🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen-mlflow-service
Branch: ldev
Build: #14
Date: 2026-05-05 13:20:45

0

Critical

1

High

2

Medium

0

Low

0

Secrets

1

Misconfig

🔴 Vulnerabilities (2)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2026-39892 cryptography 46.0.6 46.0.7 cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API
MEDIUM CVE-2026-33865 mlflow 3.11.0 3.11.1 MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLm
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)