File Substitution Vulnerability in Melange by Chainguard
CVE-2026-54174
8.3HIGH
What is CVE-2026-54174?
Melange, a tool for building APK packages with declarative pipelines, exhibits a significant vulnerability where the data section hash, which includes the actual package files, is not verified against the signed APKINDEX. Prior to the release of Melange version 0.50.4 and Apko version 1.2.9, this oversight allowed attackers to manipulate file contents by compromising mirrors, poisoning caches, or executing man-in-the-middle attacks during the package fetching process, while still passing the control hash check. The updated versions rectify this issue, enhancing the integrity and security of the package installation process.
Affected Version(s)
apko < 1.2.9
melange < 0.50.4
