Denial of Service Vulnerability in Trivy Security Scanner
CVE-2026-54448

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-54448?

Trivy, a popular security scanner developed by Aqua Security, has a vulnerability that affects its ability to process Helm chart archives before version 0.71.0. This issue allows an attacker to manipulate a .tgz file in a way that it unpacks into an excessively large volume of data, potentially leading to the termination of the Trivy process by the operating system's Out Of Memory (OOM) killer. This can result in service disruption and hinder security scanning efforts. The vulnerability has been addressed in the subsequent version, 0.71.0, enhancing the resilience of Trivy against such exploitation.

Affected Version(s)

trivy < 0.71.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.