Buildkit · Buildkit · CVE-2024-23650
**Name of the Vulnerable Software and Affected Versions**
BuildKit versions prior to 0.12.5
**Description**
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue is related to the conversion of source code to build artifacts. As a workaround, avoid using BuildKit frontends from untrusted sources.
**Recommendations**
For versions prior to 0.12.5, update to version 0.12.5 to resolve the issue.
As a temporary workaround, consider avoiding the use of BuildKit frontends from untrusted sources until the issue is resolved.