apko是apko开源的一个基于 apk 的 OCI 镜像构建器。 apko 0.14.8版本至1.1.1之前版本存在资源管理错误漏洞,该漏洞源于ExpandApk函数未强制执行解压缩限制,可能导致资源耗尽、构建失败或拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chainguard-dev | apko | >= 0.14.8, < 1.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24843 | 8.2 HIGH | melange QEMU runner could write files outside workspace directory |
| CVE-2026-25143 | 7.8 HIGH | melange affected by potential host command execution via license-check YAML mode patch pip |
| CVE-2026-24844 | 7.8 HIGH | melange pipeline working-directory could allow command injection |
| CVE-2026-25121 | 7.5 HIGH | apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside |
| CVE-2026-25122 | 5.5 MEDIUM | apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-contro |
| CVE-2026-25145 | 5.5 MEDIUM | melange has a path traversal in license-path which allows reading files outside workspace |
No comments yet