🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen-vip-face-authentication-api
Branch: features/vulnerabilities_fixes
Build: #42
Date: 2026-02-11 11:38:59

0

Critical

6

High

5

Medium

0

Low

0

Secrets

2

Misconfig

🔴 Vulnerabilities (9)
SeverityCVE IDPackageInstalledFixed InDescription
HIGH CVE-2025-69223 aiohttp 3.13.2 3.13.3 aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
MEDIUM CVE-2025-69227 aiohttp 3.13.2 3.13.3 aiohttp: aiohttp: Denial of Service via specially crafted POST request
MEDIUM CVE-2025-69228 aiohttp 3.13.2 3.13.3 aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request
MEDIUM CVE-2025-69229 aiohttp 3.13.2 3.13.3 aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling
MEDIUM CVE-2025-68146 filelock 3.19.1 3.20.1 filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbi
MEDIUM CVE-2026-22701 filelock 3.19.1 3.20.3 filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock
HIGH CVE-2026-0994 protobuf 6.33.2 6.33.5, 5.29.6 python: protobuf: Protobuf: Denial of Service due to recursion depth bypass
HIGH CVE-2026-24486 python-multipart 0.0.20 0.0.22 python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability
HIGH CVE-2026-21441 urllib3 2.6.2 2.6.3 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (st
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (2)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
HIGH DS-0029 'apt-get' missing '--no-install-recommends' Dockerfile '--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y python3
📄 Raw JSON Report (click to expand)