PT-2026-23003 · Melange · Melange
1Seal
·
Published
2026-03-02
·
Updated
2026-03-25
·
CVE-2026-29049
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
melange versions prior to 0.40.5
Description
melange enables users to create apk packages using declarative pipelines. In versions 0.40.5 and earlier, the
melange update-cache function downloads URIs from build configurations using io.Copy without any size limitations or HTTP client timeouts. An attacker-controlled URI within a melange configuration can lead to unrestricted disk writes, potentially exhausting disk space on the build runner. The vulnerable code is located in pkg/renovate/cache/cache.go.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Melange