Chainguard develops a focused suite of tools for container image building, signing, and supply-chain security, including products such as Melange, Apko, Malcontent, and Kaniko that are embedded in CI/CD pipelines and build infrastructure. Its vulnerability profile centers on path-traversal, resource-exhaustion, and command-injection weaknesses that arise from the parsing and build-orchestration demands of container tooling, reflecting risks inherent to systems that consume and process untrusted image definitions and dependencies. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chainguard over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28406HIGH kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks buil | Feb 27, 2026 | 8.5 | 32 | NO | NO |
CVE-2026-24843HIGH melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could | Feb 4, 2026 | 8.4 | 26 | NO | NO |
CVE-2026-24844HIGH melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline | Feb 4, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-25143HIGH melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execu | Feb 4, 2026 | 7.8 | 24 | NO | NO |
CVE-2026-25140HIGH apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository | Feb 4, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-25121HIGH apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's di | Feb 4, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-24845MEDIUM malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to | Jan 29, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-29050MEDIUM melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuratio | Apr 24, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-28407MEDIUM malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives w | Feb 27, 2026 | 5.3 | 21 | NO | NO |
CVE-2026-29049MEDIUM melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any | Mar 6, 2026 | 4.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chainguard.
Media articles that mention a CVE ID that affects a product developed by Chainguard — matched by CVE ID, not by vendor name.