PT-2026-23003 · Melange · Melange

1Seal

·

Publicado

2026-03-02

·

Atualizado

2026-03-25

·

CVE-2026-29049

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions melange versions prior to 0.40.5
Description melange enables users to create apk packages using declarative pipelines. In versions 0.40.5 and earlier, the melange update-cache function downloads URIs from build configurations using io.Copy without any size limitations or HTTP client timeouts. An attacker-controlled URI within a melange configuration can lead to unrestricted disk writes, potentially exhausting disk space on the build runner. The vulnerable code is located in pkg/renovate/cache/cache.go.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29049
GHSA-7RP8-R62P-Q6WC
GO-2026-4588
SUSE-SU-2026:1042-1

Produtos afetados

Melange