chainguard
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 29, 2026 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root
Chainguard Academy (edu) Nginx directory redirect downgrades HTTPS requests to HTTP
melange has Path Traversal via .PKGINFO in --persist-lint-results
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses
melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI
malcontent's nested archive extraction failure can drop content from scan inputs
kaniko has tar archive path traversal in build context extraction allows writing files outside destination directory
melange has a path traversal in license-path which allows reading files outside workspace
melange affected by potential host command execution via license-check YAML mode patch pipeline
apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
Monitor chainguard in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.