Vulnerability record · CVE-2026-33634 · published 23 March 2026
CVE-2026-33634: Trivy and trivy-action supply chain compromise via malicious release and tags
Aquasec · Setup Trivy
A threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits. The attack continued a supply chain campaign that began in late February 2026, and a non-atomic credential rotation left a window in which newly rotated secrets could be exfiltrated. Because these components run inside CI/CD pipelines, any pipeline that executed an affected version may have exposed all secrets it could reach.
Description
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityActive supply chain exploitation is confirmed by CISA KEV listing, a very high EPSS score, and a CVSS 4.0 base of 9.4, with broad secret exposure across CI/CD pipelines.
What it is
A threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits. The attack continued a supply chain campaign that began in late February 2026, and a non-atomic credential rotation left a window in which newly rotated secrets could be exfiltrated. Because these components run inside CI/CD pipelines, any pipeline that executed an affected version may have exposed all secrets it could reach.
Impact
An attacker gains credentials and secrets accessible to affected build pipelines, enabling further repository and release tampering and lateral movement into downstream environments. The malicious release and tag rewrites also let the attacker distribute credential-stealing code to anyone consuming the mutable tags.
Attack surface
Reached through the software supply chain: pulling the Trivy v0.69.4 container image or Go binary, or referencing mutable version tags of aquasecurity/trivy-action or aquasecurity/setup-trivy in a workflow. No user interaction is required, and the CVSS vector indicates network reachability with low privileges; the victim does not need to be authenticated to the attacker's infrastructure, only to run the compromised artifact.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2026-03-26 with a 2026-04-09 due date, and EPSS gives a 30-day probability of 0.59164 (99th percentile). Reference tags include Exploit, and the vendor advisory and third-party analyses describe the attack as actively conducted.
What to do
- Remove or replace Trivy v0.69.4 and any affected trivy-action (0.0.1–0.34.2) or setup-trivy (0.2.0–0.2.6 prior to the safe recreation) artifacts; move to known safe versions 0.69.2/0.69.3, trivy-action 0.35.0, and setup-trivy 0.2.6.
- Treat every secret reachable by any pipeline that may have run a compromised version as exposed and rotate it immediately, including tokens, cloud credentials, and registry keys.
- Pin GitHub Actions to full immutable commit SHA hashes instead of mutable version tags.
- Review all workflows using aquasecurity/trivy-action or aquasecurity/setup-trivy and check workflow run logs from March 19–20, 2026 for signs of compromise.
- Search your GitHub organization for a repository named tpcp-docs, which may indicate the fallback exfiltration mechanism succeeded.
- Follow CISA BOD 22-01 guidance for cloud services and apply vendor mitigations or discontinue use where mitigations are unavailable.
Detection
- Hunt for workflow runs, container pulls, or binary executions of Trivy v0.69.4 and for trivy-action/setup-trivy references by tag rather than commit SHA.
- Review GitHub audit and workflow logs from March 19–20, 2026 for unexpected pushes, tag rewrites, or secret access in affected repositories.
- Search the GitHub organization for a repository named tpcp-docs and investigate any creation events around the attack window.
- Monitor for outbound connections or credential use from CI runners that executed affected Trivy components, and alert on anomalous secret access following those runs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-33634 to the Known Exploited Vulnerabilities catalog on 26 March 2026 as "Aquasecurity Trivy Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2026.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-33634 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-33634), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.