Home/Product/chainguard melange
Product

chainguard melange

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-29051
>= 0.32.0 and < 0.43.4
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `m
4.4MEDIUM
CVE-2026-29050
>= 0.32.0 and < 0.43.4
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an
6.1MEDIUM
CVE-2026-29049
<= 0.40.5
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache download
4.3MEDIUM
CVE-2026-25145
>= 0.14.0 and < 0.40.5
melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can
5.5MEDIUM
CVE-2026-25143
>= 0.10.0 and < 0.40.5
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can
7.8HIGH
CVE-2026-24844
>= 0.3.0 and <= 0.40.5
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can p
7.9HIGH
CVE-2026-24843
>= 0.11.3 and < 0.40.5
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can in
8.2HIGH
CVE-2006-0917
all versions
Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for
CVE-2002-1351
all versions
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly
CVE-2002-0552
all versions
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and pos
threatengine.sh