PT-2026-23003 · Melange · Melange

1Seal

·

Published

2026-03-02

·

Updated

2026-03-25

·

CVE-2026-29049

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions melange versions prior to 0.40.5
Description melange enables users to create apk packages using declarative pipelines. In versions 0.40.5 and earlier, the melange update-cache function downloads URIs from build configurations using io.Copy without any size limitations or HTTP client timeouts. An attacker-controlled URI within a melange configuration can lead to unrestricted disk writes, potentially exhausting disk space on the build runner. The vulnerable code is located in pkg/renovate/cache/cache.go.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29049
GHSA-7RP8-R62P-Q6WC
GO-2026-4588
SUSE-SU-2026:1042-1

Affected Products

Melange