CVE-2026-93317EPSS p4.8%

CVE-2026-93317CVE-2026-93317

Description

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.

Scoring

EPSS0.16% probability of exploitation · percentile 4.8% · 2026-10-10T12:00:23Z
Last modified2026-10-06
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.