PT-2026-6268 · Apko · Apko
1Seal
·
Published
2026-02-03
·
Updated
2026-02-20
·
CVE-2026-25122
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
apko versions 0.14.8 through 1.0.9
Description
apko is a tool for building and publishing OCI container images from apk packages. A flaw exists in the
expandapk.Split function where it drains the first gzip stream of an APK archive without explicit bounds. An attacker-controlled input stream can cause excessive gzip inflation, leading to resource exhaustion and potentially impacting availability. The Split function reads the first tar header and then drains the remaining gzip stream without limits on uncompressed byte size or inflation ratio. Parsing attacker-controlled APK streams may result in high CPU usage during gzip inflation, potentially causing timeouts or process slowdowns.Recommendations
Update to version 1.1.0 or later.
Exploit
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apko