
CVE-2026-25145 melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration fi… https://www.cve.org/CVERecord?id=CVE-2026-25145
Post summary
The text announces CVE‑2026‑25145, indicating that melange versions 0.14.0 through before 0.40.3 are vulnerable when an attacker can influence configuration, but no PoC or exploitation details are provided.
