CVE-2026-61711: BuildKit: Custom frontend could bypass Seccomp/AppArmor
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-61711 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →