| layout outside the project after entitlement validation checks a
| different path representation. Users who run untrusted Bake
| definitions are affected.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-103433
https://www.cve.org/CVERecord?id=CVE-2026-103433
[1] https://github.com/docker/buildx/security/advisories/GHSA-p54p-jq4x-rc28
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore