{"id":"GHSA-fpg8-7664-jc5q","summary":"melange: Incomplete package integrity verification allows data section substitution","details":"Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.","aliases":["CVE-2026-54174","GO-2026-5968"],"modified":"2026-07-21T19:54:01.970049402Z","published":"2026-07-10T21:43:05Z","database_specific":{"github_reviewed_at":"2026-07-10T21:43:05Z","nvd_published_at":null,"cwe_ids":["CWE-345","CWE-354"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/chainguard-dev/melange/security/advisories/GHSA-fpg8-7664-jc5q"},{"type":"PACKAGE","url":"https://github.com/chainguard-dev/melange"}],"affected":[{"package":{"name":"chainguard.dev/apko","ecosystem":"Go","purl":"pkg:golang/chainguard.dev/apko"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fpg8-7664-jc5q/GHSA-fpg8-7664-jc5q.json"}},{"package":{"name":"chainguard.dev/melange","ecosystem":"Go","purl":"pkg:golang/chainguard.dev/melange"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.50.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fpg8-7664-jc5q/GHSA-fpg8-7664-jc5q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}