CVE-2026-42576Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *rsa.PublicKey without checking the key type. If a repository JWKS endpoint returns a non-RSA key (e.g. EC), the unchecked assertion panics and crashes apko. This affects any workflow that initializes the APK database and fetches repository keys. This issue has been patched in version 1.2.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 105-0505-0905-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-091
Disclosure1
2026-05-101
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-42576 apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go uncondition… https://www.cve.org/CVERecord?id=CVE-2026-42576

    Post summary

    CVE‑2026‑42576 affects apko's DiscoverKeys function before version 1.2.7, and a patch is available in v1.2.7.

    00010105
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42576 Denial of Service via Unchecked Type Assertion in apko Before 1.2.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42576 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A notification announcing a denial‑of‑service vulnerability (CVE-2026-42576) in apko before version 1.2.7, with links to vulnerability details but no evidence of exploitation or patch information.

    0000044
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 apko, Panic on non-RSA JWKS key, #CVE-2026-42576 (Moderate) https://dailycve.com/apko-panic-on-non-rsa-jwks-key-cve-2026-42576-moderate/

    Post summary

    CVE-2026-42576 is a moderately severe vulnerability causing a panic when a non‑RSA JWKS key is used in apko; the announcement lacks PoC, exploit, patch, or active exploitation details.

    0000035
    191 followersView on X

Explore more