StackRadar

CVE-2026-33634

UnscoredKEV

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.592
99th percentile
CISA KEV
Listed
since 26 Mar 2026
Charts affected
11
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
None
affected package

Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
github.com/aquasecurity/trivygolangv0.71.0+dirty, v0.72.0, v0.74.0, v0.74.0+dirty+1 moreno fix listed11
OSV records
GO-2026-4919
Also known as
GHSA-69fq-xp46-6x23

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
harborharborOfficialVerified publisher1.19.21 of 8See more

harbor harbor 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/aquasecurity/trivy@v0.72.0
no fix listed

Open the chart page →

1,650
artifact-hubartifact-hubVerified publisher1.23.03 of 7See more

artifact-hub artifact-hub 1.23.0

3 of the 7 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
artifacthub/hub:v1.23.07d3a91c539dc
github.com/aquasecurity/trivy@v0.72.0
no fix listed
artifacthub/scanner:v1.23.02d8365601f0e
github.com/aquasecurity/trivy@v0.72.0
no fix listed
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/aquasecurity/trivy@v0.72.0
no fix listed

Open the chart page →

10,755
zotzot0.1.1241 of 1See more

zot zot 0.1.124

1 of the 1 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
github.com/aquasecurity/trivy@v0.74.0
no fix listed

Open the chart page →

318
trivytrivy-operator0.26.01 of 1See more

trivy trivy-operator 0.26.0

1 of the 1 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
aquasec/trivy:0.74.062b1e65e8869
github.com/aquasecurity/trivy@v0.74.0+dirty
no fix listed

Open the chart page →

430
sbomscannerkubewardenVerified publisher0.12.12 of 5See more

sbomscanner kubewarden 0.12.1

2 of the 5 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
ghcr.io/kubewarden/sbomscanner/controller:v0.12.1153ccb651e49
github.com/aquasecurity/trivy@v0.74.1-0.20260821131025-dc3c56eed58a
no fix listed
ghcr.io/kubewarden/sbomscanner/worker:v0.12.1b4274b7cc473
github.com/aquasecurity/trivy@v0.74.1-0.20260821131025-dc3c56eed58a
no fix listed

Open the chart page →

987
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/aquasecurity/trivy@v0.71.0+dirty
no fix listed

Open the chart page →

8,158
registry-mirrorssinextraVerified publisher2.0.191 of 1See more

registry-mirrors sinextra 2.0.19

1 of the 1 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
github.com/aquasecurity/trivy@v0.74.0
no fix listed

Open the chart page →

318
attestkeepattestkeepVerified publisher1.1.01 of 2See more

attestkeep attestkeep 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
ghcr.io/attestkeep/attestkeep-k8s:1.1.040f46bb38d0f
github.com/aquasecurity/trivy@v0.74.0+dirty
no fix listed

Open the chart page →

1,588
harborhelm-harborVerified publisher2.3.51 of 8See more

harbor helm-harbor 2.3.5

1 of the 8 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/aquasecurity/trivy@v0.72.0
no fix listed

Open the chart page →

1,650
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/aquasecurity/trivy@v0.74.0+dirty
no fix listed

Open the chart page →

1,837
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-33634.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/aquasecurity/trivy@v0.72.0
no fix listed

Open the chart page →

1,650

Container images carrying it

11 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/aquasecurity/trivy@v0.72.0
no fix listed
3
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
github.com/aquasecurity/trivy@v0.74.0
no fix listed
2
aquasec/trivy:0.74.062b1e65e8869
github.com/aquasecurity/trivy@v0.74.0+dirty
no fix listed
1
artifacthub/hub:v1.23.07d3a91c539dc
github.com/aquasecurity/trivy@v0.72.0
no fix listed
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/aquasecurity/trivy@v0.72.0
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/aquasecurity/trivy@v0.72.0
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/aquasecurity/trivy@v0.71.0+dirty
no fix listed
1
ghcr.io/attestkeep/attestkeep-k8s:1.1.040f46bb38d0f
github.com/aquasecurity/trivy@v0.74.0+dirty
no fix listed
1
ghcr.io/kubewarden/sbomscanner/controller:v0.12.1153ccb651e49
github.com/aquasecurity/trivy@v0.74.1-0.20260821131025-dc3c56eed58a
no fix listed
1
ghcr.io/kubewarden/sbomscanner/worker:v0.12.1b4274b7cc473
github.com/aquasecurity/trivy@v0.74.1-0.20260821131025-dc3c56eed58a
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/aquasecurity/trivy@v0.74.0+dirty
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.