Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54174— melange: Incomplete package integrity verification allows data section substitution

Quick assessment

Affected
chainguard-dev melange
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

melange 允许用户通过声明式流水线构建 APK 软件包。在 1.2.9 版本之前的 apko(对应 0.50.4 版本之前的 melange)仅验证控制段的哈希值(如 等),并与签名的 进行比对,但从未验证数据段的哈希值(即实际被安装的软件包文件)。攻击者若能篡改镜像源、污染缓存,或在对软件包的获取过程中实施中间人攻击(MITM),便可能在控制段哈希校验仍然通过的情况下,替换任意文件内容。apko 的 1.2.9 版本和 melange 的 0.50.4 版本已包含该问题的修复。

CVSS 8.3 · High EPSS 0.10% · P1

Affected Version Matrix 2

VendorProduct Version RangeStatus
chainguard-dev apko < 1.2.9 affected
chainguard-dev melange < 0.50.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54174

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
melange: Incomplete package integrity verification allows data section substitution
Source: CVE Program / CVE List V5
Vulnerability Description
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
完整性检查值验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
chainguard-dev melange < 0.50.4 -
chainguard-dev apko < 1.2.9 -

II. Public POCs for CVE-2026-54174

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54174

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54174 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54174

No comments yet


Leave a comment