chainguard.dev/melange vulnerabilities
CVEs whose affected-version data names the chainguard.dev/melange package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-25145Medium· 5.5melange has a path traversal in license-path which allows reading files outside workspace
melange has a path traversal in license-path which allows reading files outside workspace
▾ Sunlitmelange · chainguard.dev/melangeEPSS 0.18%via OSV
CVE-2025-54059Medium· 4.4melange's world-writable permissions expose SBOM files to potential image tampering
melange's world-writable permissions expose SBOM files to potential image tampering
▾ Sunlitmelange · chainguard.dev/melangeEPSS 0.13%via OSV