Security Flaw in apko Container Builder Software by Chainguard
CVE-2026-105768
6.3MEDIUM
What is CVE-2026-105768?
The vulnerability in apko, a tool for building and publishing OCI container images, involves improper parsing of user ID (UID) and group ID (GID) fields from /etc/passwd and /etc/group files. In affected versions (0.2.0 to <1.4.5), the application fails to validate these fields adequately, allowing an attacker to craft a malicious package that may result in the UID or GID being misinterpreted as 0 (root). This poses significant security risks as it creates potential for privilege escalation within the built images, allowing attackers to gain unauthorized root access. The issue has been addressed in version 1.4.5.
Affected Version(s)
apko 0.2.0 < 1.4.5
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Fernando (https://github.com/fthomasella)
Jorge Lucangeli Obes (https://github.com/jlucangelio)
Steve Beattie (https://github.com/stevebeattie)
SunnyR (https://github.com/SunnyR)
Chainguard (https://chainguard.dev)
