melange是Chainguard开源的一个从源代码构建APK的软件。 melange 0.40.3之前版本存在路径遍历漏洞,该漏洞源于提取tar归档时未验证路径,可能导致路径遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chainguard-dev | melange | >= 0.11.3, < 0.40.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-25143 | 7.8 HIGH | melange affected by potential host command execution via license-check YAML mode patch pip |
| CVE-2026-24844 | 7.8 HIGH | melange pipeline working-directory could allow command injection |
| CVE-2026-25121 | 7.5 HIGH | apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside |
| CVE-2026-25140 | 7.5 HIGH | apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attack |
| CVE-2026-25122 | 5.5 MEDIUM | apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-contro |
| CVE-2026-25145 | 5.5 MEDIUM | melange has a path traversal in license-path which allows reading files outside workspace |
No comments yet