StackRadar

CVE-2026-63328

Medium

Advisory

Published 18 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
20
deployed by those charts
Fix available
1 of 1
affected package

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 20 images.

Affected packageAffected versionsFixed inImages
github.com/aquasecurity/trivygolangv0.29.2, v0.32.0, v0.37.1, v0.43.1+12 more0.72.020
OSV records
GHSA-8rc5-4fr6-64pw
Also known as
GO-2026-6250

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
github.com/aquasecurity/trivy@v0.69.3
0.72.0
artifacthub/scanner:v1.23.02d8365601f0e
github.com/aquasecurity/trivy@v0.69.3
0.72.0

Open the chart page →

10,755
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/aquasecurity/trivy@v0.46.0
0.72.0

Open the chart page →

2,898
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
github.com/aquasecurity/trivy@v0.37.1
0.72.0

Open the chart page →

5,598
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/aquasecurity/trivy@v0.56.2
0.72.0

Open the chart page →

1,542
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/aquasecurity/trivy@v0.71.0+dirty
0.72.0

Open the chart page →

8,158
artifact-hubsoftonic1.19.04 of 8See more

artifact-hub softonic 1.19.0

4 of the 8 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
aquasec/trivy:0.43.1944a04445179
github.com/aquasecurity/trivy@v0.43.1
0.72.0
artifacthub/hub:v1.19.0111918d8c399
github.com/aquasecurity/trivy@v0.52.2
0.72.0
artifacthub/scanner:v1.19.0323d026e78c3
github.com/aquasecurity/trivy@v0.50.1
0.72.0
artifacthub/tracker:v1.19.06596c8c4d955
github.com/aquasecurity/trivy@v0.52.2
0.72.0

Open the chart page →

14,491
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.72.0

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.72.0

Open the chart page →

68,240
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/aquasecurity/trivy@v0.69.3
0.72.0

Open the chart page →

3,376
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/aquasecurity/trivy@v0.55.2
0.72.0

Open the chart page →

1,893
harborkubesphereVerified publisher1.9.31 of 11See more

harbor kubesphere 1.9.3

1 of the 11 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/aquasecurity/trivy@v0.29.2
0.72.0

Open the chart page →

17,798
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
github.com/aquasecurity/trivy@v0.32.0
0.72.0

Open the chart page →

4,271
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/aquasecurity/trivy@v0.48.3
0.72.0

Open the chart page →

9,774
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.72.0

Open the chart page →

68,240
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/aquasecurity/trivy@v0.44.0
0.72.0

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/aquasecurity/trivy@v0.44.1
0.72.0

Open the chart page →

2,505
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/aquasecurity/trivy@v0.51.2
0.72.0

Open the chart page →

2,477
trivy-webhook-aws-security-hubtrivy-webhook-aws-security-hubVerified publisher0.1.201 of 1See more

trivy-webhook-aws-security-hub trivy-webhook-aws-security-hub 0.1.20

1 of the 1 container images this version deploys carry CVE-2026-63328.

Container imageDigestPackageFixed in
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
github.com/aquasecurity/trivy@v0.69.3
0.72.0

Open the chart page →

616

Container images carrying it

20 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.72.0
3
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/aquasecurity/trivy@v0.51.2
0.72.0
1
aquasec/trivy:0.43.1944a04445179
github.com/aquasecurity/trivy@v0.43.1
0.72.0
1
aquasec/trivy:0.32.0973d0df16189
github.com/aquasecurity/trivy@v0.32.0
0.72.0
1
aquasec/trivy:0.69.3bcc376de8d77
github.com/aquasecurity/trivy@v0.69.3
0.72.0
1
artifacthub/hub:v1.19.0111918d8c399
github.com/aquasecurity/trivy@v0.52.2
0.72.0
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/aquasecurity/trivy@v0.69.3
0.72.0
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/aquasecurity/trivy@v0.50.1
0.72.0
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/aquasecurity/trivy@v0.52.2
0.72.0
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/aquasecurity/trivy@v0.37.1
0.72.0
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/aquasecurity/trivy@v0.69.3
0.72.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/aquasecurity/trivy@v0.29.2
0.72.0
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/aquasecurity/trivy@v0.44.0
0.72.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/aquasecurity/trivy@v0.71.0+dirty
0.72.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/aquasecurity/trivy@v0.44.1
0.72.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/aquasecurity/trivy@v0.46.0
0.72.0
1
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
github.com/aquasecurity/trivy@v0.69.3
0.72.0
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/aquasecurity/trivy@v0.56.2
0.72.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/aquasecurity/trivy@v0.48.3
0.72.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/aquasecurity/trivy@v0.55.2
0.72.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.