Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard-dev
Chainguard-dev apko |
|
| Vendors & Products |
Chainguard-dev
Chainguard-dev apko |
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression limits, allowing a malicious repository to serve a small, highly-compressed .apk that inflates into a large tar stream, consuming excessive disk space and CPU time, causing build failures or denial of service. This issue has been patched in version 1.1.1. | |
| Title | apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T19:17:36.596Z
Reserved: 2026-01-29T15:39:11.820Z
Link: CVE-2026-25140
Updated: 2026-02-04T19:17:31.427Z
Status : Awaiting Analysis
Published: 2026-02-04T19:16:15.117
Modified: 2026-02-05T14:57:20.563
Link: CVE-2026-25140
No data.
OpenCVE Enrichment
Updated: 2026-02-05T11:39:19Z