CVE-2026-33634 details a critical supply chain attack against Trivy, a security scanner, where compromised credentials were used to publish a malicious v0.69.4 release and inject credential-stealing malware into specific versions of its GitHub Actions (`aquasecurity/trivy-action` and `aquasecurity/setup-trivy`). This vulnerability is rated 8.8 HIGH (CVSSv3.1) due to its network attack vector and high impact on confidentiality, integrity, and availability, potentially leading to widespread secret exfiltration from affected pipelines. The incident, a continuation of an earlier attack likely enabled by non-atomic credential rotation, is actively being exploited and has been added to CISA's Known Exploited Vulnerabilities catalog. Despite no public exploit code, it garners significant community attention and media coverage. Organizations must treat all secrets accessible to affected pipelines as compromised and rotate them immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.6CPE matchmatch criteria | cpe:2.3:a:aquasec:setup-trivy:*:*:*:*:*:*:*:* | ||
0.69.4CPE matchmatch criteria | cpe:2.3:a:aquasec:trivy:0.69.4:*:*:*:*:go:*:* | ||
< 0.35.0CPE matchmatch criteria | cpe:2.3:a:aquasec:trivy_action:*:*:*:*:*:*:*:* | ||
1.82.7CPE matchmatch criteria | cpe:2.3:a:litellm:litellm:1.82.7:*:*:*:*:*:*:* | ||
1.82.8CPE matchmatch criteria | cpe:2.3:a:litellm:litellm:1.82.8:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.