---
title: "CVE-2026-33748\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-33748?format=md
keywords: index, follow
---

# CVE-2026-33748

Publication date 22 April 2026

Last updated 10 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-33748?format=md#impact-score)

Toggle side navigation

## Description

BuildKit is a toolkit for converting source code to build artifacts in an
efficient, expressive and repeatable manner. Prior to version 0.28.1,
insufficient validation of Git URL fragment subdir components may allow
access to files outside the checked-out Git repository root. Possible
access is limited to files on the same mounted filesystem. The issue has
been fixed in version v0.28.1 The issue affects only builds that use Git
URLs with a subpath component. As a workaround, avoid building Dockerfiles
from untrusted sources or using the subdir component from an untrusted Git
repository where the subdir component could point to a symlink.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-33748?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| docker.io | 26.04 LTS resolute | Vulnerable |
| 25.10 questing | Ignored end of life, was needed |
| 24.04 LTS noble | Vulnerable |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| docker.io-app | 26.04 LTS resolute | Fixed 29.1.3-0ubuntu4.1 |
| 25.10 questing | Ignored end of life, was needed |
| 24.04 LTS noble | Fixed 29.1.3-0ubuntu3~24.04.2 |
| 22.04 LTS jammy | Fixed 29.1.3-0ubuntu3~22.04.2 |
| 20.04 LTS focal | Fixed 26.1.3-0ubuntu1~20.04.1+esm2  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2026-33748?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [alexmurray](https://launchpad.net/~alexmurray)

Traditionally the docker.io source package contained both the
library and docker application. However, in releases that
contain the
docker.io-app source package, the docker.io source package
contains only
the library whilst the docker application itself is contained
in the
docker.io-app package.

---

### [sbeattie](https://launchpad.net/~sbeattie)

docker packages contain an embedded copy of github:moby/buildkit

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| docker.io | * Upstream:   [f5462c2](https://github.com/moby/buildkit/commit/f5462c216098af766f97ea4cb328e65c6d8f7256) * Upstream:   [45b038c](https://github.com/moby/buildkit/commit/45b038cd0b2ec2d34013ce0f085522276f7ee0d8) |
| docker.io-app | * Upstream:   [f5462c2](https://github.com/moby/buildkit/commit/f5462c216098af766f97ea4cb328e65c6d8f7256) * Upstream:   [45b038c](https://github.com/moby/buildkit/commit/45b038cd0b2ec2d34013ce0f085522276f7ee0d8) |

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2026-33748?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2026-33748?format=md)

**Base score**

8.2 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | High |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | None |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.2 · High |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33748)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-33748)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-33748)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-33748)

### Related Ubuntu Security Notices (USN)

+ [USN-8230-1](https://usn.ubuntu.com/USN-8230-1)
+ Docker vulnerabilities
+ 6 May 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-33748>
* <https://docs.docker.com/build/concepts/context/#url-fragments>
* <https://github.com/moby/buildkit/releases/tag/v0.28.1>
* <https://github.com/moby/buildkit/security/advisories/GHSA-4vrq-3vrq-g6gg>
