Chainguard.dev/melange
This hub aggregates every CVE we track for Chainguard.dev/melange, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
4
1
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Chainguard.dev/melange.
- CVE-2026-29049melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI4.3
- CVE-2026-25145melange has a path traversal in license-path which allows reading files outside workspace5.5
- CVE-2026-25143melange affected by potential host command execution via license-check YAML mode patch pipeline7.8
- CVE-2026-24844melange pipeline working-directory could allow command injection7.9
- CVE-2026-24843melange QEMU runner could write files outside workspace directory8.2
- CVE-2025-54059melange creates SBOM files in APKs with world-writable permissions4.4
Product normalization is registry-driven with AI assist and human review. How it works