openSUSE-SU-2026:21249-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21249-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21249-1
Upstream
CVE (2)
Related
Published
2026-07-07T16:21:44Z
Modified
2026-07-09T18:24:31Z
Summary
Security update for trivy
Details

This update for trivy fixes the following issues

Update to version 0.72.0.

  • CVE-2026-54448: tar unpacker reads scanned Helm chart archives (.tgz) with io.ReadAll(tr) and defines no size limit, which can lead to a DoS (bsc#1269271).
  • CVE-2026-55092: org.opencontainers.image.title annotation from OCI artifact manifest is used as a destination filename without validation and can lead to arbitrary file writes (bsc#1269269).

Other updates and bugfixes:

  • Version 0.72.0:
    • feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893)
    • fix(misconf): support github_repository_vulnerability_alerts resource (#10680)
    • feat(java): detect JAR licenses from packaged LICENSE files (#10856)
    • fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861)
    • fix(server): propagate package repository class in client/server mode (#10874)
    • chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888)
    • fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795)
    • feat(java): detect JAR licenses from the embedded pom.xml (#10851)
    • chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)
    • ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873)
    • chore(deps): bump alpine to 3.24.1 (#10868)
    • docs: fix article typo in plugin developer guide (#10860)
    • feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848)
    • docs: fix typos (#10857)
    • fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843)
    • feat(secret): support new stateless format for GitHub App installation tokens (#10826)
    • fix: correct format verbs in diagnostic messages (#10805)
    • ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845)
    • refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830)
    • docs: fix repository scan heading typo (#10828)
    • fix: forward ospkg detector options through ospkg.NewScanner (#10811)
    • chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)
    • fix(vex): load VEX documents from within the repository directory (#10820)
    • ci!: migrate docker config to dockers_v2 (#10783)
    • feat(dotnet): detect bundled runtime in self-contained deployments (#10786)
    • feat(secret): add OpenAI secret detection rules (#10798)
    • ci: expect GitHub App bot as backport PR author (#10813)
    • fix: surface the original analysis error instead of context cancellation (#10793)
    • chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803)
    • chore(deps): bump the common group with 4 updates (#10797)
    • chore(deps): bump the aws group with 4 updates (#10796)
    • fix: use random suffix for process temp directory instead of PID (#10431)
    • docs: update signature verification for deb and rpm packages (#10784)
    • fix(image): lookup origin layer for custom resources in merged layers (#10788)
    • ci: bump GoReleaser to v2.16.0 (#10774)
    • docs: fix broken nixpkgs reference link in installation guide (#10776)
    • fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777)
    • fix(spdx): guard against nil root component in SPDX marshaler (#10771)
    • ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)
References

Affected packages

openSUSE:Leap 16.0 / trivy

Package

Name
trivy
Purl
pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.72.0-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "trivy":  "0.72.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21249-1.json"