Aquasec

Trivy

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 02.10.2026 19:52:36
  • Zuletzt bearbeitet 05.10.2026 18:17:33

Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contain...

  • EPSS 0.27%
  • Veröffentlicht 25.06.2026 16:27:33
  • Zuletzt bearbeitet 26.06.2026 19:27:05

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft ...

  • EPSS 0.29%
  • Veröffentlicht 25.06.2026 16:26:46
  • Zuletzt bearbeitet 27.06.2026 20:45:23

Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch ...

Warnung Medienbericht Exploit
  • EPSS 59.16%
  • Veröffentlicht 23.03.2026 21:47:29
  • Zuletzt bearbeitet 30.03.2026 18:50:38

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all ...