CVE-2026-54174High· 8.3▾ Twilightmelange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (.PKGINFO etc.) against the signed APKINDEX, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
chainguard.dev/apko < 1.2.9chainguard.dev/melange < 0.50.4Patched in:
chainguard.dev/apko 1.2.9chainguard.dev/melange 0.50.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-29049Medium· 4.3melange allows users to build apk packages using declarative pipelines
CVE-2026-26007Medium· 6.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-63405Medium· 5.9AnyCable is a realtime server for reliable two-way communication that supports any backend
CVE-2026-82549High· 8.3A vulnerability was identified in Linux Foundation Magma 1.9.0
CVE-2026-54167High· 8.2Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library