CVE-2026-29051 Details
Description
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) constructs output file paths by joining `--out-dir` with the `arch` and `pkgname` values read from the `.PKGINFO` control file of the APK being linted. In affected versions these values were not validated for path separators or `..` sequences, so an attacker who can supply an APK to a melange-based lint/build pipeline (e.g. CI that lints third-party APKs, or build-as-a-service) could cause melange to write `lint-<pkgname>-<pkgver>-r<epoch>.json` to an arbitrary `.json` path reachable by the melange process. The written file is a JSON lint report whose content is partially attacker-influenced. There is no direct code-execution path, but the write can clobber other JSON artifacts on the filesystem. The issue only affects deployments that explicitly pass `--persist-lint-results`; the flag is off by default. The issue is fixed in melange v0.43.4 by validating `arch` and `pkgname` for `..`, `/`, and `filepath.Separator` before path construction in `pkg/linter/results.go` (commit 84f3b45). As a workaround, do not pass `--persist-lint-results` when linting or building APKs whose `.PKGINFO` contents are not fully trusted. Running melange as a low-privileged user and confining writes to an isolated directory also limits impact.
A path traversal vulnerability has been identified in Melange versions 0.32.0 prior to 0.43.4. The issue arises when using the opt-in flag '--persist-lint-results' with the 'melange lint' or 'melange build' commands. In these versions, the output file paths for lint results were constructed by combining the '--out-dir' option with the 'arch' and 'pkgname' values extracted from the APK's '.PKGINFO' control file. However, these values were not properly validated for path separators or parent directory sequences. As a result, an attacker could manipulate the 'arch' or 'pkgname' fields to write lint result files to arbitrary locations within the file system, potentially overwriting other JSON artifacts. This vulnerability only affects deployments that explicitly use the '--persist-lint-results' flag, which is off by default.
Users can upgrade to Melange version 0.43.4 or later, where this vulnerability has been fixed. If an immediate upgrade is not possible, do not use the '--persist-lint-results' flag when working with APKs whose '.PKGINFO' contents cannot be fully trusted. Additionally, running Melange as a low-privileged user and restricting file writes to a separate directory can help mitigate the impact.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chainguard-dev/melange/commit/84f3b450ce6e472c4abb8dc4c26d0ce8ac1259ac | [email protected] | Patch |
| https://github.com/chainguard-dev/melange/security/advisories/GHSA-q2pw-xx38-p64j | [email protected] | MitigationPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| chainguard melange | >= 0.32.0, < 0.43.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | New CVE Received | [email protected] |