VYPR

Trivy

by Aquasec

Source repositories

CVEs (3)

  • CVE-2026-33634HigKEVMar 23, 2026
    risk 0.67cvss 8.8epss 0.59

    Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in…

  • CVE-2026-55092HigJun 25, 2026
    risk 0.42cvss 7.5epss 0.00

    Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled…

  • CVE-2026-54448MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive…