← Vulnerability feed

Vulnerability record · CVE-2026-33634 · published 23 March 2026

CVE-2026-33634: Trivy and trivy-action supply chain compromise via malicious release and tags

Aquasec · Setup Trivy

A threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits. The attack continued a supply chain campaign that began in late February 2026, and a non-atomic credential rotation left a window in which newly rotated secrets could be exfiltrated. Because these components run inside CI/CD pipelines, any pipeline that executed an affected version may have exposed all secrets it could reach.

9.4 CVSS 4.0 Critical CISA KEV since 26 Mar 2026 EPSS 1.7% · top 24.0% CWE-506 · CWE-506
9.4CVSS 4.0 base score
1.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
14References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityActive supply chain exploitation is confirmed by CISA KEV listing, a very high EPSS score, and a CVSS 4.0 base of 9.4, with broad secret exposure across CI/CD pipelines.

What it is

A threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits. The attack continued a supply chain campaign that began in late February 2026, and a non-atomic credential rotation left a window in which newly rotated secrets could be exfiltrated. Because these components run inside CI/CD pipelines, any pipeline that executed an affected version may have exposed all secrets it could reach.

Impact

An attacker gains credentials and secrets accessible to affected build pipelines, enabling further repository and release tampering and lateral movement into downstream environments. The malicious release and tag rewrites also let the attacker distribute credential-stealing code to anyone consuming the mutable tags.

Attack surface

Reached through the software supply chain: pulling the Trivy v0.69.4 container image or Go binary, or referencing mutable version tags of aquasecurity/trivy-action or aquasecurity/setup-trivy in a workflow. No user interaction is required, and the CVSS vector indicates network reachability with low privileges; the victim does not need to be authenticated to the attacker's infrastructure, only to run the compromised artifact.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-03-26 with a 2026-04-09 due date, and EPSS gives a 30-day probability of 0.59164 (99th percentile). Reference tags include Exploit, and the vendor advisory and third-party analyses describe the attack as actively conducted.

What to do

  • Remove or replace Trivy v0.69.4 and any affected trivy-action (0.0.1–0.34.2) or setup-trivy (0.2.0–0.2.6 prior to the safe recreation) artifacts; move to known safe versions 0.69.2/0.69.3, trivy-action 0.35.0, and setup-trivy 0.2.6.
  • Treat every secret reachable by any pipeline that may have run a compromised version as exposed and rotate it immediately, including tokens, cloud credentials, and registry keys.
  • Pin GitHub Actions to full immutable commit SHA hashes instead of mutable version tags.
  • Review all workflows using aquasecurity/trivy-action or aquasecurity/setup-trivy and check workflow run logs from March 19–20, 2026 for signs of compromise.
  • Search your GitHub organization for a repository named tpcp-docs, which may indicate the fallback exfiltration mechanism succeeded.
  • Follow CISA BOD 22-01 guidance for cloud services and apply vendor mitigations or discontinue use where mitigations are unavailable.

Detection

  • Hunt for workflow runs, container pulls, or binary executions of Trivy v0.69.4 and for trivy-action/setup-trivy references by tag rather than commit SHA.
  • Review GitHub audit and workflow logs from March 19–20, 2026 for unexpected pushes, tag rewrites, or secret access in affected repositories.
  • Search the GitHub organization for a repository named tpcp-docs and investigate any creation events around the attack window.
  • Monitor for outbound connections or credential use from CI runners that executed affected Trivy components, and alert on anomalous secret access following those runs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-33634 to the Known Exploited Vulnerabilities catalog on 26 March 2026 as "Aquasecurity Trivy Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2026.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33634 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-42208LiteLLM proxy SQL injection in API key checkLiteLLM versions 1.81.16 to before 1.83.7 build a database query for proxy API key checks by concatenating the caller-supplied key into the query tex…KEVEPSS 5.8%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed9.8CVE-2024-5751Litellm code injection vulnerabilityBerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_de…EPSS 0.88%9.8CVE-2024-2952Litellm vulnerabilityBerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_te…EPSS 1.3%9.5CVE-2026-49468Litellm authentication bypass by spoofing vulnerabilityLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM prox…EPSS 0.82%9.4CVE-2026-35030Litellm improper authentication vulnerabilityLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt…EPSS 0.88%8.8CVE-2026-40217Litellm code injection vulnerabilityLiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2026-33634), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.