CVE-2026-25122 is a resource exhaustion vulnerability affecting Chainguard apko versions 0.14.8 through 1.0.x. The apko tool, used for building OCI container images, can be forced to perform excessive gzip inflation on attacker-controlled APK archives, leading to CPU exhaustion and denial of service. This vulnerability has a CVSS score of 5.5 (Medium) due to its low attack complexity and high availability impact, requiring user interaction (UI:R) for exploitation. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The issue has been patched in apko version 1.1.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.14.8, < 1.1.0CPE matchmatch criteria | cpe:2.3:a:chainguard:apko:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.