CVE-2026-33634

HIGH KEV

Trivy ecosystem supply chain briefly compromised

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-33634 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 26, 2026. EIP tracks 3 public exploits from researchers including AshleyT3, fevar54, ugurrates.

AI-analyzed exploit summary This repository provides a technical demonstration of the risks associated with mounting the Docker socket into containers, specifically referencing CVE-2026-33634. It includes a Next.js application and a safer approach to running Trivy scans without exposing the Docker socket.

Description

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.

Exploits (3)

nomisec WRITEUP
by AshleyT3 · poc
https://github.com/AshleyT3/docker-socket-risk-demos

This repository provides a technical demonstration of the risks associated with mounting the Docker socket into containers, specifically referencing CVE-2026-33634. It includes a Next.js application and a safer approach to running Trivy scans without exposing the Docker socket.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Docker socket (docker.sock)
No auth needed
Prerequisites: Access to a Docker environment · Ability to mount volumes in containers
devstral-2 · analyzed Apr 09, 2026 Full analysis →
nomisec SCANNER
by fevar54 · poc
https://github.com/fevar54/CVE-2026-33634-Scanner

This repository contains a Python-based scanner designed to detect indicators of compromise (IOCs) associated with CVE-2026-33634, a supply chain attack. It includes modules for file scanning, network monitoring, and DNS analysis to identify malicious hashes, IPs, domains, and URLs.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Systems affected by TeamPCP supply chain attack
No auth needed
Prerequisites: Python 3.8+ · Scapy (optional for DNS monitoring) · Access to system files and network traffic
devstral-2 · analyzed Apr 09, 2026 Full analysis →
nomisec WRITEUP
by ugurrates · poc
https://github.com/ugurrates/teampcp-supply-chain-attack

This repository provides a detailed technical analysis of CVE-2026-33634, a supply chain attack by TeamPCP affecting multiple CI/CD ecosystems. It includes attack timelines, kill chain breakdowns, compromised artifacts, and detection methods.

Classification
Writeup 100%
Attack Type
Other
Complexity
Complex
Reliability
Reliable
Target: GitHub Actions, Docker Hub, OpenVSX, npm, PyPI
No auth needed
Prerequisites: Compromised credentials or access to CI/CD pipelines
devstral-2 · analyzed Mar 25, 2026 Full analysis →

References (14)

Core 14
Core References
Issue Tracking, Mitigation, Third Party Advisory
https://github.com/BerriAI/litellm/issues/24518#issuecomment-4127436387
X_Refsource_Misc x_refsource_misc
https://github.com/BerriAI/litellm/issues/24518

Scores

CVSS v3 8.8
EPSS 0.2658
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-03-26
VulnCheck KEV 2026-03-23
ENISA EUVD EUVD-2026-14601
CWE
CWE-506
Status published
Products (17)
aquasec/setup-trivy < 0.2.6
aquasec/trivy 0.69.4
aquasec/trivy_action < 0.35.0
aquasecurity/setup-trivy < 0.2.6
aquasecurity/trivy Go
aquasecurity/trivy = 0.6.94
aquasecurity/trivy = 0.69.4
aquasecurity/trivy-action < 0.35.0
aquasecurity/trivy-action <0.35.0
BerriAI/LiteLLM >= 1.82.7, <= 1.82.8
... and 7 more
Published Mar 23, 2026
KEV Added Mar 26, 2026
Tracked Since Mar 24, 2026