🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: ha-rule-engine-2
Branch: bugfix/Vulnerabilities-fix1
Build: #118
Date: 2026-02-20 14:46:44

0

Critical

5

High

6

Medium

0

Low

0

Secrets

1

Misconfig

🔴 Vulnerabilities (10)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-58057 io.netty:netty-codec 4.1.124.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style
MEDIUM CVE-2025-67735 io.netty:netty-codec-http 4.1.124.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
HIGH CVE-2025-48988 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat DoS in multipart upload
HIGH CVE-2025-48989 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
HIGH CVE-2025-55752 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possi
MEDIUM CVE-2025-31650 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 9.0.104, 10.1.40, 11.0.6 tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
MEDIUM CVE-2025-49124 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 11.0.8, 10.1.42, 9.0.106 Apache Tomcat installer for Windows has an untrusted search path vulnerability
MEDIUM CVE-2025-49125 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.35 11.0.14, 10.1.49, 9.0.112 tomcat: Client certificate verification bypass due to virtual host mapping
HIGH CVE-2025-41249 org.springframework:spring-core 6.2.10 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)