PT-2026-6270 · Apko · Apko

1Seal

·

Published

2026-02-04

·

Updated

2026-03-03

·

CVE-2026-25140

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions apko versions 0.14.8 through 1.1.0
Description apko is a tool that enables users to build and publish OCI container images from apk packages. A flaw exists where a malicious or compromised APK repository can lead to resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go does not limit decompression, allowing a small, highly compressed .apk file to expand into a large tar stream, potentially causing build failures or a denial of service.
Recommendations Update to version 1.1.1 or later.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-25140
GHSA-F4W5-5XV9-85F6
GO-2026-4410
SUSE-SU-2026:0757-1

Affected Products

Apko