GHSA-fpg8-7664-jc5q

Suggest an improvement
Source
https://github.com/advisories/GHSA-fpg8-7664-jc5q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fpg8-7664-jc5q/GHSA-fpg8-7664-jc5q.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-fpg8-7664-jc5q
Aliases
Downstream
CGA (4)
MINI (2)
Published
2026-07-10T21:43:05Z
Modified
2026-07-21T19:54:01Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
melange: Incomplete package integrity verification allows data section substitution
Details

Previously, Apko verified the control section hash (.PKGINFO etc.) against the signed APKINDEX, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.

Database specific
{
    "cwe_ids":  [
        "CWE-345",
        "CWE-354"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-10T21:43:05Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Go / chainguard.dev/apko

Package

Name
chainguard.dev/apko
View open source insights on deps.dev
Purl
pkg:golang/chainguard.dev/apko

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fpg8-7664-jc5q/GHSA-fpg8-7664-jc5q.json"

Go / chainguard.dev/melange

Package

Name
chainguard.dev/melange
View open source insights on deps.dev
Purl
pkg:golang/chainguard.dev/melange

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.50.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fpg8-7664-jc5q/GHSA-fpg8-7664-jc5q.json"