CVE-2026-33481Disclosure(anchore / syft)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch anchore syft systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly cleanup temporary storage if the temporary storage was exhausted during a scan. When scanning archives Syft will unpack those archives into temporary storage then inspect the unpacked contents. Under normal operation Syft will remove the temporary data it writes after completing a scan. This vulnerability would affect users of Syft that were scanning content that could cause Syft to fill the temporary storage that would then cause Syft to raise an error and exit. When the error is triggered Syft would exit without properly removing the temporary files in use. In our testing this was most easily reproduced by scanning very large artifacts or highly compressed artifacts such as a zipbomb. Because Syft would not clean up its temporary files, the result would be filling temporary file storage preventing future runs of Syft or other system utilities that rely on temporary storage being available. The patch has been released in v1.42.3. Syft now cleans up temporary files when an error condition is encountered. There are no workarounds for this vulnerability in Syft. Users that find their temporary storage depleted can manually remove the temporary files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-460

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • syft

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
syft

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-26: 103-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33481 Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not p… https://www.cve.org/CVERecord?id=CVE-2026-33481

    Post summary

    The post announces that Syft versions before v1.42.3 are affected by CVE-2026-33481 and that upgrading to v1.42.3 or newer addresses the issue, but it does not provide a PoC, exploit code, or evidence of active misuse.

    00010293
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-33481 Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not p… https://www.cve.org/CVERecord?id=CVE-2026-33481 ----- Traducción: CVE-2026-33481 Syf… http://infoflow.cloud`

    Post summary

    The message references CVE-2026-33481 associated with Syft (versions before v1.42.3) but offers no concrete PoC, exploit details, patch, or in‑the‑wild activity, making it a general mention.

    0000029
    65 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanchoresyft---

Explore more