StackRadar

CVE-2026-33748

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
77
of 17,781 indexed, latest versions
Container images
68
deployed by those charts
Fix available
2 of 2
affected packages

BuildKit Git URL subdir component can cause access to restricted files

Carried by container images the latest versions of 77 of 17,781 indexed charts deploy, on 68 images.

Affected packageAffected versionsFixed inImages
github.com/moby/buildkitgolangv0.0.0-20181107081847-c3a857e3fca0, v0.0.0-20260906160352-29f5975892d6, v0.7.2, v0.8.1+27 more0.28.166
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6, 26.1.5+dfsg1-9+b1326.1.5+dfsg1-9+deb13u12
OSV records
DEBIAN-CVE-2026-33748GHSA-4vrq-3vrq-g6gg
Also known as
GO-2026-4859

Charts affected

77 by stars
ChartLatestAffected imagesRadar Score
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/moby/buildkit@v0.11.7-0.20230908085316-d3e6c1360f6e
0.28.1

Open the chart page →

3,225
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/moby/buildkit@v0.11.6
0.28.1

Open the chart page →

3,225
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/moby/buildkit@v0.11.6
0.28.1

Open the chart page →

9,774
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
github.com/moby/buildkit@v0.11.2
0.28.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
github.com/moby/buildkit@v0.11.2
0.28.1

Open the chart page →

10,603
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
github.com/moby/buildkit@v0.10.1-0.20220403220257-10e6f94bf90d
0.28.1

Open the chart page →

4,547
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
github.com/moby/buildkit@v0.10.1-0.20220403220257-10e6f94bf90d
0.28.1

Open the chart page →

27,465
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
github.com/moby/buildkit@v0.21.0
0.28.1

Open the chart page →

6,037
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/moby/buildkit@v0.11.5
0.28.1

Open the chart page →

8,599
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
library/docker:23.0.1-dindd9a0fd8bdd15
github.com/moby/buildkit@v0.11.5
0.28.1

Open the chart page →

4,237
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
gcr.io/kaniko-project/executor:latest4e7a52dd1f14
github.com/moby/buildkit@v0.22.0
0.28.1

Open the chart page →

71,208
pet-battle-infrapetbattle1.0.322 of 2See more

pet-battle-infra petbattle 1.0.32

2 of the 2 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
github.com/moby/buildkit@v0.12.5
0.28.1
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.402 of 3See more

pet-battle-tournament petbattle 1.0.40

2 of the 3 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
github.com/moby/buildkit@v0.12.5
0.28.1
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

15,466
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11c57233403eff
github.com/moby/buildkit@v0.12.5
0.28.1

Open the chart page →

25,934
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

15,291
gitops-operatorredhat-cop0.10.61 of 1See more

gitops-operator redhat-cop 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
github.com/moby/buildkit@v0.12.5
0.28.1

Open the chart page →

369
ploigosredhat-cop0.0.92 of 2See more

ploigos redhat-cop 0.0.9

2 of the 2 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
github.com/moby/buildkit@v0.12.5
0.28.1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/moby/buildkit@v0.8.1
0.28.1

Open the chart page →

29,227
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/moby/buildkit@v0.11.6
0.28.1

Open the chart page →

68,240
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/moby/buildkit@v0.15.0
0.28.1

Open the chart page →

2,429
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/moby/buildkit@v0.11.6
0.28.1

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/moby/buildkit@v0.11.6
0.28.1

Open the chart page →

2,505
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1

Open the chart page →

28,165
act-runnertektonops0.1.22 of 2See more

act-runner tektonops 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
github.com/moby/buildkit@v0.13.2
0.28.1
library/docker:23.0.6-dindafa5d5134900
github.com/moby/buildkit@v0.12.2
0.28.1

Open the chart page →

4,212
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-33748.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/moby/buildkit@v0.12.5
0.28.1

Open the chart page →

2,477

Container images carrying it

68 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/caninehq/canine:latesta058034ca006
github.com/moby/buildkit@v0.22.0
0.28.1
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/moby/buildkit@v0.16.0
0.28.1
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/moby/buildkit@v0.11.7-0.20230908085316-d3e6c1360f6e
0.28.1
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
github.com/moby/buildkit@v0.11.6
0.28.1
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/moby/buildkit@v0.11.6
0.28.1
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/moby/buildkit@v0.11.6
0.28.1
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/moby/buildkit@v0.15.1
0.28.1
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
github.com/moby/buildkit@v0.26.3
0.28.1
1
ghcr.io/zapier/kubechecks:latest60cea46ce830
github.com/moby/buildkit@v0.26.2
0.28.1
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/moby/buildkit@v0.9.3
0.28.1
1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/moby/buildkit@v0.0.0-20181107081847-c3a857e3fca0
0.28.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/moby/buildkit@v0.11.5
0.28.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/moby/buildkit@v0.8.1
0.28.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.