chainguard.dev/melange
Go9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting chainguard.dev/melangepage 1 of 1
- CVE-2025-54059MEDIUMCVSS 4.4EG 4.4fixed in 0.29.52025-07-18
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unpriv…
- CVE-2026-24843HIGHCVSS 8.4EG 8.4fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the…
- CVE-2026-24844HIGHCVSS 8.8EG 8.8fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the…
- CVE-2026-25143HIGHCVSS 7.8EG 7.8fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell commands on the build host. The patch pi…
- CVE-2026-25145MEDIUMCVSS 5.5EG 5.5fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios)…
- CVE-2026-29049MEDIUMCVSS 4.3EG 4.3fixed in 0.43.42026-03-02
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache…
- CVE-2026-29050MEDIUMCVSS 6.1EG 6.1fixed in 0.43.42026-04-24
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file — for example through pull-request-driven CI or bu…
- CVE-2026-29051MEDIUMCVSS 4.4EG 4.4fixed in 0.43.42026-04-24
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) con…
- CVE-2026-54174HIGHCVSS 8.3EG 8.3fixed in 0.50.42026-07-10
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but n…
Check whether chainguard.dev/melange is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for chainguard.dev/melange CVEs against the assets you own.
Book a Demo →