Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2026-54448

около 1 месяца назад

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-54448

около 1 месяца назад

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q3fv-x8vg-qqm4

25 дней назад

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21249-1

около 1 месяца назад

Security update for trivy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-54448

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-54448

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm ...

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-q3fv-x8vg-qqm4

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

0%
Низкий
25 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21249-1

Security update for trivy

около 1 месяца назад

Уязвимостей на страницу