github.com/aquasecurity/trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Activity
- Latest release
- 1mo ago
- Total releases
- 66
- Cadence
- ~27 days
- Last 12 months
- 16
Reach
- Stars
- 37.5k
Details
- First release
- May 08, 2019
| Version | Released | |
|---|---|---|
v0.74.0
minor
1 CVE
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.74.0
minor
Dependencies (125)
+ 117 more |
|
v0.73.0
minor
1 CVE
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.73.0
minor
Dependencies (125)
+ 117 more |
|
v0.72.0
minor
1 CVE
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.72.0
minor
Dependencies (126)
+ 118 more |
|
v0.71.2
minor
2 CVEs
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.71.2
minor
Dependencies (126)
+ 118 more |
|
v0.71.1
patch
2 CVEs
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.71.1
patch
Dependencies (126)
+ 118 more |
|
v0.71.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.71.0
minor
Dependencies (126)
+ 118 more |
|
v0.70.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33634
GO-2026-4919
GHSA-69fq-xp46-6x23
Apr 01, 2026
Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release. References
Updated Jun 16, 2026 · Source: OSV.dev |
v0.70.0
minor
Dependencies (128)
+ 120 more |
|
v0.69.3
patch
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.69.3
patch
Dependencies (129)
+ 121 more |
|
v0.69.2
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.69.2
minor
Dependencies (129)
+ 121 more |
|
v0.69.1
patch
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.69.1
patch
Dependencies (129)
+ 121 more |
|
v0.69.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.69.0
minor
Dependencies (129)
+ 121 more |
|
v0.68.2
patch
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.68.2
patch
Dependencies (126)
+ 118 more |
|
v0.68.1
patch
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.68.1
patch
Dependencies (126)
+ 118 more |
|
v0.68.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.68.0
minor
Dependencies (126)
+ 118 more |
|
v0.67.2
patch
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.67.2
patch
Dependencies (125)
+ 117 more |
|
v0.67.1
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.67.1
minor
Dependencies (125)
+ 117 more |
|
v0.67.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.67.0
minor
Dependencies (125)
+ 117 more |
|
v0.66.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.66.0
minor
Dependencies (128)
+ 120 more |
|
v0.65.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.65.0
minor
Dependencies (128)
+ 120 more |
|
v0.64.1
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.64.1
minor
Dependencies (127)
+ 119 more |
|
v0.63.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.63.0
minor
Dependencies (126)
+ 118 more |
|
v0.62.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.62.0
minor
Dependencies (126)
+ 118 more |
|
v0.61.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.61.0
minor
Dependencies (127)
+ 119 more |
|
v0.59.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.59.0
minor
Dependencies (128)
+ 120 more |
|
v0.58.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.58.0
minor
Dependencies (128)
+ 120 more |
|
v0.56.1
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.56.1
minor
Dependencies (125)
+ 117 more |
|
v0.54.0
minor
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.54.0
minor
Dependencies (126)
+ 118 more |
|
v0.51.3
patch
3 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev |
v0.51.3
patch
Dependencies (129)
+ 121 more |
|
v0.51.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.51.0
minor
Dependencies (129)
+ 121 more |
|
v0.50.2
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.50.2
minor
Dependencies (131)
+ 123 more |
|
v0.49.1
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.49.1
minor
Dependencies (113)
+ 105 more |
|
v0.46.1
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.46.1
patch
Dependencies (104)
+ 96 more |
|
v0.46.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.46.0
minor
Dependencies (104)
+ 96 more |
|
v0.39.1
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.39.1
patch
Dependencies (101)
+ 93 more |
|
v0.39.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.39.0
minor
Dependencies (101)
+ 93 more |
|
v0.38.3
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.38.3
patch
Dependencies (99)
+ 91 more |
|
v0.38.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.38.0
minor
Dependencies (99)
+ 91 more |
|
v0.37.1
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.37.1
minor
Dependencies (98)
+ 90 more |
|
v0.36.1
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.36.1
minor
Dependencies (96)
+ 88 more |
|
v0.35.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (96)
+ 88 more |
|
v0.32.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (90)
+ 82 more |
|
v0.31.2
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.31.2
minor
Dependencies (87)
+ 79 more |
|
v0.30.4
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.4
patch
Dependencies (80)
+ 72 more |
|
v0.30.2
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.2
patch
Dependencies (80)
+ 72 more |
|
v0.30.1
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.1
patch
Dependencies (80)
+ 72 more |
|
v0.30.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (80)
+ 72 more |
|
v0.29.1
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.29.1
patch
Dependencies (53)
+ 45 more |
|
v0.29.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (53)
+ 45 more |
|
v0.28.0
minor
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (49)
+ 41 more |
|
v0.25.4
patch
4 CVEs
CVE-2026-55092
GO-2026-6294
GHSA-mcj4-mphf-j9ff
Aug 26, 2026
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy Fixed in
0.71.1
References
Updated Aug 28, 2026 · Source: OSV.dev
CVE-2026-63328
GO-2026-6250
GHSA-8rc5-4fr6-64pw
Aug 25, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy Fixed in
0.72.0
References Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-54448
GO-2026-5983
GHSA-q3fv-x8vg-qqm4
Jul 27, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy Fixed in
0.71.0
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2024-35192
GO-2024-2870
GHSA-xcq4-m2r3-cmrj
May 22, 2024
Credential leakage in github.com/aquasecurity/trivy A malicious registry can cause Trivy to leak credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR) if the registry is scanned from directly using Trivy. These tokens can then be used to push/pull images from those registries to which the identity/user running Trivy has access. This vulnerability only applies when scanning container images directly from a registry. If you use Docker, containerd or other runtime to pull images locally and scan them with Trivy, you are not affected. To enforce this behavior, you can use the --image-src flag to select which sources you trust. Fixed in
0.51.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.25.4
patch
Dependencies (41)
+ 33 more |