๐Ÿ›ก๏ธ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen-vip-gateway-api
Branch: ldev
Build: #225
Date: 2026-04-13 12:03:29

0

Critical

2

High

1

Medium

0

Low

0

Secrets

1

Misconfig

๐Ÿ”ด Vulnerabilities (2)
SeverityCVE IDPackageInstalledFixed InDescription
HIGH CVE-2026-32597 PyJWT 2.11.0 2.12.0 pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ยง4.1.11 MUST violation)
MEDIUM CVE-2026-25645 requests 2.32.5 2.33.0 requests: Requests: Security bypass due to predictable temporary file creation
๐Ÿ”‘ Secrets (0)
TypeFileLineMatch
โœ… No secrets found
โš™๏ธ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
๐Ÿ“„ Raw JSON Report (click to expand)