
🟠 CVE-2026-24843 - High melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files... https://www.thehackerwire.com/vulnerability/CVE-2026-24843/ https://t.co/uiyltYF7vw
Post summary
A high severity CVE-2026-24843 has been disclosed, impacting Melange’s APK builder by allowing an attacker to influence a tar stream from a QEMU guest to write files. The post provides technical details but no PoC, exploit code, or evidence of active exploitation.

