cbcvebase.

Chainguard-Dev Apko vulnerabilities

8 known vulnerabilities affecting chainguard-dev/apko.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-42574P3HIGHCVSS 7.5v>= 0.14.8, < 1.2.52026-05-09
CVE-2026-42574 [HIGH] CWE-22 CVE-2026-42574: apko allows users to build and publish OCI container images built from apk packages. From version 0. apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host
nvd
CVE-2026-25121P3HIGHCVSS 7.5v>= 0.14.8, < 1.1.12026-02-04
CVE-2026-25121 [HIGH] CWE-23 CVE-2026-25121: apko allows users to build and publish OCI container images built from apk packages. From version 0. apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a malicious APK package (e.g., via a compromised or typosquatted repository) could create directories or symlinks outsi
nvd
CVE-2026-42575P3HIGHCVSS 7.5fixed in 1.2.72026-05-09
CVE-2026-42575 [HIGH] CWE-345 CVE-2026-42575: apko allows users to build and publish OCI container images built from apk packages. Prior to versio apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares individually downloaded .apk packages against the checksum recorded in the signed index. The checksum is parsed and available via ChecksumString(), and the downloaded package con
nvd
CVE-2026-25140P3HIGHCVSS 7.5v>= 0.14.8, < 1.1.12026-02-04
CVE-2026-25140 [HIGH] CWE-400 CVE-2026-25140: apko allows users to build and publish OCI container images built from apk packages. From version 0. apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression
nvd
CVE-2024-36127P3HIGHCVSS 7.5fixed in 0.14.52024-06-03
CVE-2024-36127 [HIGH] CWE-522 CVE-2024-36127: apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository a apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.
nvd
CVE-2026-42576P4MEDIUMCVSS 6.5fixed in 1.2.72026-05-09
CVE-2026-42576 [MEDIUM] CWE-704 CVE-2026-42576: apko allows users to build and publish OCI container images built from apk packages. Prior to versio apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *rsa.PublicKey without checking the key type. If a repository JWKS endpoint returns a non-RSA key (e.g. EC), the unchecked assertion panics and crashes ap
nvd
CVE-2025-53945P4HIGHCVSS 7.0v>= 0.27.0, < 0.29.52025-07-18
CVE-2025-53945 [HIGH] CWE-276 CVE-2025-53945: apko allows users to build and publish OCI container images built from apk packages. Starting in ver apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
nvd
CVE-2026-25122P4MEDIUMCVSS 5.5v>= 0.14.8, < 1.1.02026-02-04
CVE-2026-25122 [MEDIUM] CWE-400 CVE-2026-25122: apko allows users to build and publish OCI container images built from apk packages. From version 0. apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream of an APK archive via io.Copy(io.Discard, gzi) without explicit bounds. With an attacker-controlled input stream, this can force large gzip inflation work and lead to resource exhausti
nvd
Chainguard-Dev Apko vulnerabilities | cvebase