Security1 publisher2 min readPublished
Chainguard discloses 14 Java bugs that were fixed upstream but never got a CVE
Chainguard disclosed 14 Java vulnerabilities that were fixed upstream but never assigned a CVE, one rated critical and one high. Teams still on the affected versions got no scanner alert, some for years, because nobody announced the fixes when they landed at HEAD.
The Watch · Security desk

What happened
- Chainguard says none of the 14 is a live zero-day, since a fixed version already exists upstream for each of them.
- Chainguard published plain patch files for every affected version in a public GitHub repository, under each project's original license.
- The advisory is a free, public Chainguard VEX feed that lists the affected versions.
- Chainguard Libraries customers get rebuilt artifacts with the same package coordinates plus a -0cgr.n qualifier, swapped in with a one-line lockfile change.
- Ten new shield and surface partners joined Athena, among them Palo Alto Networks, Sysdig, ReversingLabs and Oligo Security.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Dependency tools that read only CVE data will keep passing the affected versions unless CVEs are assigned later. Seeing these bugs now means reading Chainguard's feed or using a surface partner's product.
- decision Teams on affected versions have three routes. They can take a free upstream upgrade, apply the free patches and do their own rebuild, signing, SBOM and SLSA L3 provenance, or pay for Chainguard's rebuilt artifacts.
- precedent Chainguard calls this batch a test ahead of thousands more findings, so the number of advisories arriving through this feed is set to grow well past 14.
Twelve of the 14 are rated medium or low [1]. "A few are still serious if you're running an affected version," Jackie Porter, Chainguard's senior director of product management, and a co-author wrote [6][19]. The opening of their post names none of the affected projects. It sends readers to Chainguard's public patch repository for the full list [4]. The ratings and every other detail here come from Chainguard's post [3]. Chainguard also sells the rebuilt artifacts that fix the bugs [13].
Chainguard is patching the old versions itself because the projects have no path to accept a fix for them [11]. Its rebuilt artifacts need "No code changes, no major version upgrade," the post says [22]. That pitch implies the free upstream fix can mean a major version jump for a team on an old branch [22]. If a maintainer later adopts a backport Chainguard wrote, Chainguard deprecates its own version and points users upstream [15]. For teams that cannot swap a dependency quickly, shield partners turn the patch data into firewall rules, endpoint protections, application exploit blocking and traffic-level blocks [17].
The bugs came in through Athena. Members point frontier models at sandboxed applications and submit what they find through a secure portal [8]. Chainguard's premise is that those models now find vulnerabilities faster than disclosure and patching processes were built to absorb [18]. It picked this batch because acting on bugs that are already fixed does not step on anyone else's process. That let it run every step, from patch and advisory to partner mitigation and shipped artifact, and see what breaks [7].
Bugs still present at the latest version take a different route. They go through the Linux Foundation's Akrites initiative, and the maintainers ship the fix [9]. Chainguard says it has started to upstream five of those zero-days in recent weeks, including a critical fix in what it called an important package [10]. "The Akrites path is slower by design, and it's starting to move," the authors wrote [20].
What to watch
- Whether any of the 14 receive CVEs, putting them in the feeds that standard dependency scanners already read.
- Chainguard's promised details on the five zero-days moving through Akrites, including the critical upstream fix.
- Independent analysis of the critical bug from anyone other than Chainguard, including whether it is reachable in common deployments.