Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-29049

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk writes, exhausting disk on the build runne. Version 0.43.4 contains a patch.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.3%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-29049


Contact Us

Shodan ® - All rights reserved