melange vulnerabilities
CVEs whose affected-version data names the melange package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54174High· 8.3melange allows users to build apk packages using declarative pipelines
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…
▾ Twilightchainguard-dev · melangeEPSS 0.10%via NVD
CVE-2026-29049Medium· 4.3melange allows users to build apk packages using declarative pipelines
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…
▾ Sunlitchainguard · melangeEPSS 0.22%via NVD