PT-2026-6268 · Apko · Apko

·

CVE-2026-25122

·

Publicado

2026-02-03

·

Atualizado

2026-02-20

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions apko versions 0.14.8 through 1.0.9
Description apko is a tool for building and publishing OCI container images from apk packages. A flaw exists in the expandapk.Split function where it drains the first gzip stream of an APK archive without explicit bounds. An attacker-controlled input stream can cause excessive gzip inflation, leading to resource exhaustion and potentially impacting availability. The Split function reads the first tar header and then drains the remaining gzip stream without limits on uncompressed byte size or inflation ratio. Parsing attacker-controlled APK streams may result in high CPU usage during gzip inflation, potentially causing timeouts or process slowdowns.
Recommendations Update to version 1.1.0 or later.

Exploit

Correção

Allocation of Resources Without Limits

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25122
GHSA-6P9P-Q6WH-9J89
GO-2026-4406
SUSE-SU-2026:0403-1

Produtos afetados

Apko