<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:10:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-247887</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-247887</link>
      <description>EUVD-2026-247887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-247887</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54059</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54059</link>
      <description>&lt;p&gt;melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54059</guid>
    </item>
    <item>
      <title>GHSA-5662-cv6m-63wh — melange's world-writable permissions expose SBOM files to potential image tampering</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5662-cv6m-63wh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: chainguard.dev/melange&lt;/p&gt;
&lt;p&gt;It was discovered that the SBOM files generated by melange in apks had file system permissions mode 666:
```
$ apkrane ls https://packages.wolfi.dev/os/x86_64/APKINDEX.tar.gz -P hello-wolfi --full --latest  | xargs wget -q -O  - | tar tzv 2&amp;gt;/dev/null var/lib/db/sbom
drwxr-xr-x root/root         0 2025-06-23 14:17 var/lib/db/sbom
-rw-rw-rw- root/root      3383 2025-06-23 14:17 var/lib/db/sbom/hello-wolfi-2.12.2-r1.spdx.json
```&lt;/p&gt;
&lt;p&gt;This issue was introduced in commit 1b272db (&amp;#34;Persist workspace filesystem throughout package builds (#1836)&amp;#34;) ([v0.23.0](https://github.com/chainguard-dev/melange/releases/tag/v0.23.0)).&lt;/p&gt;
&lt;p&gt;### Impact
This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances.&lt;/p&gt;
&lt;p&gt;### Patches
This issue was addressed in melange in e29494b (&amp;#34;fix: tighten up permissions for written SBOM files and signature tarballs (#2086)&amp;#34;) ([v0.29.5](https://github.com/chainguard-dev/melange/releases/tag/v0.29.5)).&lt;/p&gt;
&lt;p&gt;## Acknowledgements&lt;/p&gt;
&lt;p&gt;Thanks to Cody Harris [H2O.ai](https://h2o.ai/) and Markus Boehme for independently reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: chainguard.dev/melange&lt;/p&gt;
&lt;p&gt;It was discovered that the SBOM files generated by melange in apks had file system permissions mode 666:
```
$ apkrane ls https://packages.wolfi.dev/os/x86_64/APKINDEX.tar.gz -P hello-wolfi --full --latest  | xargs wget -q -O  - | tar tzv 2&amp;gt;/dev/null var/lib/db/sbom
drwxr-xr-x root/root         0 2025-06-23 14:17 var/lib/db/sbom
-rw-rw-rw- root/root      3383 2025-06-23 14:17 var/lib/db/sbom/hello-wolfi-2.12.2-r1.spdx.json
```&lt;/p&gt;
&lt;p&gt;This issue was introduced in commit 1b272db (&amp;#34;Persist workspace filesystem throughout package builds (#1836)&amp;#34;) ([v0.23.0](https://github.com/chainguard-dev/melange/releases/tag/v0.23.0)).&lt;/p&gt;
&lt;p&gt;### Impact
This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances.&lt;/p&gt;
&lt;p&gt;### Patches
This issue was addressed in melange in e29494b (&amp;#34;fix: tighten up permissions for written SBOM files and signature tarballs (#2086)&amp;#34;) ([v0.29.5](https://github.com/chainguard-dev/melange/releases/tag/v0.29.5)).&lt;/p&gt;
&lt;p&gt;## Acknowledgements&lt;/p&gt;
&lt;p&gt;Thanks to Cody Harris [H2O.ai](https://h2o.ai/) and Markus Boehme for independently reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5662-cv6m-63wh</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
