Apko
Chainguard-Dev · 10 CVEs
apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root
Oct 5, 2026
melange: Incomplete package integrity verification allows data section substitution
Sep 11, 2026
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
May 9, 2026
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
May 9, 2026
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
May 9, 2026
apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
Feb 4, 2026
apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base
Feb 4, 2026
apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Feb 4, 2026
apko has incorrect permission (0666) in /etc/ld.so.cache and other files
Jul 18, 2025
apko Exposure of HTTP basic auth credentials in log output
Jun 3, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-105768 | apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root | MEDIUM | 0.30% | Oct 5, 2026 |
| CVE-2026-54174 | melange: Incomplete package integrity verification allows data section substitution | HIGH | 0.15% | Sep 11, 2026 |
| CVE-2026-42576 | apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery | MEDIUM | 0.45% | May 9, 2026 |
| CVE-2026-42575 | apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) | HIGH | 0.23% | May 9, 2026 |
| CVE-2026-42574 | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root | HIGH | 0.51% | May 9, 2026 |
| CVE-2026-25140 | apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams | HIGH | 0.41% | Feb 4, 2026 |
| CVE-2026-25121 | apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base | HIGH | 0.42% | Feb 4, 2026 |
| CVE-2026-25122 | apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams | MEDIUM | 0.13% | Feb 4, 2026 |
| CVE-2025-53945 | apko has incorrect permission (0666) in /etc/ld.so.cache and other files | HIGH | 0.13% | Jul 18, 2025 |
| CVE-2024-36127 | apko Exposure of HTTP basic auth credentials in log output | HIGH | 0.44% | Jun 3, 2024 |
Showing 1 to 10 of 10 CVEs