chainguard.dev/apko
Go8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting chainguard.dev/apkopage 1 of 1
- CVE-2024-36127HIGHCVSS 7.5EG 7.5✓ Fixed in 0.14.52024-06-03
apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.
- CVE-2025-53945HIGHCVSS 7.0EG 7.0✓ Fixed in 0.29.52025-07-18
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. V…
- CVE-2026-25121HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.02026-02-04
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a ma…
- CVE-2026-25122MEDIUMCVSS 5.5EG 5.5✓ Fixed in 1.1.02026-02-04
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream of an APK archive via io.Copy(io.Discard, gzi) without explicit bounds. …
- CVE-2026-25140HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.12026-02-04
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build h…
- CVE-2026-42574HIGHCVSS 7.5EG 7.5✓ Fixed in 1.2.52026-05-09
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subse…
- CVE-2026-42575HIGHCVSS 7.5EG 7.5✓ Fixed in 1.2.72026-05-09
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares individually downloaded .apk packages against the checksum recor…
- CVE-2026-42576MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.2.72026-05-09
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *rsa.PublicKey without checking the key ty…
Check whether chainguard.dev/apko is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for chainguard.dev/apko CVEs against the assets you own.
Start Free Scan →