« Back to list

Aquasec

Aquasec Trivy: vulnerabilities and CVEs

Aquasec Trivy has 7 published vulnerabilities, 6 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs7
Last 12 months6
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-33634Critical (9.4)1.7%⚠ Active exploitationMar 23, 2026
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-104994Low (2.5)——Oct 2, 2026
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a…
CVE-2026-63328Medium (6.8)0.19%—Aug 18, 2026
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who…
CVE-2026-55092High (7)0.44%—Jun 25, 2026
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An…
CVE-2026-54448Medium (6.9)0.44%—Jun 25, 2026
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file…
CVE-2026-33634Critical (9.4)1.7%⚠ Active exploitationMar 23, 2026
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to…
CVE-2026-28353Critical (10)0.45%—Mar 5, 2026
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code…
CVE-2024-35192Medium (5.5)0.19%—May 20, 2024
Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System2
  2. T1195 Supply Chain Compromise2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1203 Exploitation for Client Execution1
  5. T1565.001 Stored Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Aquasec