Dear Steve,
This might be a new horror^H^H^H^H^H^H^H security bedtime history for SN listeners, affecting everyone (European Commission and Eclipse Foundation projects, amongst many others): https://github.com/aquasecurity/trivy/discussions/10425
Conclusion: https://github.com/aquasecurity/trivy/discussions/10462
Security advisory: https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23
CVE: CVE-2026-33634 https://nvd.nist.gov/vuln/detail/CVE-2026-33634 [CVSS-B 9.4 CRITICAL]
More references:
This might be a new horror^H^H^H^H^H^H^H security bedtime history for SN listeners, affecting everyone (European Commission and Eclipse Foundation projects, amongst many others): https://github.com/aquasecurity/trivy/discussions/10425
Conclusion: https://github.com/aquasecurity/trivy/discussions/10462
Security advisory: https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23
CVE: CVE-2026-33634 https://nvd.nist.gov/vuln/detail/CVE-2026-33634 [CVSS-B 9.4 CRITICAL]
More references:
- https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
- https://www.infoq.com/news/2026/04/trivy-supply-chain-attack/
- https://www.docker.com/blog/trivy-supply-chain-compromise-what-docker-hub-users-should-know/
- https://www.infoq.com/news/2026/04/trivy-supply-chain-attack/
- https://thenextweb.com/news/european-commission-breach-trivy-supply-chain
- https://www.securityweek.com/europe...a-breach-linked-to-trivy-supply-chain-attack/
- https://www.eclipse.org/lists/eclipse.org-committers/msg01561.html
- https://mikael.barbero.tech/blog/post/2026-03-24-stop-trusting-mutable-references/
- https://securityboulevard.com/2026/...omise-what-happened-and-playbooks-to-respond/
- https://snyk.io/articles/trivy-github-actions-supply-chain-compromise/
- https://alluresecurity.com/blog/trivy-supply-chain-attack-infrastructure-trust/
- CVE references more sources
Last edited:

