chainguard.dev/melange
Activity
- Latest release
- 3d ago
- Total releases
- 74
- Cadence
- ~5 days
- Last 12 months
- 40
Details
- First release
- Dec 22, 2022
| Version | Released | |
|---|---|---|
v0.60.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.60.0
minor
Dependencies (51)
+ 43 more |
|
v0.59.5
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.59.5
patch
Dependencies (51)
+ 43 more |
|
v0.59.4
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.59.4
patch
Dependencies (51)
+ 43 more |
|
v0.59.3
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.59.3
patch
Dependencies (51)
+ 43 more |
|
v0.59.2
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.59.2
patch
Dependencies (51)
+ 43 more |
|
v0.59.1
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.59.1
patch
Dependencies (51)
+ 43 more |
|
v0.59.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.59.0
minor
Dependencies (51)
+ 43 more |
|
v0.58.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.58.0
minor
Dependencies (51)
+ 43 more |
|
v0.57.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.57.0
minor
Dependencies (51)
+ 43 more |
|
v0.56.5
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.56.5
patch
Dependencies (51)
+ 43 more |
|
v0.56.4
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.56.4
minor
Dependencies (51)
+ 43 more |
|
v0.56.3
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.56.3
patch
Dependencies (51)
+ 43 more |
|
v0.56.2
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.56.2
patch
Dependencies (51)
+ 43 more |
|
v0.56.1
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.56.1
patch
Dependencies (51)
+ 43 more |
|
v0.56.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.56.0
minor
Dependencies (51)
+ 43 more |
|
v0.55.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.55.0
minor
Dependencies (51)
+ 43 more |
|
v0.54.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.54.0
minor
Dependencies (51)
+ 43 more |
|
v0.53.3
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.53.3
patch
Dependencies (51)
+ 43 more |
|
v0.53.2
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.53.2
patch
Dependencies (51)
+ 43 more |
|
v0.53.1
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.53.1
minor
Dependencies (51)
+ 43 more |
|
v0.53.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.53.0
minor
Dependencies (51)
+ 43 more |
|
v0.52.1
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.52.1
patch
Dependencies (51)
+ 43 more |
|
v0.52.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.52.0
minor
Dependencies (51)
+ 43 more |
|
v0.51.0
minor
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.51.0
minor
Dependencies (51)
+ 43 more |
|
v0.50.8
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.50.8
patch
Dependencies (51)
+ 43 more |
|
v0.50.7
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.50.7
patch
Dependencies (51)
+ 43 more |
|
v0.50.6
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.50.6
patch
Dependencies (51)
+ 43 more |
|
v0.50.5
patch
1 CVE
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.50.5
patch
Dependencies (51)
+ 43 more |
|
v0.50.2
minor
2 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.50.2
minor
Dependencies (51)
+ 43 more |
|
v0.46.1
patch
2 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.46.1
patch
Dependencies (52)
+ 44 more |
|
v0.46.0
minor
2 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.46.0
minor
Dependencies (52)
+ 44 more |
|
v0.43.6
patch
2 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.43.6
patch
Dependencies (53)
+ 45 more |
|
v0.43.2
minor
4 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev |
v0.43.2
minor
Dependencies (53)
+ 45 more |
|
v0.39.0
minor
8 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.39.0
minor
Dependencies (52)
+ 44 more |
|
v0.38.0
minor
8 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.38.0
minor
Dependencies (52)
+ 44 more |
|
v0.37.1
minor
8 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.37.1
minor
Dependencies (52)
+ 44 more |
|
v0.35.0
minor
8 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (52)
+ 44 more |
|
v0.34.3
patch
8 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.34.3
patch
Dependencies (52)
+ 44 more |
|
v0.34.1
minor
8 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29051
GO-2026-5562
GHSA-q2pw-xx38-p64j
Jun 25, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange melange has Path Traversal via .PKGINFO in --persist-lint-results in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29050
GO-2026-5279
GHSA-98f2-w9h9-7fp9
Jun 25, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses in chainguard.dev/melange Fixed in
0.43.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.34.1
minor
Dependencies (51)
+ 43 more |
|
v0.31.9
patch
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.31.9
patch
Dependencies (48)
+ 40 more |
|
v0.31.2
minor
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.31.2
minor
Dependencies (48)
+ 40 more |
|
v0.30.4
patch
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.30.4
patch
Dependencies (51)
+ 43 more |
|
v0.30.2
patch
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.30.2
patch
Dependencies (51)
+ 43 more |
|
v0.30.1
patch
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.30.1
patch
Dependencies (51)
+ 43 more |
|
v0.30.0
minor
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (51)
+ 43 more |
|
v0.29.5
patch
6 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev |
v0.29.5
patch
Dependencies (51)
+ 43 more |
|
v0.29.1
patch
7 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-54059
GO-2025-3815
GHSA-5662-cv6m-63wh
Jul 29, 2025
melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange Fixed in
0.29.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.29.1
patch
Dependencies (51)
+ 43 more |
|
v0.29.0
minor
7 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-54059
GO-2025-3815
GHSA-5662-cv6m-63wh
Jul 29, 2025
melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange Fixed in
0.29.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (51)
+ 43 more |
|
v0.26.12
patch
7 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-54059
GO-2025-3815
GHSA-5662-cv6m-63wh
Jul 29, 2025
melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange Fixed in
0.29.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.26.12
patch
Dependencies (49)
+ 41 more |
|
v0.26.10
patch
7 CVEs
CVE-2026-54174
GO-2026-5968
GHSA-fpg8-7664-jc5q
Jul 17, 2026
melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko melange: Incomplete package integrity verification allows data section substitution in chainguard.dev/apko Fixed in
0.50.4
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-29049
GO-2026-4588
GHSA-7rp8-r62p-q6wc
Mar 10, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-24844
GO-2026-4408
GHSA-vqqr-rmpc-hhg2
Feb 05, 2026
melange pipeline working-directory could allow command injection in chainguard.dev/melange melange pipeline working-directory could allow command injection in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25145
GO-2026-4409
GHSA-2w4f-9fgg-q2v9
Feb 05, 2026
melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange melange has a path traversal in license-path which allows reading files outside workspace in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-24843
GO-2026-4407
GHSA-qxx2-7h4c-83f4
Feb 05, 2026
melange QEMU runner could write files outside workspace directory in chainguard.dev/melange melange QEMU runner could write files outside workspace directory in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25143
GO-2026-4412
GHSA-rf4g-89h5-crcr
Feb 05, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange melange affected by potential host command execution via license-check YAML mode patch pipeline in chainguard.dev/melange Fixed in
0.40.3
References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-54059
GO-2025-3815
GHSA-5662-cv6m-63wh
Jul 29, 2025
melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange Fixed in
0.29.5
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.26.10
patch
Dependencies (49)
+ 41 more |