https://seclists.org/oss-sec/2026/q1/371: Trivy github actions po compromised, infostealer added
Published Mar 23, 2026
·Updated
Affected Software
2 affected components
github/aquasecurity/trivy-action
docker/aquasecurity/trivy=0.69.5, =0.69.6
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is currently under assessment due to the potential impact on users of the affected repositories.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, remove any compromised credentials and update the affected repositories from trusted sources.
3
What systems are affected by CVE-2026-XXXX?
CVE-2026-XXXX affects the GitHub Actions for the trivy-action and Docker images associated with aquasecurity.
4
What are the potential risks associated with CVE-2026-XXXX?
The potential risks include unauthorized access to the repository and potential deployment of malicious code.
5
When was CVE-2026-XXXX published?
CVE-2026-XXXX was published on March 23, 2026.