Evan Gibler
8 exploits
Active since Jul 2025
melange 0.23.0-0.29.4 - Incorrect Default Permissions in SBOM Files
CVSS 4.4
malcontent 1.8.0-1.20.2 - Path Traversal via Symlink Handling
CVSS 5.5
melange has Path Traversal via .PKGINFO in --persist-lint-results
CVSS 4.4
malcontent <1.21.0 - Info Disclosure
CVSS 5.3
melange 0.23.0-0.29.4 - Incorrect Default Permissions in SBOM Files
CVSS 4.4
malcontent 0.10.0-1.20.2 - Unauthenticated Docker Registry Credential Exposure via WWW-Authenticate Header
CVSS 6.5
malcontent 1.8.0-1.20.2 - Path Traversal via Symlink Handling
CVSS 5.5
melange 0.10.0-0.40.2 - OS Command Injection via Patch Pipeline Input Embedding
CVSS 7.8