Aller au contenu

Fiche vulnérabilité

CVE-2026-54448 : faille moyenne aquasec trivy (CVSS 6.5)

Description

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.

En bref

Sévérité
Moyenne (CVSS 6.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
25 juin 2026
Dernière mise à jour
26 juin 2026

Produits concernés

  • aquasec trivy

Références

Rechercher une autre vulnérabilité dans la base CVE