MEDIUM4.3
GHSA-7rp8-r62p-q6wc
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
Quick fix
GHSA-7rp8-r62p-q6wc — chainguard.dev/melange: upgrade to the fixed version with the command below.
go get chainguard.dev/melange@v0.43.4Details
`melange update-cache` downloads URIs from build configs via `io.Copy` without any size limit or HTTP client timeout (`pkg/renovate/cache/cache.go`). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runner. Affected versions <= 0.40.5.
**Fix:** Merged **Acknowledgements**
Thank you to Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/chainguard-dev/melange/security/advisories/GHSA-7rp8-r62p-q6wc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-29049[ADVISORY]
- https://github.com/chainguard-dev/melange/pull/2379[WEB]
- https://github.com/chainguard-dev/melange/commit/652ca5af08588f78e2d405e64b058fac8398d23f[WEB]
- https://github.com/chainguard-dev/melange[PACKAGE]
- https://github.com/chainguard-dev/melange/releases/tag/v0.43.4[WEB]