highCVSS 8.3Vulnerability

CVE-2026-54174

Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.

Properties

ghsa_id
GHSA-fpg8-7664-jc5q
severity
high
summary
melange: Incomplete package integrity verification allows data section substitution
cvss_score
8.3
cve_id
CVE-2026-54174
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-07-10T21:43:05Z
source_url
https://github.com/advisories/GHSA-fpg8-7664-jc5q
ghsa_updated
2026-07-10T21:43:06Z

Related Entities (7)

VULNERABLE_TO (2)

[Software]go/chainguard.dev/melange
[Software]go/chainguard.dev/apko

AFFECTS (2)

[Software]go/chainguard.dev/melange
[Software]go/chainguard.dev/apko

HAS_WEAKNESS (2)

[Weakness]Insufficient Verification of Data Authenticity
[Weakness]Improper Validation of Integrity Check Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54174 (CVSS 8.3) — Ninja Signal Threat Intelligence | Ninja Signal