CVE-2026-24843Disclosure(chainguard / melange)

LOWCVSS 8.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries without validating that paths stay within the workspace, allowing path traversal via ../ sequences. This issue has been patched in version 0.40.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • melange

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
melange

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-04: 2Technical Details · 2026-02-04: 202-04
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-24843 - High melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files... https://www.thehackerwire.com/vulnerability/CVE-2026-24843/ https://t.co/uiyltYF7vw

    Post summary

    A high severity CVE-2026-24843 has been disclosed, impacting Melange’s APK builder by allowing an attacker to influence a tar stream from a QEMU guest to write files. The post provides technical details but no PoC, exploit code, or evidence of active exploitation.

    0000053
    113 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24843 melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU g… https://www.cve.org/CVERecord?id=CVE-2026-24843

    Post summary

    CVE-2026-24843 involves a potential attack surface in melange's APK build pipeline, where an attacker can influence the tar stream from QEMU; no evidence of PoC, exploit, or patch is provided.

    00000219
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchainguardmelange-go-

Explore more