🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen-agent-document-service
Branch: eizen-agent-document-service
Build: #143
Date: 2026-02-24 15:43:34

1

Critical

3

High

4

Medium

0

Low

2

Secrets

1

Misconfig

🔴 Vulnerabilities (7)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2023-36464 PyPDF2 3.0.1 No fix pypdf: Possible Infinite Loop when a comment isn't followed by a character
HIGH CVE-2025-69223 aiohttp 3.13.0 3.13.3 aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
MEDIUM CVE-2025-69227 aiohttp 3.13.0 3.13.3 aiohttp: aiohttp: Denial of Service via specially crafted POST request
MEDIUM CVE-2025-69228 aiohttp 3.13.0 3.13.3 aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request
MEDIUM CVE-2025-69229 aiohttp 3.13.0 3.13.3 aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling
CRITICAL CVE-2025-14009 nltk 3.9.2 No fix nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
HIGH CVE-2026-25990 pillow 10.4.0 12.1.1 pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
🔑 Secrets (2)
TypeFileLineMatch
GitHub security-reports/gitleaks-report.json 9 "Match": "**************************************...
GitHub security-reports/gitleaks-report.json 10 "Secret": "*************************************...
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0029 'apt-get' missing '--no-install-recommends' Dockerfile '--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y libgl1 libgl
📄 Raw JSON Report (click to expand)