Description
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.
Published: 2026-09-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Local code execution via package substitution
Action: Immediate Patch
AI Analysis

Impact

Melange builds APK packages from declarative pipelines. Affected Apko 1.2.9 and Melange 0.50.4 add a missing check: earlier versions verified only the control section (.PKGINFO etc.) against a signed APKINDEX but omitted verification of the data section containing the actual files that will be installed. If an attacker compromises a package mirror, poisons a cache, or performs a man‑in‑the‑middle attack while a package is fetched, they can replace those data section files with arbitrary content while the control hash check still succeeds. Once the package is installed on a target system, the substituted files can lead to arbitrary code execution or other malicious behaviors.

Affected Systems

Chainguard’s Apko tool versions before 1.2.9 and the Melange pipeline tool before 0.50.4 that build and distribute APK packages are affected the distributed version reaches the specific fixed releases; updated releases contain the fix.

Risk and Exploitability

The CVSS base score of 8.3 indicates a high severity vulnerability, yet the EPSS score of less than 1% suggests a very low probability of exploitation in current environments. The flaw is not listed in CISA KEV. Attackers can only exploit the weakness by tampering with the package distribution channel, so the vector is remote but requires control over or influence on an untrusted mirror or network. When succeeded, the possibility to replace arbitrary package files can provide an attacker with local code execution or data tampering on the systems that install the compromised packages.

Generated by OpenCVE AI on September 15, 2026 at 20:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apko to version 1.2.9 or later and Melange to version 0.50.4 or later.
  • Replace or harden the package mirrors used by Apko, ensuring they are authenticated and served over HTTPS to prevent MITM and cache poisoning.
  • Implement additional listing or code‑signature validation, to provide a second line of defense against data section tampering.

Generated by OpenCVE AI on September 15, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fpg8-7664-jc5q melange: Incomplete package integrity verification allows data section substitution
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Chainguard-dev
Chainguard-dev apko
Chainguard-dev melange
Vendors & Products Chainguard-dev
Chainguard-dev apko
Chainguard-dev melange

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.
Title melange: Incomplete package integrity verification allows data section substitution
Weaknesses CWE-345
CWE-354
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Chainguard-dev Apko Melange
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:19:01.111Z

Reserved: 2026-06-11T21:46:52.381Z

Link: CVE-2026-54174

cve-icon Vulnrichment

Updated: 2026-09-14T16:18:55.665Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:11.403

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-354

    Improper Validation of Integrity Check Value