<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T18:04:27.915115+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15349</id>
    <title>bdu:2026-15349</title>
    <updated>2026-10-09T18:04:27.921056+00:00</updated>
    <content>bdu:2026-15349</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330383</id>
    <title>EUVD-2026-330383</title>
    <updated>2026-10-09T18:04:27.921095+00:00</updated>
    <content>EUVD-2026-330383</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54448</id>
    <title>fkie_cve-2026-54448</title>
    <updated>2026-10-09T18:04:27.921109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q3fv-x8vg-qqm4</id>
    <title>GHSA-q3fv-x8vg-qqm4 — Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser</title>
    <updated>2026-10-09T18:04:27.921147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/aquasecurity/trivy</p>
<p>## Summary</p>
<p>When Trivy scans a Helm chart archive (`.tgz`), its custom tar unpacker reads each entry with `io.ReadAll(tr)` and no size limit. An attacker who can place a malicious `.tgz` file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer.</p>
<p>## Affected configurations</p>
<p>Exploitation requires the attacker to place a crafted `.tgz` file in a location that Trivy will scan as a Helm chart. This applies to the following scan targets:</p>
<p>| Command | Condition |
| --- | --- |
| `trivy config &lt;dir&gt;` | Directory contains a crafted `.tgz` Helm chart (misconfiguration scanning is always enabled) |
| `trivy filesystem --scanners misconf &lt;dir&gt;` | Directory contains a crafted `.tgz` Helm chart **and** `--scanners misconf` is explicitly enabled |
| `trivy image --scanners misconf &lt;image&gt;` | Image contains a crafted `.tgz` Helm chart **and** `--scanners misconf` is explicitly enabled |</p>
<p>Realistic scenarios include:
- A CI pipeline that runs `trivy config .` on a repository where a contributor can submit a pull request containing a crafted chart archive.
- A pipeline that scans a container image with `--scanners misconf`, whose build context includes untrusted `.tgz` files.</p>
<p>## Impact</p>
<p>An attacker who satisfies the conditions above can exhaust all available memory on the host running Trivy. The OS OOM killer will terminate the Trivy process and may affect other processes sharing the same host or…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q3fv-x8vg-qqm4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11162-1</id>
    <title>openSUSE-SU-2026:11162-1 — trivy-0.71.2-2.1 on GA media</title>
    <updated>2026-10-09T18:04:27.921230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>trivy-0.71.2-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11162-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2082</id>
    <title>WID-SEC-W-2026-2082 — Aqua Security Trivy: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-09T18:04:27.921249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Aqua Security Trivy ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2082"/>
  </entry>
</feed>
