{"id":"CVE-2026-54174","aliases":["GO-2026-5968"],"url":"https://o3.security/vulnerability/CVE-2026-54174","summary":"melange: Incomplete package integrity verification allows data section substitution","details":"Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.","published":"2026-07-10T21:43:05Z","modified":"2026-07-21T19:19:20.019407554Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"chainguard.dev/apko","fixedVersion":"1.2.9"},{"ecosystem":"Go","name":"chainguard.dev/melange","fixedVersion":"0.50.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q"},{"type":"PACKAGE","url":"https://github.com/chainguard-dev/melange"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-21T19:19:20.019407554Z"}}