🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen-llava-inference
Branch: code-refactor-v2
Build: #22
Date: 2026-02-06 10:05:33

0

Critical

8

High

17

Medium

0

Low

0

Secrets

1

Misconfig

🔴 Vulnerabilities (24)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-27516 Jinja2 3.1.5 3.1.6 jinja2: Jinja sandbox breakout through attr filter selecting format method
MEDIUM CVE-2025-68146 filelock 3.17.0 3.20.1 filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbi
MEDIUM CVE-2026-22701 filelock 3.17.0 3.20.3 filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock
HIGH CVE-2025-4565 protobuf 5.29.3 4.25.8, 5.29.5, 6.31.1 python-protobuf: Unbounded recursion in Python Protobuf
HIGH CVE-2026-0994 protobuf 5.29.3 6.33.5, 5.29.6 python: protobuf: Protobuf: Denial of Service due to recursion depth bypass
MEDIUM CVE-2024-47081 requests 2.32.3 2.32.4 requests: Requests vulnerable to .netrc credentials leak via malicious URLs
HIGH CVE-2026-1260 sentencepiece 0.2.0 0.2.1 sentencepiece: Sentencepiece: Invalid memory access leading to potential arbitrary code execution vi
HIGH CVE-2025-47273 setuptools 75.8.2 78.1.1 setuptools: Path Traversal Vulnerability in setuptools PackageIndex
MEDIUM CVE-2025-3730 torch 2.7.1 2.8.0 A vulnerability, which was classified as problematic, was found in PyT ...
MEDIUM CVE-2025-1194 transformers 4.49.0 4.50.0 Transformers Regular Expression Denial of Service (ReDoS) vulnerability
MEDIUM CVE-2025-2099 transformers 4.49.0 4.50.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-3262 transformers 4.49.0 4.51.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-3263 transformers 4.49.0 4.51.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-3264 transformers 4.49.0 4.51.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-3933 transformers 4.49.0 4.52.1 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-5197 transformers 4.49.0 4.53.0 transformers: Transformers ReDoS Vulnerability
MEDIUM CVE-2025-6051 transformers 4.49.0 4.53.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-6638 transformers 4.49.0 4.53.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
MEDIUM CVE-2025-6921 transformers 4.49.0 4.53.0 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
HIGH CVE-2025-66418 urllib3 2.3.0 2.6.0 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
HIGH CVE-2025-66471 urllib3 2.3.0 2.6.0 urllib3: urllib3 Streaming API improperly handles highly compressed data
HIGH CVE-2026-21441 urllib3 2.3.0 2.6.3 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (st
MEDIUM CVE-2025-50181 urllib3 2.3.0 2.5.0 urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
MEDIUM CVE-2025-50182 urllib3 2.3.0 2.5.0 urllib3: urllib3 does not control redirects in browsers and Node.js
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)