CVE-2026-33634CISA KEV: Actively Exploited

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Published Mar 26, 2026·Updated Mar 26, 2026

Description

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

Public Exploits & PoCs4 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free