Product
high
advisory
Incomplete Package Integrity Verification in Chainguard apko and melange Allows Data Section Substitution
2 TTPsA critical vulnerability, CVE-2026-54174, in Chainguard's apko and melange packages allows attackers to substitute arbitrary file contents within packages due to incomplete integrity verification, potentially leading to remote code execution.
apko +1
supply-chain
package-manager
integrity-bypass
remote-code-execution
defense-evasion
2t
high
advisory
Apko Package Substitution Vulnerability
2 rules 1 TTPApko versions prior to 1.2.7 are vulnerable to package substitution due to not verifying downloaded apk packages against the APKINDEX checksum, potentially allowing an attacker who can substitute download responses to install arbitrary packages into built images.
apko +1
package-substitution
supply-chain
linux
2r
1t