Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Chainguard

First CVE: Jan 29, 2026Active for: 1 yearTotal CVEs: 14
27.8
VTI Score
Low

Chainguard develops a focused suite of tools for container image building, signing, and supply-chain security, including products such as Melange, Apko, Malcontent, and Kaniko that are embedded in CI/CD pipelines and build infrastructure. Its vulnerability profile centers on path-traversal, resource-exhaustion, and command-injection weaknesses that arise from the parsing and build-orchestration demands of container tooling, reflecting risks inherent to systems that consume and process untrusted image definitions and dependencies. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Chainguard over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2026
5 months ago
Most Recent CVE
Apr 24, 2026
91 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-28406HIGH
kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks buil
Feb 27, 20268.532NONO
CVE-2026-24843HIGH
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could
Feb 4, 20268.426NONO
CVE-2026-24844HIGH
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline
Feb 4, 20268.825NONO
CVE-2026-25143HIGH
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execu
Feb 4, 20267.824NONO
CVE-2026-25140HIGH
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository
Feb 4, 20267.524NONO
CVE-2026-25121HIGH
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's di
Feb 4, 20267.524NONO
CVE-2026-24845MEDIUM
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to
Jan 29, 20266.522NONO
CVE-2026-29050MEDIUM
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuratio
Apr 24, 20266.121NONO
CVE-2026-28407MEDIUM
malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives w
Feb 27, 20265.321NONO
CVE-2026-29049MEDIUM
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any
Mar 6, 20264.320NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
50%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local8 (57.1%)
Network6 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (57.1%)
Unknown0 (0.0%)
Required6 (42.9%)
Privileges Required
Low6 (42.9%)
High0 (0.0%)
None8 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Chainguard.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Chainguard — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Chainguard's Products

View all 1 CNAs →

Top CWEs