PT-2026-6268 · Apko · Apko

1Seal

·

Published

2026-02-03

·

Updated

2026-02-20

·

CVE-2026-25122

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions apko versions 0.14.8 through 1.0.9
Description apko is a tool for building and publishing OCI container images from apk packages. A flaw exists in the expandapk.Split function where it drains the first gzip stream of an APK archive without explicit bounds. An attacker-controlled input stream can cause excessive gzip inflation, leading to resource exhaustion and potentially impacting availability. The Split function reads the first tar header and then drains the remaining gzip stream without limits on uncompressed byte size or inflation ratio. Parsing attacker-controlled APK streams may result in high CPU usage during gzip inflation, potentially causing timeouts or process slowdowns.
Recommendations Update to version 1.1.0 or later.

Exploit

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-25122
GHSA-6P9P-Q6WH-9J89
GO-2026-4406
SUSE-SU-2026:0403-1

Affected Products

Apko