Количество 4
Количество 4
CVE-2026-54448
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.
CVE-2026-54448
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm ...
GHSA-q3fv-x8vg-qqm4
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
openSUSE-SU-2026:21249-1
Security update for trivy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-54448 Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54448 Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm ... | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-q3fv-x8vg-qqm4 Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser | 0% Низкий | 25 дней назад | ||
openSUSE-SU-2026:21249-1 Security update for trivy | около 1 месяца назад |
Уязвимостей на страницу