← Back to home
wid-sec-w-2026-0898  ·  Published 2026-03-29  ·  View on BSI CERT-Bund ↗

Aqua Security Trivy: Vulnerability allows vollständige Kompromittierung des Systems

CVSS 9.4 CRITICAL CISA KEV — Known Exploited

Risk Summary

Ein Angreifer kann eine Schwachstelle in Aqua Security Trivy ausnutzen, um das vollständige System zu kompromittieren.

CVEs (1)

Affected Vendors

Aqua Security

Affected Products (7)

Aqua Security · Trivy 0.69.4
Aqua Security · Trivy setup-trivy <0.2.6
Aqua Security · Trivy setup-trivy 0.2.6
Aqua Security · Trivy trivy-action <0.35.0
Aqua Security · Trivy trivy-action 0.35.0
Aqua Security · Trivy Container Image 0.69.5
Aqua Security · Trivy Container Image 0.69.6

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more