CPE
high
advisory
Path Traversal in Trivy via OCI Artifact Annotation
2 TTPs 1 CVETrivy versions prior to 0.71.1 are vulnerable to arbitrary file write via path traversal in OCI artifact titles, allowing attackers to overwrite files if a user is directed to an untrusted OCI registry.
Trivy
2t
1c
low
advisory
Trivy Unbounded Read Leads to Denial of Service via Helm Chart Tar Bomb
1 TTP 1 CVETrivy versions prior to 0.71.0 are vulnerable to CVE-2026-54448, a denial-of-service attack where a crafted Helm chart archive (.tgz) can cause unbounded memory consumption, leading to the OS OOM killer terminating the Trivy process and other services on the host or CI runner.
Trivy
supply-chain
vulnerability
denial-of-service
ci-cd
1t
1c