FlawAtlas
Search the atlas
OPENSUSE-SU-2026:21249-1 Not scored

Security update for trivy

This update for trivy fixes the following issues Update to version 0.72.0. - CVE-2026-54448: tar unpacker reads scanned Helm chart archives (.tgz) with `io.ReadAll(tr)` and defines no size limit, which can lead to a DoS (bsc#1269271). - CVE-2026-55092: `org.opencontainers.image.title` annotation from OCI artifact manifest is used as a destination filename without validation and can lead to arbitrary file writes (bsc#1269269). Other updates and bugfixes: - Version 0.72.0: * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893) * fix(misconf): support github_repository_vulnerability_alerts resource (#10680) * feat(java): detect JAR licenses from packaged LICENSE files (#10856) * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861) * fix(server): propagate package repository class in client/server mode (#10874) * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888) * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795) * feat(java): detect JAR licenses from the embedded pom.xml (#10851) * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863) * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873) * chore(deps): bump alpine to 3.24.1 (#10868) * docs: fix article typo in plugin developer guide (#10860) * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848) * docs: fix typos (#10857) * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843) * feat(secret): support new stateless format for GitHub App installation tokens (#10826) * fix: correct format verbs in diagnostic messages (#10805) * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845) * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830) * docs: fix repository scan heading typo (#10828) * fix: forward ospkg detector options through ospkg.NewScanner (#10811) * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801) * fix(vex): load VEX documents from within the repository directory (#10820) * ci!: migrate docker config to dockers_v2 (#10783) * feat(dotnet): detect bundled runtime in self-contained deployments (#10786) * feat(secret): add OpenAI secret detection rules (#10798) * ci: expect GitHub App bot as backport PR author (#10813) * fix: surface the original analysis error instead of context cancellation (#10793) * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803) * chore(deps): bump the common group with 4 updates (#10797) * chore(deps): bump the aws group with 4 updates (#10796) * fix: use random suffix for process temp directory instead of PID (#10431) * docs: update signature verification for deb and rpm packages (#10784) * fix(image): lookup origin layer for custom resources in merged layers (#10788) * ci: bump GoReleaser to v2.16.0 (#10774) * docs: fix broken nixpkgs reference link in installation guide (#10776) * fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777) * fix(spdx): guard against nil root component in SPDX marshaler (#10771) * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)

Exploit probability Not scored
Published July 7, 2026
Required by Not available
Last source change July 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 trivy

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:21249-1

This update for trivy fixes the following issues Update to version 0.72.0. - CVE-2026-54448: tar unpacker reads scanned Helm chart archives (.tgz) with `io.ReadAll(tr)` and defines no size limit, which can lead to a DoS (bsc#1269271). - CVE-2026-55092: `org.opencontainers.image.title` annotation from OCI artifact manifest is used as a destination filename without validation and can lead to arbitrary file writes (bsc#1269269). Other updates and bugfixes: - Version 0.72.0: * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893) * fix(misconf): support github_repository_vulnerability_alerts resource (#10680) * feat(java): detect JAR licenses from packaged LICENSE files (#10856) * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861) * fix(server): propagate package repository class in client/server mode (#10874) * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888) * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795) * feat(java): detect JAR licenses from the embedded pom.xml (#10851) * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863) * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873) * chore(deps): bump alpine to 3.24.1 (#10868) * docs: fix article typo in plugin developer guide (#10860) * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848) * docs: fix typos (#10857) * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843) * feat(secret): support new stateless format for GitHub App installation tokens (#10826) * fix: correct format verbs in diagnostic messages (#10805) * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845) * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830) * docs: fix repository scan heading typo (#10828) * fix: forward ospkg detector options through ospkg.NewScanner (#10811) * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801) * fix(vex): load VEX documents from within the repository directory (#10820) * ci!: migrate docker config to dockers_v2 (#10783) * feat(dotnet): detect bundled runtime in self-contained deployments (#10786) * feat(secret): add OpenAI secret detection rules (#10798) * ci: expect GitHub App bot as backport PR author (#10813) * fix: surface the original analysis error instead of context cancellation (#10793) * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803) * chore(deps): bump the common group with 4 updates (#10797) * chore(deps): bump the aws group with 4 updates (#10796) * fix: use random suffix for process temp directory instead of PID (#10431) * docs: update signature verification for deb and rpm packages (#10784) * fix(image): lookup origin layer for custom resources in merged layers (#10788) * ci: bump GoReleaser to v2.16.0 (#10774) * docs: fix broken nixpkgs reference link in installation guide (#10776) * fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777) * fix(spdx): guard against nil root component in SPDX marshaler (#10771) * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)

View original source

05 / REFERENCES

Further evidence