Aquasec
Aquasec Trivy: vulnerabilities and CVEs
Aquasec Trivy has 7 published vulnerabilities, 6 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.
CVEs7
Last 12 months6
Critical2
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33634 | Critical (9.4) | 1.7% | ⚠ Active exploitation | Mar 23, 2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-104994 | Low (2.5) | — | — | Oct 2, 2026 | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a… |
| CVE-2026-63328 | Medium (6.8) | 0.19% | — | Aug 18, 2026 | Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who… |
| CVE-2026-55092 | High (7) | 0.44% | — | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An… |
| CVE-2026-54448 | Medium (6.9) | 0.44% | — | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file… |
| CVE-2026-33634 | Critical (9.4) | 1.7% | ⚠ Active exploitation | Mar 23, 2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to… |
| CVE-2026-28353 | Critical (10) | 0.45% | — | Mar 5, 2026 | Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code… |
| CVE-2024-35192 | Medium (5.5) | 0.19% | — | May 20, 2024 | Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.