CVE-2026-33481
Last modified
CVE-2026-33481 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly cleanup temporary storage if the temporary storage was exhausted during a scan. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly cleanup temporary storage if the temporary storage was exhausted during a scan. When scanning archives Syft will unpack those archives into temporary storage then inspect the unpacked contents. Under normal operation Syft will remove the temporary data it writes after completing a scan. This vulnerability would affect users of Syft that were scanning content that could cause Syft to fill the temporary storage that would then cause Syft to raise an error and exit. When the error is triggered Syft would exit without properly removing the temporary files in use. In our testing this was most easily reproduced by scanning very large artifacts or highly compressed artifacts such as a zipbomb. Because Syft would not clean up its temporary files, the result would be filling temporary file storage preventing future runs of Syft or other system utilities that rely on temporary storage being available. The patch has been released in v1.42.3. Syft now cleans up temporary files when an error condition is encountered. There are no workarounds for this vulnerability in Syft. Users that find their temporary storage depleted can manually remove the temporary files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anchore | Syft | < 1.42.3 |
References
- https://github.com/anchore/stereoscope/pull/537Issue Tracking, Patch
- https://github.com/anchore/syft/pull/4629Issue Tracking, Patch
- https://github.com/anchore/syft/pull/4668Issue Tracking, Patch
- https://github.com/anchore/syft/security/advisories/GHSA-rjcw-vg7j-m9rcPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33481?
How severe is CVE-2026-33481?
How do I fix CVE-2026-33481?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33476SiYuan is a personal knowledge management system. Prior to v…7.5
- CVE-2026-33477FileRise is a self-hosted web-based file manager with multi-…4.3
- CVE-2026-33478WWBN AVideo is an open source video platform. In versions up…10
- CVE-2026-33479WWBN AVideo is an open source video platform. In versions up…8.8
- CVE-2026-3348The MinhNhut Link Gateway plugin for WordPress is vulnerable…4.4
- CVE-2026-33480WWBN AVideo is an open source video platform. In versions up…8.6
- CVE-2026-33482WWBN AVideo is an open source video platform. In versions up…8.1
- CVE-2026-33483WWBN AVideo is an open source video platform. In versions up…7.5
- CVE-2026-33484Langflow is a tool for building and deploying AI-powered age…7.5
- CVE-2026-33485WWBN AVideo is an open source video platform. In versions up…7.5
- CVE-2026-33486Roadiz is a polymorphic content management system based on a…6.5
- CVE-2026-33487goxmlsig provides XML Digital Signatures implemented in Go. …7.5
Are you affected by CVE-2026-33481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
