-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing validation checks for mandatory platform fields in image configurations. The patch added explicit checks for 'img.OS' and 'img.Architecture' in patchImageConfig() to prevent null/missing values from causing panics. The CWE-754 (Improper Check for Unusual Conditions) and commit diff showing added validations confirm this was the vulnerable function.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/moby/buildkit | go | < 0.12.5 | 0.12.5 |
Ongoing coverage of React2Shell