Apko: melange: Incomplete package integrity verification allows data section substitution (CVE-2026-54174)
Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.
AI Analysis
Technical Summary
The vulnerability in Apko (chainguard.dev/apko) arises from incomplete package integrity verification. While the control section hash (such as .PKGINFO) was verified against the signed APKINDEX, the data section hash, which covers the actual files installed by the package, was not verified. This gap allows an attacker with the ability to compromise a package mirror, cache, or intercept package fetches to substitute arbitrary file contents without detection, as the control hash verification still passes. This issue affects versions prior to 1.2.9 and 0.50.4. The CVSS 3.1 vector indicates network attack complexity is high, no privileges required, user interaction required, scope changed, and high impact on confidentiality, integrity, and availability.
Potential Impact
An attacker capable of compromising a package mirror, poisoning a cache, or performing a man-in-the-middle attack can substitute arbitrary files in the package data section without detection. This can lead to full compromise of confidentiality, integrity, and availability of the system installing the package, as malicious or altered files may be installed despite passing control section hash verification.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using affected versions and obtain packages only from trusted, verified sources. Monitoring for updates from the vendor is recommended to apply any forthcoming patches addressing this vulnerability.
Apko: melange: Incomplete package integrity verification allows data section substitution (CVE-2026-54174)
Description
Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.
CVSS v3.1
Score 8.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Apko (chainguard.dev/apko) arises from incomplete package integrity verification. While the control section hash (such as .PKGINFO) was verified against the signed APKINDEX, the data section hash, which covers the actual files installed by the package, was not verified. This gap allows an attacker with the ability to compromise a package mirror, cache, or intercept package fetches to substitute arbitrary file contents without detection, as the control hash verification still passes. This issue affects versions prior to 1.2.9 and 0.50.4. The CVSS 3.1 vector indicates network attack complexity is high, no privileges required, user interaction required, scope changed, and high impact on confidentiality, integrity, and availability.
Potential Impact
An attacker capable of compromising a package mirror, poisoning a cache, or performing a man-in-the-middle attack can substitute arbitrary files in the package data section without detection. This can lead to full compromise of confidentiality, integrity, and availability of the system installing the package, as malicious or altered files may be installed despite passing control section hash verification.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using affected versions and obtain packages only from trusted, verified sources. Monitoring for updates from the vendor is recommended to apply any forthcoming patches addressing this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fpg8-7664-jc5q
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54174"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a520eab68715ace438f49af
Added to database: 07/11/2026, 09:36:43 UTC
Last enriched: 07/11/2026, 09:46:24 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.