Aquasec develops container security and vulnerability-scanning tooling, with its primary exposure centered on the Trivy scanner and associated GitHub Actions integrations. The observed vulnerability signal reflects integration and command-handling concerns, including embedded malicious code and OS command injection risks within the tooling supply chain. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aquasec over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33634HIGH Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquas | Mar 23, 2026 | 8.8 | 93 | YES | NO |
CVE-2026-55092HIGH Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destinat | Jun 25, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-54448MEDIUM Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attac | Jun 25, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-26189HIGH Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31 | Feb 19, 2026 | 8.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aquasec.
Media articles that mention a CVE ID that affects a product developed by Aquasec — matched by CVE ID, not by vendor name.