chainguard
DevTools & CIoss-project
Top products
Latest CVEs
The 14 most recently published vulnerabilities affecting chainguard.
- CVE-2026-29051melange has Path Traversal via .PKGINFO in --persist-lint-results4.4
- CVE-2026-29050melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses6.1
- CVE-2026-29049melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI4.3
- CVE-2026-28407malcontent's nested archive extraction failure can drop content from scan inputs5.3
- CVE-2026-28406kaniko has tar archive path traversal in build context extraction allows writing files outside destination directory8.2
- CVE-2026-25145melange has a path traversal in license-path which allows reading files outside workspace5.5
- CVE-2026-25143melange affected by potential host command execution via license-check YAML mode patch pipeline7.8
- CVE-2026-24844melange pipeline working-directory could allow command injection7.9
- CVE-2026-24843melange QEMU runner could write files outside workspace directory8.2
- CVE-2026-25140apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams7.5
- CVE-2026-25121apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base7.5
- CVE-2026-25122apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams5.5
- CVE-2026-24846malcontent's archive extraction could write outside extraction directory5.5
- CVE-2026-24845malcontent's OCI image scanning could expose registry credentials6.5