Medium severity6.5NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-54448
CVE-2026-54448
Description
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/aquasecurity/trivyGo | < 0.71.0 | 0.71.0 |
Affected products
11- Range: <0.71.0
- osv-coords9 versionspkg:apk/chainguard/cloudbeat-8.19pkg:apk/chainguard/cloudbeat-9.2pkg:apk/chainguard/cloudbeat-fips-8.19pkg:apk/chainguard/trivy-operatorpkg:apk/chainguard/trivy-operator-fipspkg:apk/wolfi/trivy-operatorpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/trivy&distro=openSUSE%20Tumbleweed
< 8.19.18-r2+ 8 more
- (no CPE)range: < 8.19.18-r2
- (no CPE)range: < 9.2.8-r20
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 0.30.1-r26
- (no CPE)range: < 0.30.1-r23
- (no CPE)range: < 0.30.1-r26
- (no CPE)range: < 0.0.20260727T201416-160000.1.1
- (no CPE)range: < 0.72.0-160000.1.1
- (no CPE)range: < 0.71.2-2.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-q3fv-x8vg-qqm4ghsaADVISORY
- github.com/aquasecurity/trivy/pull/10718nvdIssue TrackingThird Party AdvisoryWEB
- github.com/aquasecurity/trivy/security/advisories/GHSA-q3fv-x8vg-qqm4nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-54448ghsaADVISORY
- github.com/aquasecurity/trivy/commit/441251e51ae46cbcf7f436547e0a5766b25328b4ghsaWEB
- github.com/aquasecurity/trivy/releases/tag/v0.71.0ghsaWEB
News mentions
0No linked articles in our index yet.