CVE-2026-54174: CWE-354: Improper Validation of Integrity Check Value in chainguard-dev melange
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.
AI Analysis
Technical Summary
The vulnerability arises from improper validation of the integrity check value (CWE-354) in melange and Apko. Specifically, the control section hash (e.g., .PKGINFO) was verified against the signed APKINDEX, but the data section hash, which covers the actual package files installed, was not validated. This gap enables an attacker with the ability to intercept or poison package sources to inject malicious or altered files without detection by the control hash verification. The flaw affects melange versions prior to 0.50.4 and Apko versions prior to 1.2.9. The vendor fixed the issue by adding verification of the data section hash in melange 0.50.4 and Apko 1.2.9.
Potential Impact
An attacker who can compromise a package mirror, cache, or perform a man-in-the-middle attack can substitute arbitrary package file contents while still passing the control hash verification. This can lead to the installation of malicious or altered files, potentially resulting in complete compromise of systems relying on these packages. The CVSS score of 8.3 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available. Users should upgrade to melange version 0.50.4 or later and Apko version 1.2.9 or later to ensure proper validation of the data section hash. Applying these updates mitigates the vulnerability by verifying the integrity of the actual package files, preventing substitution attacks.
CVE-2026-54174: CWE-354: Improper Validation of Integrity Check Value in chainguard-dev melange
Description
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed. Apko version 1.2.9 and melange version 0.50.4 contain a fix.
CVSS v3.1
Score 8.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from improper validation of the integrity check value (CWE-354) in melange and Apko. Specifically, the control section hash (e.g., .PKGINFO) was verified against the signed APKINDEX, but the data section hash, which covers the actual package files installed, was not validated. This gap enables an attacker with the ability to intercept or poison package sources to inject malicious or altered files without detection by the control hash verification. The flaw affects melange versions prior to 0.50.4 and Apko versions prior to 1.2.9. The vendor fixed the issue by adding verification of the data section hash in melange 0.50.4 and Apko 1.2.9.
Potential Impact
An attacker who can compromise a package mirror, cache, or perform a man-in-the-middle attack can substitute arbitrary package file contents while still passing the control hash verification. This can lead to the installation of malicious or altered files, potentially resulting in complete compromise of systems relying on these packages. The CVSS score of 8.3 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available. Users should upgrade to melange version 0.50.4 or later and Apko version 1.2.9 or later to ensure proper validation of the data section hash. Applying these updates mitigates the vulnerability by verifying the integrity of the actual package files, preventing substitution attacks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fpg8-7664-jc5q
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54174"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a520eab68715ace438f49af
Added to database: 07/11/2026, 09:36:43 UTC
Last enriched: 09/11/2026, 22:24:19 UTC
Last updated: 09/14/2026, 22:11:36 UTC
Views: 129
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.