CVE detail
CVE-2026-33634
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- FBI: TeamPCP Compromised Dev Tools to Steal Cloud CredentialsSecurity Affairs
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The […]
newssecurityaffairs.comJul 4, 2026, 7:55 AM The European Union’s Computer Emergency Response Team, CERT-EU, has traced last week’s theft of data from the Europa.eu platform to the recent supply chain attack on Aqua Security’s Trivy open-source vulnerability scanner. The attack on the AWS cloud infrastructure hosting the Europa.eu web hub on March 24 resulted in the theft of 350 GB of […]
newswww.csoonline.comApr 3, 2026, 4:18 PM- Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: NIST updates its DNS security guidance for the first time in over a decade DNS infrastructure underpins nearly every network connection an organization makes, yet security configurations for it have gone largely unrevised at the federal guidance level for more than twelve years. NIST published SP 800-81r3, the Secure Domain Name System Deployment Guide, superseding a version that dates to … More →
newswww.helpnetsecurity.comMar 29, 2026, 8:00 AM - CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitationHelp Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and workflows, and CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security’s Trivy security scanner. Their addition to the catalog means that US federal civilian agencies are required to address the flaws within their networks by April 8 and 9, … More →
newswww.helpnetsecurity.comMar 27, 2026, 10:43 AM - U.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Aquasecurity Trivy flaw, tracked as CVE-2026-33634 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. On March 19, 2026, attackers used compromised credentials to release a malicious […]
newssecurityaffairs.comMar 27, 2026, 10:14 AM The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
newswww.securityweek.comMar 25, 2026, 11:55 AM- https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/www.microsoft.com
No excerpt available.
Technical Descriptionwww.microsoft.comMar 23, 2026, 10:16 PM No excerpt available.
Mitigationwww.cisa.govMar 23, 2026, 10:16 PM- https://rosesecurity.dev/2026/03/20/typosquatting-trivy.htmlrosesecurity.dev
No excerpt available.
Exploitrosesecurity.devMar 23, 2026, 10:16 PM No excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Not Applicablewww.wiz.ioMar 23, 2026, 10:16 PMNo excerpt available.
Broken Linkinspector.pypi.ioMar 23, 2026, 10:16 PMNo excerpt available.
Broken Linkinspector.pypi.ioMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Third Party Advisoryfuturesearch.aiMar 23, 2026, 10:16 PM- https://docs.litellm.ai/blog/security-update-march-2026docs.litellm.ai
No excerpt available.
Third Party Advisorydocs.litellm.aiMar 23, 2026, 10:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-46412CVSS 10.0 · Critical
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker u…
- CVE-2026-46421CVSS 9.3 · Critical
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool.…
- CVE-2026-45758CVSS 9.6 · Critical
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai…
- CVE-2026-48027CVSS 9.3 · Critical
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC,…
- CVE-2026-8398CVSS 9.3 · Critical
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate websi…
- CVE-2026-44484CVSS 9.3 · Critical
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting m…