melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. There is no known patch publicly available.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7rp8-r62p-q6wc `melange update-cache` has unbounded HTTP download that can exhaust disk in CI
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 06 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
Description melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. There is no known patch publicly available.
Title melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI
Weaknesses CWE-400
CWE-918
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-06T07:03:10.361Z

Reserved: 2026-03-03T17:50:11.243Z

Link: CVE-2026-29049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T07:16:02.093

Modified: 2026-03-06T07:16:02.093

Link: CVE-2026-29049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses