Impact
Melative pipelines. In versions before 0.40.5, the update-cache command downloads URIs from build configurations using io.Copy without imposing a size limit or HTTP client timeout. An attacker‑controlled URI in a melange config can therefore cause unbounded disk writes, exhausting disk on the CI runner during a build. The vulnerability corresponds to CWE‑400 and CWE‑918. This description has been updated to include additional details. The issue is fixed in version 0.43.4.
Affected Systems
Chainguard’s melange, version 0.40.5 and earlier, are affected. The flaw resides in the pkg module. Any environment that runs melange update-cache with a build configuration containing attacker‑supplied download URLs is exposed.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is < likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog and no exploitation reports are documented in the CVE data. The likely attack vector is remote delivery via a compromised or malicious build definition. An build failures and resource denial for other jobs.
OpenCVE Enrichment
Github GHSA