Feed/CVE-2026-54174
CVE-2026-54174HIGHCVSS 8.3

melange: Incomplete package integrity verification allows data section substitution

Published Jul 10, 2026·Updated Jul 10, 2026

NVD Description

Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.

Affected Packages (2)

chainguard.dev/melangeGO
Fixed in 0.50.4
chainguard.dev/apkoGO
Fixed in 1.2.9

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free