<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:26:57.306361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-247887</id>
    <title>EUVD-2026-247887</title>
    <updated>2026-10-02T15:26:57.367312+00:00</updated>
    <content>EUVD-2026-247887</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-247887"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54059</id>
    <title>fkie_cve-2025-54059</title>
    <updated>2026-10-02T15:26:57.367357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54059"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5662-cv6m-63wh</id>
    <title>GHSA-5662-cv6m-63wh — melange's world-writable permissions expose SBOM files to potential image tampering</title>
    <updated>2026-10-02T15:26:57.367411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: chainguard.dev/melange</p>
<p>It was discovered that the SBOM files generated by melange in apks had file system permissions mode 666:
```
$ apkrane ls https://packages.wolfi.dev/os/x86_64/APKINDEX.tar.gz -P hello-wolfi --full --latest  | xargs wget -q -O  - | tar tzv 2&gt;/dev/null var/lib/db/sbom
drwxr-xr-x root/root         0 2025-06-23 14:17 var/lib/db/sbom
-rw-rw-rw- root/root      3383 2025-06-23 14:17 var/lib/db/sbom/hello-wolfi-2.12.2-r1.spdx.json
```</p>
<p>This issue was introduced in commit 1b272db ("Persist workspace filesystem throughout package builds (#1836)") ([v0.23.0](https://github.com/chainguard-dev/melange/releases/tag/v0.23.0)).</p>
<p>### Impact
This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances.</p>
<p>### Patches
This issue was addressed in melange in e29494b ("fix: tighten up permissions for written SBOM files and signature tarballs (#2086)") ([v0.29.5](https://github.com/chainguard-dev/melange/releases/tag/v0.29.5)).</p>
<p>## Acknowledgements</p>
<p>Thanks to Cody Harris [H2O.ai](https://h2o.ai/) and Markus Boehme for independently reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5662-cv6m-63wh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</id>
    <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
    <updated>2026-10-02T15:26:57.367469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1"/>
  </entry>
</feed>
