CVE-2026-54448
- EPSS 0.27%
- Veröffentlicht 25.06.2026 16:27:33
- Zuletzt bearbeitet 26.06.2026 19:27:05
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft ...
CVE-2026-55092
- EPSS 0.29%
- Veröffentlicht 25.06.2026 16:26:46
- Zuletzt bearbeitet 27.06.2026 20:45:23
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch ...
CVE-2026-33634
- EPSS 59.16%
- Veröffentlicht 23.03.2026 21:47:29
- Zuletzt bearbeitet 30.03.2026 18:50:38
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all ...