Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/chainguard-dev/melange

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-29051 is a path traversal vulnerability in chainguard-dev's melange versions from 0.32.0 up to but not including 0.43.4. When the --persist-lint-results flag is used, melange constructs output file paths from unvalidated values in the APK's . PKGINFO file, allowing an attacker supplying a malicious APK to cause melange to write JSON lint reports to arbitrary filesystem locations. This can overwrite existing JSON files but does not allow direct code execution. The vulnerability only affects deployments explicitly using the --persist-lint-results option, which is off by default. The issue is fixed in version 0.

Join the discussion

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. Version 0.43.4 contains a patch.

Join the discussion

CVE-2026-25145 is a medium severity path traversal vulnerability in chainguard-dev's melange tool versions 0.14.0 up to before 0.40.3. It allows an attacker who can influence melange configuration files—such as via pull request-driven CI or build-as-a-service environments—to read arbitrary files on the host system. The vulnerability arises from insufficient validation of license file paths in the LicensingInfos function, enabling traversal outside the intended workspace directory. The contents of these files can then be embedded into the generated SBOM, facilitating exfiltration of sensitive data through build artifacts. This issue does not require privileges but does require user interaction to trigger a build with a malicious configuration. The flaw has been patched in version 0.

Join the discussion

CVE-2026-25143 is a high-severity OS command injection vulnerability in chainguard-dev's melange tool versions 0.10.0 to before 0.40.3. It arises from improper neutralization of special shell characters in the patch pipeline, allowing attackers who can influence patch-related inputs to execute arbitrary shell commands on the build host. Exploitation requires user interaction but no privileges and can lead to full compromise of the build environment. The issue is fixed in version 0.40.3.

Join the discussion

CVE-2026-24844 is a high-severity OS command injection vulnerability in chainguard-dev's melange tool versions 0.3.0 up to but not including 0.40.3. The flaw arises when user-controlled input values are substituted into the working-directory field of declarative build pipelines without proper shell escaping, allowing attackers with limited privileges to execute arbitrary shell commands. Exploitation requires the attacker to provide build input values and involves user interaction, but does not require modification of pipeline definitions. The vulnerability impacts confidentiality and integrity but not availability. It has been patched in version 0.40.

Join the discussion

CVE-2026-24843 is a high-severity path traversal vulnerability in chainguard-dev's melange tool versions 0.11.3 up to before 0.40.3. It allows an attacker who can influence the tar stream from a QEMU guest VM to write files outside the intended workspace on the host system. This occurs because the retrieveWorkspace function does not properly validate tar entry paths, enabling directory traversal via '.. /' sequences. Exploitation requires local access to influence the tar stream and some user interaction, but no privileges are needed. The vulnerability can lead to integrity and availability impacts by overwriting or creating arbitrary files on the host.

Join the discussion

melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/chainguard-dev/melange
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses