CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-33634: Trivy Supply-Chain Compromise

August 12, 2026

CVE-2026-33634 is a critical vulnerability in the Trivy scanner ecosystem, exploited in a supply-chain attack that also affected LiteLLM. Added to CISA's Known Exploited Vulnerabilities catalog on March 26, 2026, it involves malicious commits to trivy-action and setup-trivy tags, as well as a malicious Trivy 0.69.4 release. The advisory lists BerriAI LiteLLM 1.82.7 through 1.82.8 as affected.