Skip to content

Conversation

@success-ng
Copy link
Member

… reporting

@github-actions
Copy link

github-actions bot commented Oct 27, 2025

🔒 Trivy Security Scan Results

Scan Summary:

  • 🎯 Severity Filter: CRITICAL, HIGH
  • 📦 Total Vulnerabilities: 6
  • ⚠️ Critical: 1
  • 🔶 High: 5
  • 📅 Scan Time: 16:50:37 27/10/2025

📋 Vulnerability Details

Severity CVE/ID Package Current Fixed Description
🟠 HIGH CVE-2024-6221 Flask-Cors 4.0.0 4.0.2 A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Ac ...
🔴 CRITICAL CVE-2024-36039 PyMySQL 1.1.0 1.1.1 python-pymysql: SQL injection if used with untrusted JSON input
🟠 HIGH CVE-2024-34069 Werkzeug 2.2.3 3.0.3 python-werkzeug: user may execute code on a developer's machine
🟠 HIGH CVE-2024-1135 gunicorn 21.0.1 22.0.0 python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-E
🟠 HIGH CVE-2024-6827 gunicorn 21.0.1 22.0.0 gunicorn: HTTP Request Smuggling in benoitc/gunicorn
🟠 HIGH CVE-2023-52323 pycryptodome 3.12.0 3.19.1 pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycry

🔧 Recommendations

  1. Review all CRITICAL vulnerabilities immediately
  2. Update affected packages to fixed versions
  3. Check for available patches or workarounds

🤖 Automated by Trivy Scanner | Run #18836731731 | View Workflow

@success-ng success-ng closed this Oct 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants