Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| aquasecurity/setup-trivy | affected | < 0.2.6 | vendor fix → 0.2.6 | osv GHSA-69fq-xp46-6x23 | |
| aquasecurity/trivy-action | affected | < 0.35.0 | vendor fix → 0.35.0 | osv GHSA-69fq-xp46-6x23 | |
| github.com/aquasecurity/trivy | affected | 0.69.4 | none available | osv GHSA-69fq-xp46-6x23 | |
| github.com/aquasecurity/trivy | affected | >= 0.69.4 | none available | osv GO-2026-4919 | |
| https://github.com/aquasecurity/setup-trivy | affected | < 3fb12ec12f41e471780db15c232d5dd185dcb514 | vendor fix → 3fb12ec12f41e471780db15c232d5dd185dcb514 | osv | |
| https://github.com/aquasecurity/setup-trivy | affected | < bd30e983e3b9444dd750478b6976ed79fbf7d4e5 | vendor fix → bd30e983e3b9444dd750478b6976ed79fbf7d4e5 | osv | |
| https://github.com/aquasecurity/setup-trivy | affected | < 57a97c7e7821a5776cebc9bb87c984fa69cba8f1 | vendor fix → 57a97c7e7821a5776cebc9bb87c984fa69cba8f1 | osv | |
| https://github.com/aquasecurity/setup-trivy | affected | >= 8bbd1654fa6392a210a277b13a1d35dd19c70243, <= 8bbd1654fa6392a210a277b13a1d35dd19c70243 | none available | osv | |
| aquasecurity/setup-trivy | fixed | 0.2.6 | vendor fix → 0.2.6 | osv GHSA-69fq-xp46-6x23 | |
| aquasecurity/trivy-action | fixed | 0.35.0 | vendor fix → 0.35.0 | osv GHSA-69fq-xp46-6x23 | |
| https://github.com/aquasecurity/setup-trivy | fixed | 3fb12ec12f41e471780db15c232d5dd185dcb514 | vendor fix → 3fb12ec12f41e471780db15c232d5dd185dcb514 | osv | |
| https://github.com/aquasecurity/setup-trivy | fixed | bd30e983e3b9444dd750478b6976ed79fbf7d4e5 | vendor fix → bd30e983e3b9444dd750478b6976ed79fbf7d4e5 | osv | |
| https://github.com/aquasecurity/setup-trivy | fixed | 57a97c7e7821a5776cebc9bb87c984fa69cba8f1 | vendor fix → 57a97c7e7821a5776cebc9bb87c984fa69cba8f1 | osv | |
| BerriAI/LiteLLM BerriAI · LiteLLM | affected | >= 1.82.7, <= 1.82.8 | none available | cve_cna | |
| aquasecurity/setup-trivy aquasecurity · setup-trivy | affected | < 0.2.6 | none available | cve_cna | |
| team-telnyx/telnyx team-telnyx · telnyx | affected | >= 4.87.1, <= 4.87.2 | none available | cve_cna | |
| aquasecurity/trivy aquasecurity · trivy | affected | = 0.69.4 | none available | cve_cna | |
| aquasecurity/trivy-action aquasecurity · trivy-action | affected | < 0.35.0 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.