{"id":"CVE-2026-54174","title":"melange allows users to build apk packages using declarative pipelines","summary":"melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-345","CWE-354"],"vendor":"chainguard-dev","product":"melange","affected":["melange < 0.50.4","apko < 1.2.9"],"patched":["chainguard.dev/apko 1.2.9","chainguard.dev/melange 0.50.4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T17:17:47.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54174","references":[{"url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-fpg8-7664-jc5q"}],"tags":["nvd","cve.org","ghsa","go"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-14T16:18:49.717621Z"},"epss":0.00105,"epssPercentile":0.01198,"aliases":["GHSA-fpg8-7664-jc5q"],"ecosystem":"go","ingestedAt":"2026-07-10T22:06:49.364Z","slug":"CVE-2026-54174","body":"## Overview\n\nmelange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54174)\n\nAffected packages:\n\n- `chainguard.dev/apko < 1.2.9`\n- `chainguard.dev/melange < 0.50.4`\n\nPatched in:\n\n- `chainguard.dev/apko 1.2.9`\n- `chainguard.dev/melange 0.50.4`\n\nSource: https://github.com/advisories/GHSA-fpg8-7664-jc5q","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":45.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}