CVE-2026-29049: melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI
melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runner. Affected versions <= 0.40.5.
Fix: Merged Acknowledgements
melange thanks Oleh Konko from 1seal for discovering and reporting this issue.
Other sources
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. Version 0.43.4 contains a patch.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
melangeto a version that resolves this vulnerability.Fixed in 0.43.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29049?
CVE-2026-29049 has been classified with a severity level that reflects potential risks associated with unbounded HTTP downloads causing disk exhaustion.
How do I fix CVE-2026-29049?
To fix CVE-2026-29049, ensure to update to versions of Melange beyond 0.40.5 that implement proper limits on HTTP download sizes.
Which versions are affected by CVE-2026-29049?
CVE-2026-29049 affects all versions of Melange up to and including 0.40.5.
What can attackers do with CVE-2026-29049?
Attackers can exploit CVE-2026-29049 to create unbounded downloads leading to depletion of disk space on the host.
Is there a workaround for CVE-2026-29049?
A temporary workaround for CVE-2026-29049 includes implementing monitoring on disk usage and reviewing build configurations for untrusted URIs.