Chainguard has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 3.3 (low). Most affected products: Chainguard Academy (edu) (2), melange (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 3.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2026-29049Medium· 4.3melange allows users to build apk packages using declarative pipelines24CVE-2026-105767Low· 3.3Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07…18CVE-2026-105766Low· 3.1Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 all…17
Chainguard vulnerabilities
CVEs affecting Chainguard, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-105767Low· 3.3Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07…
Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07…
CVE-2026-105766Low· 3.1Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 all…
Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 all…
CVE-2026-29049Medium· 4.3melange allows users to build apk packages using declarative pipelines
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…