CVE-2026-25140
HIGHapko 0.14.8-1.1.1 - Denial of Service via Unbounded APK Decompression
Title source: llmDescription
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression limits, allowing a malicious repository to serve a small, highly-compressed .apk that inflates into a large tar stream, consuming excessive disk space and CPU time, causing build failures or denial of service. This issue has been patched in version 1.1.1.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/chainguard-dev/apko/security/advisories/GHSA-f4w5-5xv9-85f6
Scores
CVSS v3
7.5
EPSS
0.0037
EPSS Percentile
28.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
CWE-400
Status
published
Products (1)
chainguard/apko
0.14.8 - 1.1.1
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026