
CVE-2026-29049 melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Cop… https://www.cve.org/CVERecord?id=CVE-2026-29049
Post summary
The post provides a brief disclosure of CVE-2026-29049, noting that melange allows APK builds via pipelines and that update‑cache downloads URIs in older versions, but offers no PoC, exploit, patch, or evidence of active exploitation.

