Security Flaw in apko Container Builder Software by Chainguard
CVE-2026-105768

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105768?

The vulnerability in apko, a tool for building and publishing OCI container images, involves improper parsing of user ID (UID) and group ID (GID) fields from /etc/passwd and /etc/group files. In affected versions (0.2.0 to <1.4.5), the application fails to validate these fields adequately, allowing an attacker to craft a malicious package that may result in the UID or GID being misinterpreted as 0 (root). This poses significant security risks as it creates potential for privilege escalation within the built images, allowing attackers to gain unauthorized root access. The issue has been addressed in version 1.4.5.

Affected Version(s)

apko 0.2.0 < 1.4.5

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fernando (https://github.com/fthomasella)
Jorge Lucangeli Obes (https://github.com/jlucangelio)
Steve Beattie (https://github.com/stevebeattie)
SunnyR (https://github.com/SunnyR)
Chainguard (https://chainguard.dev)
.