
CVE-2026-33481 Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not p… https://www.cve.org/CVERecord?id=CVE-2026-33481
Post summary
The post announces that Syft versions before v1.42.3 are affected by CVE-2026-33481 and that upgrading to v1.42.3 or newer addresses the issue, but it does not provide a PoC, exploit code, or evidence of active misuse.

