CVE-2026-25140: apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
An attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression limits, allowing a malicious repository to serve a small, highly-compressed .apk that inflates into a large tar stream, consuming excessive disk space and CPU time, causing build failures or denial of service. Fix: Fixed in 2be3903. Released in 1.1.0. Acknowledgements apko thanks Oleh Konko (@1seal) from 1seal for discovering and reporting this issue.
Other sources
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression limits, allowing a malicious repository to serve a small, highly-compressed .apk that inflates into a large tar stream, consuming excessive disk space and CPU time, causing build failures or denial of service. This issue has been patched in version 1.1.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25140?
CVE-2026-25140 has a critical severity rating due to its potential for resource exhaustion on the build host.
How do I fix CVE-2026-25140?
To mitigate CVE-2026-25140, upgrade to version 1.1.0 or later of the chainguard-dev/apko package.
What causes CVE-2026-25140?
CVE-2026-25140 is caused by the ExpandApk function in apko not enforcing decompression limits during .apk stream expansions.
Who is affected by CVE-2026-25140?
Users of the chainguard-dev/apko package versions between 0.14.8 and 1.1.0 are affected by CVE-2026-25140.
What can an attacker do with CVE-2026-25140?
An attacker can exploit CVE-2026-25140 to cause resource exhaustion on the build host by serving specially crafted .apk files.