Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Use trusted build sources.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby buildkit |
|
| Vendors & Products |
Moby
Moby buildkit |
Mon, 20 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process. | |
| Title | WCOW cache mount source selector resolves NTFS junctions outside of cache root | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-07-21T12:40:56.055Z
Reserved: 2026-07-14T19:25:38.521Z
Link: CVE-2026-15788
Updated: 2026-07-21T12:40:21.632Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-20T22:15:03Z