chainguard-dev
DevTools & CIcommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting chainguard-dev.
- CVE-2026-54174melange: Incomplete package integrity verification allows data section substitution8.3
- CVE-2026-42576apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery6.5
- CVE-2026-42575apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)7.5
- CVE-2026-42574apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root7.5
- CVE-2026-29051melange has Path Traversal via .PKGINFO in --persist-lint-results4.4
- CVE-2026-29050melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses6.1
- CVE-2026-29049melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI4.3
- CVE-2026-28407malcontent's nested archive extraction failure can drop content from scan inputs5.3
- CVE-2026-25145melange has a path traversal in license-path which allows reading files outside workspace5.5
- CVE-2026-25143melange affected by potential host command execution via license-check YAML mode patch pipeline7.8
- CVE-2026-24844melange pipeline working-directory could allow command injection7.9
- CVE-2026-24843melange QEMU runner could write files outside workspace directory8.2
- CVE-2026-25140apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams7.5
- CVE-2026-25121apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base7.5
- CVE-2026-25122apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams5.5