Docker patches command execution via BuildKit’s Git checkout and five other build flaws
On July 16 2026 Docker Engine 29.6.2 fixed five BuildKit vulnerabilities, including CVE-2026-15793 which can execute commands on the host during a malicious Git checkout, and CVE-2026-17106 was fixed in 29.7.0. Pipelines that build from untrusted sources should update Engine, Buildx and BuildKit now.