chainguard.dev/melange
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting chainguard.dev/melangepage 1 of 1
- CVE-2025-54059MEDIUMCVSS 4.4EG 4.4✓ Fixed in 0.29.52025-07-18
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unpriv…
- CVE-2026-24843HIGHCVSS 8.2EG 8.2✓ Fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the…
- CVE-2026-24844HIGHCVSS 7.9EG 7.9✓ Fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the…
- CVE-2026-25143HIGHCVSS 7.8EG 7.8✓ Fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell commands on the build host. The patch pi…
- CVE-2026-25145MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.40.32026-02-04
melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios)…
- CVE-2026-29050MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.43.42026-04-24
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file — for example through pull-request-driven CI or bu…
- CVE-2026-29051MEDIUMCVSS 4.4EG 4.4✓ Fixed in 0.43.42026-04-24
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) con…
Check whether chainguard.dev/melange is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for chainguard.dev/melange CVEs against the assets you own.
Start Free Scan →