📦 Apko

by Chainguard

🔍 What is Apko?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25140

HIGH CVSS 7.5 Feb 4, 2026

This vulnerability in apko allows attackers who control or compromise APK repositories to cause resource exhaustion on build hosts. By serving a small, highly-compressed .apk file that expands into a ...

CVE-2026-25121

HIGH CVSS 7.5 Feb 4, 2026

A path traversal vulnerability in apko's dirFS filesystem abstraction allows attackers to create directories or symlinks outside the intended installation root. This affects users building OCI contain...

CVE-2026-25122

MEDIUM CVSS 5.5 Feb 4, 2026

This vulnerability in apko allows attackers to cause resource exhaustion by forcing excessive CPU usage during gzip inflation of malicious APK archives. It affects users who process untrusted APK stre...