File Substitution Vulnerability in Melange by Chainguard
CVE-2026-54174

8.3HIGH

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-54174?

Melange, a tool for building APK packages with declarative pipelines, exhibits a significant vulnerability where the data section hash, which includes the actual package files, is not verified against the signed APKINDEX. Prior to the release of Melange version 0.50.4 and Apko version 1.2.9, this oversight allowed attackers to manipulate file contents by compromising mirrors, poisoning caches, or executing man-in-the-middle attacks during the package fetching process, while still passing the control hash check. The updated versions rectify this issue, enhancing the integrity and security of the package installation process.

Affected Version(s)

apko < 1.2.9

melange < 0.50.4

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.