VYPR
Vendor

Aquasec

Products
3
CVEs
4
Across products
6
Status
Private

Products

3

Recent CVEs

4
  • CVE-2026-33634HigKEVMar 23, 2026
    risk 0.67cvss 8.8epss 0.59

    Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in…

  • CVE-2026-55092HigJun 25, 2026
    risk 0.42cvss 7.5epss 0.00

    Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled…

  • CVE-2026-54448MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive…

  • CVE-2026-26189MedFeb 19, 2026
    risk 0.31cvss 5.9epss 0.01

    Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 due to improper handling of action inputs when exporting environment variables.…