Chainguard.dev/apko
This hub aggregates every CVE we track for Chainguard.dev/apko, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
2
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Chainguard.dev/apko.
- CVE-2026-25121apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base7.5
- CVE-2026-25122apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams5.5
- CVE-2025-53945apko has incorrect permission (0666) in /etc/ld.so.cache and other files7.0
- CVE-2024-36127apko Exposure of HTTP basic auth credentials in log output7.5
Product normalization is registry-driven with AI assist and human review. How it works