cbcvebase.
CVE-2025-54059
published 2025-07-18

CVE-2025-54059: melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange…

PriorityP419medium4.4CVSS 3.1
AVLACLPRLUINSUCNILAL
EPSS
0.13%
2.6th percentile
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue.

Affected

2 ranges
VendorProductVersion rangeFixed in
chainguard-devmelange
chainguard.devmelange>= 0.23.0 < 0.29.50.29.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.