PT-2026-6270 · Apko · Apko
1Seal
·
Published
2026-02-04
·
Updated
2026-03-03
·
CVE-2026-25140
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
apko versions 0.14.8 through 1.1.0
Description
apko is a tool that enables users to build and publish OCI container images from apk packages. A flaw exists where a malicious or compromised APK repository can lead to resource exhaustion on the build host. The
ExpandApk function in pkg/apk/expandapk/expandapk.go does not limit decompression, allowing a small, highly compressed .apk file to expand into a large tar stream, potentially causing build failures or a denial of service.Recommendations
Update to version 1.1.1 or later.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apko