{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21249-1","published":"2026-07-07T16:21:44Z","modified":"2026-07-09T10:00:11.603771958Z","related":["CVE-2026-54448","CVE-2026-55092"],"upstream":["CVE-2026-54448","CVE-2026-55092"],"summary":"Security update for trivy","details":"This update for trivy fixes the following issues\n\nUpdate to version 0.72.0.\n\n- CVE-2026-54448: tar unpacker reads scanned Helm chart archives (.tgz) with `io.ReadAll(tr)` and defines no size\n  limit, which can lead to a DoS (bsc#1269271).\n- CVE-2026-55092: `org.opencontainers.image.title` annotation from OCI artifact manifest is used as a destination\n  filename without validation and can lead to arbitrary file writes (bsc#1269269).\n\nOther updates and bugfixes:\n\n- Version 0.72.0:\n  * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893)\n  * fix(misconf): support github_repository_vulnerability_alerts resource (#10680)\n  * feat(java): detect JAR licenses from packaged LICENSE files (#10856)\n  * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861)\n  * fix(server): propagate package repository class in client/server mode (#10874)\n  * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888)\n  * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795)\n  * feat(java): detect JAR licenses from the embedded pom.xml (#10851)\n  * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)\n  * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873)\n  * chore(deps): bump alpine to 3.24.1 (#10868)\n  * docs: fix article typo in plugin developer guide (#10860)\n  * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848)\n  * docs: fix typos (#10857)\n  * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843)\n  * feat(secret): support new stateless format for GitHub App installation tokens (#10826)\n  * fix: correct format verbs in diagnostic messages (#10805)\n  * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845)\n  * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830)\n  * docs: fix repository scan heading typo (#10828)\n  * fix: forward ospkg detector options through ospkg.NewScanner (#10811)\n  * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)\n  * fix(vex): load VEX documents from within the repository directory (#10820)\n  * ci!: migrate docker config to dockers_v2 (#10783)\n  * feat(dotnet): detect bundled runtime in self-contained deployments (#10786)\n  * feat(secret): add OpenAI secret detection rules (#10798)\n  * ci: expect GitHub App bot as backport PR author (#10813)\n  * fix: surface the original analysis error instead of context cancellation (#10793)\n  * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803)\n  * chore(deps): bump the common group with 4 updates (#10797)\n  * chore(deps): bump the aws group with 4 updates (#10796)\n  * fix: use random suffix for process temp directory instead of PID (#10431)\n  * docs: update signature verification for deb and rpm packages (#10784)\n  * fix(image): lookup origin layer for custom resources in merged layers (#10788)\n  * ci: bump GoReleaser to v2.16.0 (#10774)\n  * docs: fix broken nixpkgs reference link in installation guide (#10776)\n  * fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777)\n  * fix(spdx): guard against nil root component in SPDX marshaler (#10771)\n  * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)\n","affected":[{"package":{"name":"trivy","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.72.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"trivy":"0.72.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21249-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269269"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55092"}]}