Skip to main content
Loading…
    CVE-2026-24843 — melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside — CVE Database · The Intelligence Room