
CVE-2026-42574 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeS… https://www.cve.org/CVERecord?id=CVE-2026-42574
Post summary
The snippet announces a CVE (CVE-2026-42574) where a crafted apk may install unauthorized content during OCI image creation, targeting apko versions 0.14.8 through 1.2.5.

