{"api_version":"v1","generated_at":"2026-10-08T18:05:00+00:00","product":{"cve_count":9,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-chainguard-dev-melange-293805f68f68","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/melange","name":"melange","next_cursor":null,"observations":[{"affected":"melange: < 0.50.4; apko: < 1.2.9","affected_versions_present":true,"cve_id":"CVE-2026-54174","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54174","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T16:19:01.111Z","patch_url":"","primary_source":"","published":"2026-09-11T21:05:30.789Z"},{"affected":">= 0.32.0, < 0.43.4","affected_versions_present":true,"cve_id":"CVE-2026-29051","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29051","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-24T13:10:10.825Z","patch_url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-q2pw-xx38-p64j","primary_source":"","published":"2026-04-24T00:00:36.253Z"},{"affected":">= 0.32.0, < 0.43.4","affected_versions_present":true,"cve_id":"CVE-2026-29050","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29050","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-25T01:38:30.604Z","patch_url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-98f2-w9h9-7fp9","primary_source":"","published":"2026-04-23T23:58:39.668Z"},{"affected":"< 0.43.4","affected_versions_present":true,"cve_id":"CVE-2026-29049","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29049","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-07T13:10:28.323Z","patch_url":"","primary_source":"","published":"2026-03-06T07:03:10.361Z"},{"affected":">= 0.14.0, < 0.40.3","affected_versions_present":true,"cve_id":"CVE-2026-25145","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25145","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-05T14:32:56.438Z","patch_url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-2w4f-9fgg-q2v9","primary_source":"","published":"2026-02-04T19:32:35.907Z"},{"affected":">= 0.10.0, < 0.40.3","affected_versions_present":true,"cve_id":"CVE-2026-25143","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25143","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-05T14:33:04.735Z","patch_url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-rf4g-89h5-crcr","primary_source":"","published":"2026-02-04T19:32:17.216Z"},{"affected":">= 0.3.0, < 0.40.3","affected_versions_present":true,"cve_id":"CVE-2026-24844","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24844","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-05T14:33:09.866Z","patch_url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-vqqr-rmpc-hhg2","primary_source":"","published":"2026-02-04T19:31:55.830Z"},{"affected":">= 0.11.3, < 0.40.3","affected_versions_present":true,"cve_id":"CVE-2026-24843","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24843","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-05T14:33:15.392Z","patch_url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-qxx2-7h4c-83f4","primary_source":"","published":"2026-02-04T19:31:35.608Z"},{"affected":">= 0.23.0, < 0.29.5","affected_versions_present":true,"cve_id":"CVE-2025-54059","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54059","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-18T16:04:30.154Z","patch_url":"","primary_source":"","published":"2025-07-18T15:40:43.277Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"chainguard-dev"}}
