VDB

GO-2025-3815

GO-2025-3815 PUBLISHED

melange's world-writable permissions expose SBOM files to potential image tampering in chainguard.dev/melange

Affected Products

VendorProductVersions
chainguard.devmelange0.23.0, 0.23.0

Timeline

  • Jul 29, 2025 CVE Published
  • Feb 4, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›