Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 421
Alerts This Week
Warning Icon 1 421

openSUSE Trivy Important Security Fix Advisory 2026-0263-1

opensuse
Calendar Grey July 27, 2026
Scroller Opensuse
This important security update for openSUSE addresses multiple vulnerabilities in Trivy to enhance system protection.
openSUSE released a security update for Trivy, addressing six vulnerabilities, with upgrades to dependencies and new features in version 0.72.0, emphasizing improved functionality ...

Description

This update for trivy fixes the following issues:

- Update embedded dependencies:

* update x/net to 0.57.0 (boo#1266495, CVE-2026-39821)

* update x/text to 0.40.0 (boo#1271670, CVE-2026-56852)

* update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151)

- Update trivy to version 0.72.0:

* release: v0.72.0 [main] (#10782)

* test: close plugin manager in tests cleanup (#10904)

* Merge commit from fork

* feat(bottlerocket): add vulnerability matching for Bottlerocket OS

(#10893)

* fix(misconf): support github_repository_vulnerability_alerts resource

(#10680)

* feat(java): detect JAR licenses from packaged LICENSE files (#10856)

* fix(nodejs): parse project dependencies from multi-document

pnpm-lock.yaml (#10861)

* fix(server): propagate package repository class in client/server mode

(#10874)

* chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to

2.3.2 (#10888)

*...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-263=1

Package List

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

trivy-0.72.0-bp157.2.15.1

References

https://www.suse.com/security/cve/CVE-2026-39821.html

https://www.suse.com/security/cve/CVE-2026-46680.html

https://www.suse.com/security/cve/CVE-2026-50151.html

https://www.suse.com/security/cve/CVE-2026-54448.html

https://www.suse.com/security/cve/CVE-2026-55092.html

https://www.suse.com/security/cve/CVE-2026-56852.html

https://bugzilla.suse.com/1266495

https://bugzilla.suse.com/1268356

https://bugzilla.suse.com/1269269

https://bugzilla.suse.com/1269271

https://bugzilla.suse.com/1271658

https://bugzilla.suse.com/1271670

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0263-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.