
CVE-2026-25122 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream… https://www.cve.org/CVERecord?id=CVE-2026-25122
Post summary
The post announces CVE‑2026‑25122, noting that apko’s expandapk.Split improperly handles gzip streams when building OCI images, but provides no PoC, exploit code, or patch information.
