CVE-2026-25140: apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams

Published Feb 4, 2026
·
Updated

An attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression limits, allowing a malicious repository to serve a small, highly-compressed .apk that inflates into a large tar stream, consuming excessive disk space and CPU time, causing build failures or denial of service. Fix: Fixed in 2be3903. Released in 1.1.0. Acknowledgements apko thanks Oleh Konko (@1seal) from 1seal for discovering and reporting this issue.

Other sources

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk streams without enforcing decompression limits, allowing a malicious repository to serve a small, highly-compressed .apk that inflates into a large tar stream, consuming excessive disk space and CPU time, causing build failures or denial of service. This issue has been patched in version 1.1.1.

— MITRE

Affected Software

2 affected componentsFixes available
go/chainguard-dev/apko>0.14.8<1.1.0
1.1.0
chainguard Apko Go>=0.14.8<1.1.1

Event History

Feb 4, 2026
Advisory Published
via GitHub·12:07 AM
Data Sourced
via GitHub·12:07 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-25140?

CVE-2026-25140 has a critical severity rating due to its potential for resource exhaustion on the build host.

2

How do I fix CVE-2026-25140?

To mitigate CVE-2026-25140, upgrade to version 1.1.0 or later of the chainguard-dev/apko package.

3

What causes CVE-2026-25140?

CVE-2026-25140 is caused by the ExpandApk function in apko not enforcing decompression limits during .apk stream expansions.

4

Who is affected by CVE-2026-25140?

Users of the chainguard-dev/apko package versions between 0.14.8 and 1.1.0 are affected by CVE-2026-25140.

5

What can an attacker do with CVE-2026-25140?

An attacker can exploit CVE-2026-25140 to cause resource exhaustion on the build host by serving specially crafted .apk files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203