CVE-2026-33634

unknown KEV
Published 2026-03-24 · Modified 2026-03-26
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
1.5

Description

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

CISA KEV

Vendor
Aquasecurity
Product
Trivy
Due date
2026-04-09

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev — This vulnerability involves a supply‑chain compromise in a product that may be used across multiple products and environments. Additional vendor‑provided guidance must be followed to ensure full remediation. For more information, please see: https://github.com/advisories/GHSA-69fq-xp46-6x23 ; https://nvd.nist.gov/vuln/detail/CVE-2026-33634}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/aquasecurity/trivy
GitHub Actionsaquasecurity/trivy-action<0.35.00.35.0
GitHub Actionsaquasecurity/setup-trivy<0.2.60.2.6
golang Gogithub.com/aquasecurity/trivy>=0.69.4

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.