CVE-2024-35192
Trivy vulnerability analysis and mitigation

Overview

Trivy, a security scanner, was found to contain a vulnerability (CVE-2024-35192) prior to version 0.51.2. The vulnerability could allow a malicious actor to trigger Trivy to scan container images from a crafted malicious registry, potentially leading to the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR). The vulnerability was discovered and disclosed on May 20, 2024 (GitHub Advisory).

Technical details

The vulnerability is rated as Moderate with a CVSS v3.1 base score of 5.5 (MEDIUM). The CVSS vector string is CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N, indicating Local attack vector, High attack complexity, No privileges required, Required user interaction, Changed scope, and High confidentiality impact with No impact on integrity and availability (GitHub Advisory).

Impact

If exploited, the vulnerability allows attackers to obtain tokens that can be used to push/pull images from registries to which the identity/user running Trivy has access. The impact is particularly significant when Trivy is executed with environment variables containing static AWS credentials, within a Pod running on an EKS cluster with IRSA annotations, or similar configurations for GCP and Azure (GitHub Advisory).

Exploitability

The vulnerability only applies when scanning container images directly from a registry. Systems are not affected if the default credential provider chain is unable to obtain valid credentials, or if using Docker, containerd, or other runtime to pull images locally for scanning (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Trivy version 0.51.2. For users of earlier versions, it is recommended to only scan images from trusted registries. Users can enforce this behavior by using the --image-src flag to select trusted sources. Additionally, using Docker, containerd, or other runtime to pull images locally before scanning with Trivy provides protection against this vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Trivy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-securityhub
NoYesJul 21, 2026
CVE-2026-71556HIGH7.1
  • Packer logoPacker
  • kubescape
NoYesAug 07, 2026
CVE-2026-71557MEDIUM6.3
  • Packer logoPacker
  • cloudbeat-fips-9.3
NoYesAug 07, 2026
CVE-2026-54787LOW3.1
  • Docker Compose logoDocker Compose
  • cloudbeat-fips-9.4
NoYesJul 31, 2026
CVE-2026-48702NONEN/A
  • Datadog Agent logoDatadog Agent
  • hauler
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management