VDB
KO

GO-2026-6294

Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy

Quick fix

GO-2026-6294 — github.com/aquasecurity/trivy: upgrade to the fixed version with the command below.

go get github.com/aquasecurity/trivy@v0.71.1

Details

Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/aquasecurity/trivy
Introduced in: 0 Fixed in: 0.71.1
Fix go get github.com/aquasecurity/trivy@v0.71.1

References