{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-20T19:12:56Z",
  "bugzilla" : {
    "description" : "github.com/moby/buildkit: BuildKit: Information Disclosure via Improper Handling of NTFS Directory Junctions",
    "id" : "2502989",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2502989"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.", "A flaw was found in BuildKit. An untrusted user, when authoring a build on a Windows Container on Windows (WCOW) configured BuildKit daemon, can exploit a vulnerability in the cache mount source selector. This flaw allows the user to read arbitrary files from the host system, leading to information disclosure." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-22T00:00:00Z",
    "advisory" : "RHSA-2026:43122",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "buildah-main-1.44.0-3.2.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44152",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "podman-main-6.0.2-2.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-27T00:00:00Z",
    "advisory" : "RHSA-2026:46988",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "trivy-main-0.72.0-0.1.2.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51065",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "buildah-main-1.45.0-2.hum1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-15788\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15788\nhttps://github.com/moby/buildkit/security/advisories/GHSA-388v-wmr2-g2v2" ],
  "name" : "CVE-2026-15788",
  "csaw" : false
}