🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: ha-process-engine2
Branch: feature/dev-1
Build: #121
Date: 2026-02-20 15:42:02

0

Critical

7

High

10

Medium

0

Low

5

Secrets

1

Misconfig

🔴 Vulnerabilities (16)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-11226 ch.qos.logback:logback-core 1.5.18 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core
MEDIUM CVE-2025-58057 io.netty:netty-codec 4.1.119.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style
MEDIUM CVE-2025-67735 io.netty:netty-codec-http 4.1.119.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
HIGH CVE-2025-55163 io.netty:netty-codec-http2 4.1.119.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
MEDIUM CVE-2025-22227 io.projectreactor.netty:reactor-netty-http 1.1.29 1.3.0-M5, 1.2.8 io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
HIGH CVE-2025-48988 org.apache.tomcat.embed:tomcat-embed-core 10.1.40 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat DoS in multipart upload
HIGH CVE-2025-48989 org.apache.tomcat.embed:tomcat-embed-core 10.1.40 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
HIGH CVE-2025-55752 org.apache.tomcat.embed:tomcat-embed-core 10.1.40 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possi
MEDIUM CVE-2025-49124 org.apache.tomcat.embed:tomcat-embed-core 10.1.40 11.0.8, 10.1.42, 9.0.106 Apache Tomcat installer for Windows has an untrusted search path vulnerability
MEDIUM CVE-2025-49125 org.apache.tomcat.embed:tomcat-embed-core 10.1.40 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.40 11.0.14, 10.1.49, 9.0.112 tomcat: Client certificate verification bypass due to virtual host mapping
HIGH CVE-2024-10039 org.keycloak:keycloak-core 25.0.6 26.0.6 keycloak-core: mTLS passthrough
HIGH CVE-2025-41249 org.springframework:spring-core 6.1.19 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
MEDIUM CVE-2025-41234 org.springframework:spring-web 6.1.19 6.2.8, 6.1.21 springframework: Reflected download attack in Spring Framework with non-ASCII headers
MEDIUM CVE-2025-41242 org.springframework:spring-webmvc 6.1.19 6.2.10 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerability
MEDIUM CVE-2025-41254 org.springframework:spring-websocket 6.1.19 6.2.12 org.springframework/spring-core: Spring Framework STOMP CSRF Vulnerability
🔑 Secrets (5)
TypeFileLineMatch
AWS .env 16 # S3_ACCESS_ID=********************...
AWS security-reports/gitleaks-report.json 93 "Match": "********************",...
AWS security-reports/gitleaks-report.json 94 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 198 "Match": "********************",...
AWS security-reports/gitleaks-report.json 199 "Secret": "********************",...
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)