{"id":"CGA-8ww4-6485-2mx8","modified":"2026-07-17T18:47:11.407405501Z","published":"2026-06-17T12:21:27Z","upstream":["CVE-2026-33634","GHSA-69fq-xp46-6x23","GO-2026-4919"],"references":[{"type":"ARTICLE","url":"https://docs.litellm.ai/blog/security-update-march-2026"},{"type":"ARTICLE","url":"https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack"},{"type":"REPORT","url":"https://github.com/BerriAI/litellm/issues/24518"},{"type":"ADVISORY","url":"https://github.com/BerriAI/litellm/issues/24518#issuecomment-4127436387"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33634.json"},{"type":"WEB","url":"https://github.com/aquasecurity/trivy/discussions/10425"},{"type":"ADVISORY","url":"https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23"},{"type":"ADVISORY","url":"https://github.com/pypa/advisory-database/tree/main/vulns/litellm/PYSEC-2026-2.yaml"},{"type":"ADVISORY","url":"https://github.com/team-telnyx/telnyx-python/security/advisories/GHSA-955r-262c-33jc"},{"type":"WEB","url":"https://inspector.pypi.io/project/litellm/1.82.7/packages/79/5f/b6998d42c6ccd32d36e12661f2734602e72a576d52a51f4245aef0b20b4d/litellm-1.82.7-py3-none-any.whl/litellm/proxy/proxy_server.py#line.130"},{"type":"WEB","url":"https://inspector.pypi.io/project/litellm/1.82.8/packages/f6/2c/731b614e6cee0bca1e010a36fd381fba69ee836fe3cb6753ba23ef2b9601/litellm-1.82.8.tar.gz/litellm-1.82.8/litellm_init.pth#line.1"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33634"},{"type":"EVIDENCE","url":"https://rosesecurity.dev/2026/03/20/typosquatting-trivy.html"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33634"},{"type":"ADVISORY","url":"https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/"},{"type":"ARTICLE","url":"https://www.wiz.io/blog/teampcp-attack-kics-github-action"}],"affected":[{"package":{"name":"trivy-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/trivy-fips?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2026-06-17T12:45:34Z","architecture":"x86_64","component_name":"github.com/aquasecurity/trivy","component_version":"v0.70.0+dirty","component_type":"go-module","component_location":"/usr/bin/trivy","component_purl":"pkg:golang/github.com/aquasecurity/trivy@v0.70.0%2Bdirty","latest_event_status":"false_positive_determination"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-8ww4-6485-2mx8.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}