highCVSS 8.3Vulnerability
CVE-2026-54174
Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.
Properties
- ghsa_id
- GHSA-fpg8-7664-jc5q
- severity
- high
- summary
- melange: Incomplete package integrity verification allows data section substitution
- cvss_score
- 8.3
- cve_id
- CVE-2026-54174
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- is_ghsa_only
- false
- ghsa_published
- 2026-07-10T21:43:05Z
- source_url
- https://github.com/advisories/GHSA-fpg8-7664-jc5q
- ghsa_updated
- 2026-07-10T21:43:06Z
Related Entities (7)
VULNERABLE_TO (2)
←[Software]go/chainguard.dev/melange
←[Software]go/chainguard.dev/apko
AFFECTS (2)
→[Software]go/chainguard.dev/melange
→[Software]go/chainguard.dev/apko
HAS_WEAKNESS (2)
→[Weakness]Insufficient Verification of Data Authenticity
→[Weakness]Improper Validation of Integrity Check Value
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph