🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: ha-rule-engine-2
Branch: bugfix/Vulnerabilities-fix1
Build: #117
Date: 2026-02-20 14:34:57

1

Critical

7

High

10

Medium

0

Low

0

Secrets

1

Misconfig

🔴 Vulnerabilities (17)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-11226 ch.qos.logback:logback-core 1.5.16 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core
MEDIUM CVE-2025-58057 io.netty:netty-codec 4.1.118.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style
MEDIUM CVE-2025-67735 io.netty:netty-codec-http 4.1.118.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
HIGH CVE-2025-55163 io.netty:netty-codec-http2 4.1.118.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
MEDIUM CVE-2025-22227 io.projectreactor.netty:reactor-netty-http 1.2.2 1.3.0-M5, 1.2.8 io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
CRITICAL CVE-2025-24813 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.3, 10.1.35, 9.0.99 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
HIGH CVE-2025-48988 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat DoS in multipart upload
HIGH CVE-2025-48989 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
HIGH CVE-2025-55752 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possi
MEDIUM CVE-2025-31650 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 9.0.104, 10.1.40, 11.0.6 tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
MEDIUM CVE-2025-49124 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.8, 10.1.42, 9.0.106 Apache Tomcat installer for Windows has an untrusted search path vulnerability
MEDIUM CVE-2025-49125 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.34 11.0.14, 10.1.49, 9.0.112 tomcat: Client certificate verification bypass due to virtual host mapping
HIGH CVE-2025-22235 org.springframework.boot:spring-boot 3.4.2 3.3.11, 3.4.5 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actu
HIGH CVE-2025-41249 org.springframework:spring-core 6.2.2 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
MEDIUM CVE-2025-41234 org.springframework:spring-web 6.2.2 6.2.8, 6.1.21 springframework: Reflected download attack in Spring Framework with non-ASCII headers
MEDIUM CVE-2025-41242 org.springframework:spring-webmvc 6.2.2 6.2.10 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerability
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)