CVE-2026-29049
published 2026-03-06CVE-2026-29049: melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
0.23%
13.3th percentile
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. Version 0.43.4 contains a patch.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chainguard-dev | melange | < 0.43.4 | 0.43.4 |
| chainguard.dev | melange | 0 – 0.40.5 | — |
| chainguard | melange | <= 0.40.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
chainguard-dev melange up to 0.40.5 resource consumption (GHSA-7rp8-r62p-q6wc)
vuldb·2026-07-07·CVSS 4.3
CVE-2026-29049 [MEDIUM] chainguard-dev melange up to 0.40.5 resource consumption (GHSA-7rp8-r62p-q6wc)
A vulnerability was found in chainguard-dev melange up to 0.40.5 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation results in resource consumption.
This vulnerability is identified as CVE-2026-29049. The attack can be executed remotely. There is not any exploit available.
OSV
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
osv·2026-03-10
CVE-2026-29049 `melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI in chainguard.dev/melange
GHSA
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
ghsa·2026-03-02
CVE-2026-29049 [MEDIUM] CWE-400 `melange update-cache` has unbounded HTTP download that can exhaust disk in CI
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
`melange update-cache` downloads URIs from build configs via `io.Copy` without any size limit or HTTP client timeout (`pkg/renovate/cache/cache.go`). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runner. Affected versions <= 0.40.5.
**Fix:** Merged
**Acknowledgements**
melange thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.
OSV
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
osv·2026-03-02
CVE-2026-29049 [MEDIUM] `melange update-cache` has unbounded HTTP download that can exhaust disk in CI
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
`melange update-cache` downloads URIs from build configs via `io.Copy` without any size limit or HTTP client timeout (`pkg/renovate/cache/cache.go`). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runner. Affected versions <= 0.40.5.
**Fix:** Merged
**Acknowledgements**
melange thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.
No detection rules found.
No public exploits indexed.
2026-03-06
Published