THREAT OPS › Threat News › [GHSA] GHSA-7236-3392-c5c6 (medium) — BuildKit: Custom frontend could bypass Seccomp/AppArmor
[GHSA] GHSA-7236-3392-c5c6 (medium) — BuildKit: Custom frontend could bypass Seccomp/AppArmor
GHSA-7236-3392-c5c6 Severity: medium CVE: CVE-2026-61711
BuildKit: Custom frontend could bypass Seccomp/AppArmor
### Impact A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the `security.insecure` entitlement. Other security measures, like Linux capabilities were still applied to
Indicators of compromise
- CVE-2026-61711cve
Original source: https://github.com/advisories/GHSA-7236-3392-c5c6