Skip to main content
ChainguardCybersecurity incident

Chainguard's Chainguard Images and Wolfi packages are affected by a supply chain vulnerability (CVE-2026-45784) originating from their dependency on the OpenSSL library.

What happened

Post: "I tested a rust-openssl security fix and found a missed path to attacker-controlled heap corruption - CVE-2026-45784"

Source

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/Pentesting
Stage
Confirmed
Event date
Sep 2026

Companies

  • OpenSSLAlso named

The full record

From the Signal API record

People

  • Ali FirasSecurity Researcher · Named in the post

Numbers

Mentions
1

Details

Timing
Completed
Category
Supply chain
Link URL
i.redd.it
Virality
Very low
Post kind
Image
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • security
  • vulnerability
  • supply chain
  • software supply chain

Products named

  • Chainguard Images
  • Wolfi packages

Extraction

Sentiment
Negative
Detected
Sep 13, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for Chainguard and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Chainguard this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/a60c29c7-838e-5f0b-a30b-10df2f4b0bb4 returns this record as JSON. POST /v1/companies/enrich returns every signal for chainguard.dev.

{
  "signal_id": "a60c29c7-838e-5f0b-a30b-10df2f4b0bb4",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-09-13T08:21:00+00:00",
  "company": {
    "name": "Chainguard",
    "domain": "chainguard.dev"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "people": [
      {
        "name": "Ali Firas",
        "role": "mentioned",
        "title": "Security Researcher"
      }
    ],
    "timing": "completed",
    "topics": [
      "security",
      "vulnerability",
      "supply chain",
      "software supply chain"
    ],
    "post_id": "1wf1wd4",
    "summary": "Chainguard's Chainguard Images and Wolfi packages are affected by a supply chain vulnerability (CVE-2026-45784) originating from their dependency on the OpenSSL library.",
    "category": "supply_chain",
    "evidence": [
      "[image] Chainguard / Wolfi Chainguard Images • Wolfi packages",
      "[image] ONE VULNERABILITY. 3+ YEARS ACROSS MAJOR SUPPLY CHAINS. openssl CVE-2026-45784"
    ],
    "link_url": "https://i.redd.it/4bdpfuvuy8ph1.png",
    "virality": "very_low",
    "image_url": "https://i.redd.it/4bdpfuvuy8ph1.png",
    "post_date": "2026-09-13T08:21:00.000Z",
    "post_kind": "image",
    "sentiment": "negative",
    "subreddit": "Pentesting",
    "event_date": "2026-09",
    "post_title": "I tested a rust-openssl security fix and found a missed path to attacker-controlled heap corruption - CVE-2026-45784",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/Pentesting/comments/1wf1wd4/i_tested_a_rustopenssl_security_fix_and_found_a/",
    "entity_role": "subject",
    "post_author": "thesmartshadow",
    "upvote_ratio": 0.8,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/Pentesting/",
    "total_upvotes": 3,
    "comments_total": 2,
    "total_comments": 2,
    "other_companies": [
      {
        "name": "OpenSSL",
        "role": "partner",
        "domain": "openssl.org"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/thesmartshadow/",
    "signal_category": "event",
    "comments_included": 0,
    "products_mentioned": [
      "Chainguard Images",
      "Wolfi packages"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.