Alpine Linux is a lightweight, container-oriented Linux distribution whose compact vulnerability footprint belies its prominence in containerized and embedded deployments, where minimalism and supply-chain simplicity are prized. Vulnerabilities affecting the distribution skew toward serious outcomes and concentrate in core packaging and build infrastructure—Alpine Linux itself, the APK package manager and tooling, and the Aports repository—with recurring weaknesses in memory-safety, credential handling, and input validation that reflect the boundaries of a minimal userland and its integration points. Defenders relying on Alpine for container images and lightweight deployments should treat security updates for the base system and package tooling as high-priority given the distribution's role in the build and runtime supply chain; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alpinelinux over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000849HIGH Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code | Dec 20, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-9671HIGH A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz fi | Jul 17, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-9669HIGH A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz fil | Jul 17, 2017 | 7.8 | 26 | NO | NO |
CVE-2021-30139HIGH In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash. | Apr 21, 2021 | 7.5 | 23 | NO | NO |
CVE-2019-12875MEDIUM Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signi | Jun 18, 2019 | 6.5 | 22 | NO | NO |
CVE-2021-36158MEDIUM In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys ar | Jul 5, 2021 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alpinelinux.
Media articles that mention a CVE ID that affects a product developed by Alpinelinux — matched by CVE ID, not by vendor name.