Trivy ecosystem supply chain was briefly compromised
Affected range
SEMVER: introduced 0.69.4Go package metadata, published advisories, affected versions, and known-exploitation evidence.
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
v0.74.0
Published advisories match this version
Known exploitation
CISA KEV match
CVE-2026-33634
Highest advisory severity
Critical
5 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
SEMVER: introduced 0.69.4Affected range
SEMVER: introduced 0; fixed 0.71.1Fixed versions: 0.71.1
Affected range
SEMVER: introduced 0; fixed 0.71.0Fixed versions: 0.71.0
Affected range
SEMVER: introduced 0; fixed 0.72.0Fixed versions: 0.72.0
Affected range
SEMVER: introduced 0; fixed 0.51.2Fixed versions: 0.51.2