Melange Vulnerabilities

Security vulnerability tracking for Chainguard Melange

Last updated: Mar 6, 2026
Total CVEs

1

Critical

0

With Exploits

0

Last 30 Days

0

Vulnerability Timeline

1 vulnerabilities discovered over time for Melange

Severity Distribution

Critical0
0%
High0
0%
Medium1
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-290494.3

This vulnerability allows an attacker to make a build process download files from a specified location without any limits, potentially filling up the disk space on the server running the build. To exploit this, the attacker needs to control the URI in the build configuration, and there is currently no fix available.

chainguardmelange
Theoretical
about 1 month agoMar 6, 2026

About Chainguard Melange Security

This page provides comprehensive security vulnerability tracking for Chainguard Melange. Our database includes all CVEs affecting this product, updated in real-time from official sources.

Each vulnerability listing includes detailed CVSS severity analysis, exploit availability status, AI-generated explanations, and direct links to official security patches and vendor advisories.

Security Recommendations

  • • Always keep Melange updated to the latest version
  • • Subscribe to security advisories from Chainguard
  • • Monitor this page for new vulnerabilities affecting your version
  • • Prioritize patching critical and high severity issues immediately