All 4 CVE vulnerabilities found in trivy, with AI-generated Chinese analysis, references, and POCs.
Vendor: aquasecurity
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-63328 | Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write CWE-22 | 6.8 | Medium | 2026-08-18 |
| CVE-2026-54448 | Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser CWE-770 | - | - | 2026-06-25 |
| CVE-2026-55092 | Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts CWE-22 | - | - | 2026-06-25 |
| CVE-2024-35192 | Trivy possibly leaks registry credential when scanning images from malicious registries CWE-522 | 5.5 | Medium | 2024-05-20 |
All 4 known CVE vulnerabilities affecting trivy with full Chinese analysis, references, and POCs where available.