Chainguard-Dev Melange vulnerabilities
8 known vulnerabilities affecting chainguard-dev/melange.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-24844P3HIGHCVSS 8.8v>= 0.3.0, < 0.40.32026-02-04
CVE-2026-24844 [HIGH] CWE-78 CVE-2026-24844: melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses ${{vars.*}} or ${{inputs.*}} substitutions in working-directory. The field is embedded into shell sc
nvd
CVE-2026-25143P3HIGHCVSS 7.8v>= 0.10.0, < 0.40.32026-02-04
CVE-2026-25143 [HIGH] CWE-78 CVE-2026-25143: melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to befor
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell commands on the build host. The patch pipeline in pkg/build/pipelines/patch.yaml embeds input-derived values (series paths, patch filenames, and numeric pa
nvd
CVE-2026-24843P3HIGHCVSS 8.4v>= 0.11.3, < 0.40.32026-02-04
CVE-2026-24843 [HIGH] CWE-22 CVE-2026-24843: melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries without validating that paths stay within the workspace,
nvd
CVE-2026-25145P4MEDIUMCVSS 5.5v>= 0.14.0, < 0.40.32026-02-04
CVE-2026-25145 [MEDIUM] CWE-22 CVE-2026-25145: melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to befor
melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios) could read arbitrary files from the host system. The LicensingInfos function in pkg/config/config.go reads licen
nvd
CVE-2026-29050P4MEDIUMCVSS 6.1v>= 0.32.0, < 0.43.42026-04-24
CVE-2026-29050 [MEDIUM] CWE-22 CVE-2026-29050: melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 a
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file — for example through pull-request-driven CI or build-as-a-service scenarios — could set `pipeline[].uses` to a value containing `../` sequences or an absolute path.
nvd
CVE-2026-29049P4MEDIUMCVSS 4.3fixed in 0.43.42026-03-06
CVE-2026-29049 [MEDIUM] CWE-400 CVE-2026-29049: melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior,
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the bui
nvd
CVE-2025-54059P4MEDIUMCVSS 4.4v>= 0.23.0, < 0.29.52025-07-18
CVE-2025-54059 [MEDIUM] CWE-276 CVE-2025-54059: melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 a
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker co
nvd
CVE-2026-29051P4LOWCVSS 3.3v>= 0.32.0, < 0.43.42026-04-24
CVE-2026-29051 [LOW] CWE-22 CVE-2026-29051: melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 a
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) constructs output file paths by joining `--out-dir` with the `arch` and `pkgname` values read from the `.PKGINFO` contr
nvd