Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7rp8-r62p-q6wc | `melange update-cache` has unbounded HTTP download that can exhaust disk in CI |
Tue, 10 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard
Chainguard melange |
|
| CPEs | cpe:2.3:a:chainguard:melange:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Chainguard
Chainguard melange |
Mon, 09 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard-dev
Chainguard-dev melange |
|
| Vendors & Products |
Chainguard-dev
Chainguard-dev melange |
Fri, 06 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. There is no known patch publicly available. | |
| Title | melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI | |
| Weaknesses | CWE-400 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T20:00:19.899Z
Reserved: 2026-03-03T17:50:11.243Z
Link: CVE-2026-29049
Updated: 2026-03-09T20:00:14.380Z
Status : Analyzed
Published: 2026-03-06T07:16:02.093
Modified: 2026-03-10T19:28:57.330
Link: CVE-2026-29049
No data.
OpenCVE Enrichment
Updated: 2026-04-16T11:30:15Z
Github GHSA