
CVE-2026-25140 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an A… https://www.cve.org/CVERecord?id=CVE-2026-25140
Post summary
The text announces CVE-2026-25140 as a vulnerability affecting apko versions 0.14.8 through 1.1.1, enabling attackers with control over the build process to exploit container image creation.
