Aqua Security · Trivy · CVE-2026-56852
**Name of the Vulnerable Software and Affected Versions**
trivy versions prior to 0.72.0-2.1
**Description**
A `norm.Iter` can enter an infinite loop when processing input that contains invalid UTF-8 bytes. UTF-8 is a character encoding capable of encoding all possible Unicode characters.
**Recommendations**
Update to version 0.72.0-2.1.