PT-2026-57371 · Apko · Apko

CVE-2026-54174

·

Published

2026-07-10

·

Updated

2026-09-12

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apko (affected versions not specified)
Description Incomplete package integrity verification allows for data section substitution. The software verified the control section hash (such as .PKGINFO) against the signed APKINDEX but failed to verify the data section hash, which contains the actual package files being installed. This flaw allows an attacker who compromises a mirror, poisons a cache, or performs a Man-in-the-Middle (MITM) attack during a package fetch to substitute arbitrary file contents while the control hash check still passes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54174
GHSA-FPG8-7664-JC5Q
GO-2026-5968
OPENSUSE-SU-2026:21483-1

Affected Products

Apko