Security

Trivy: what changed

In the last 90 days, 10 summarized changes: 5 security advisories, 3 releases, 2 fixes. Stackdiff reads Trivy's own feeds (trivy.dev) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

0.71.1Securitymedium
GO-2026-6294: Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy
0.71.1Securitymedium
GHSA-mcj4-mphf-j9ff: Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
0.72.0Securitymedium
GO-2026-6250: Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy
0.72.0Securitymedium
GHSA-8rc5-4fr6-64pw: Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
0.71.0Securitymedium
GHSA-q3fv-x8vg-qqm4: Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

0.71.1Securitymedium
GO-2026-6294: Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy
0.71.1Securitymedium
GHSA-mcj4-mphf-j9ff: Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
0.72.0Securitymedium
GO-2026-6250: Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy
0.72.0Securitymedium
GHSA-8rc5-4fr6-64pw: Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
0.74.0Release
v0.74.0
0.73.0Release
v0.73.0
0.71.0Securitymedium
GHSA-q3fv-x8vg-qqm4: Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
0.72.0Release
v0.72.0
0.71.2Fix
v0.71.2
0.71.1Fix
v0.71.1
0.71.0Release
v0.71.0
0.70.0Release
v0.70.0
0.2.6Securitymedium
GHSA-69fq-xp46-6x23: Trivy ecosystem supply chain was briefly compromised
0.69.3Fix
v0.69.3
0.69.2Fix
v0.69.2
0.69.1Release
v0.69.1
0.51.2Securitymedium
GHSA-xcq4-m2r3-cmrj: Trivy possibly leaks registry credential when scanning images from malicious registries

Where Stackdiff reads Trivy

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get Trivy changes in your Monday brief

Add Trivy and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other security tools