<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:15:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03951</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03951</link>
      <description>bdu:2026-03951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03951</guid>
    </item>
    <item>
      <title>EUVD-2026-278078</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278078</link>
      <description>EUVD-2026-278078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278078</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33634</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33634</link>
      <description>&lt;p&gt;Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one&amp;#39;s environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one&amp;#39;s organization pulled or…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one&amp;#39;s environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one&amp;#39;s organization pulled or…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33634</guid>
    </item>
    <item>
      <title>GHSA-69fq-xp46-6x23 — Trivy ecosystem supply chain was briefly compromised</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-69fq-xp46-6x23</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/aquasecurity/trivy, GitHub Actions: aquasecurity/trivy-action, GitHub Actions: aquasecurity/setup-trivy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits.
On March 22, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.5 and v0.69.6 DockerHub images.&lt;/p&gt;
&lt;p&gt;## Exposure Window&lt;/p&gt;
&lt;p&gt;| Component     | Start (UTC)            | End (UTC)         | Duration  |
| ------------- | ---------------------- | ----------------- | --------- |
| trivy v0.69.4 | 2026-03-19 18:22 [^1]  | 2026-03-19 ~21:42 | ~3 hours  |
| trivy-action  | 2026-03-19 ~17:43 [^2] | 2026-03-20 ~05:40 | ~12 hours |
| setup-trivy   | 2026-03-19 ~17:43 [^2] | 2026-03-19 ~21:44 | ~4 hours  |
| dockerhub trivy images v0.69.5 and v0.69.6 | 2026-03-22 15:43  | 2026-03-23 ~01:40 | ~10 hours  |&lt;/p&gt;
&lt;p&gt;[^1]: Time when v0.69.4 release artifacts became publicly available. The malicious tag was pushed at ~17:43 UTC, triggering the release pipeline.
[^2]: Earliest suspicious activity observed in our audit log.
## Affected Components&lt;/p&gt;
&lt;p&gt;Note that all malicious components, artifacts, commits, etc have been removed from all sources and destinations (yet they may linger in intermediary caches). Use this information to understand if you have been exposed to the malicious artifacts during the exposure window.&lt;/p&gt;
&lt;p&gt;### `trivy` binary and image&lt;/p&gt;
&lt;p&gt;You are affected if you used:
1. trivy bin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/aquasecurity/trivy, GitHub Actions: aquasecurity/trivy-action, GitHub Actions: aquasecurity/setup-trivy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits.
On March 22, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.5 and v0.69.6 DockerHub images.&lt;/p&gt;
&lt;p&gt;## Exposure Window&lt;/p&gt;
&lt;p&gt;| Component     | Start (UTC)            | End (UTC)         | Duration  |
| ------------- | ---------------------- | ----------------- | --------- |
| trivy v0.69.4 | 2026-03-19 18:22 [^1]  | 2026-03-19 ~21:42 | ~3 hours  |
| trivy-action  | 2026-03-19 ~17:43 [^2] | 2026-03-20 ~05:40 | ~12 hours |
| setup-trivy   | 2026-03-19 ~17:43 [^2] | 2026-03-19 ~21:44 | ~4 hours  |
| dockerhub trivy images v0.69.5 and v0.69.6 | 2026-03-22 15:43  | 2026-03-23 ~01:40 | ~10 hours  |&lt;/p&gt;
&lt;p&gt;[^1]: Time when v0.69.4 release artifacts became publicly available. The malicious tag was pushed at ~17:43 UTC, triggering the release pipeline.
[^2]: Earliest suspicious activity observed in our audit log.
## Affected Components&lt;/p&gt;
&lt;p&gt;Note that all malicious components, artifacts, commits, etc have been removed from all sources and destinations (yet they may linger in intermediary caches). Use this information to understand if you have been exposed to the malicious artifacts during the exposure window.&lt;/p&gt;
&lt;p&gt;### `trivy` binary and image&lt;/p&gt;
&lt;p&gt;You are affected if you used:
1. trivy bin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-69fq-xp46-6x23</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0898 — Aqua Security Trivy: Schwachstelle ermöglicht vollständige Kompromittierung des Systems</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0898</link>
      <description>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in Aqua Security Trivy ausnutzen, um das vollständige System zu kompromittieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in Aqua Security Trivy ausnutzen, um das vollständige System zu kompromittieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0898</guid>
    </item>
  </channel>
</rss>
