ok grype-db: 0 days old (built 2026-09-11T06:29:40Z) ok trivy-db: 0 days old (built 2026-09-11T07:00:51.617232631Z) ok trivy-java-db: 0 days old (built 2026-09-11T01:12:33.350401225Z) ==== syft dir:/tmp/tmp.1BLdqIRLwi/vulnerable ==== packages catalogued: 3 python: 3 ==== grype sbom:/tmp/tmp.1BLdqIRLwi/r-vuln/sbom.syft.json ==== NAME INSTALLED FIXED IN TYPE VULNERABILITY SEVERITY EPSS RISK django 3.2.0 3.2.14 python GHSA-p64x-8rxx-wf6q Critical 73.3% (99th) 68.0 django 3.2.0 3.2.18 python GHSA-2hrw-hx67-34x6 High 62.6% (99th) 48.8 django 3.2.0 3.2.5 python GHSA-xpfp-f569-q3p2 Critical 44.4% (98th) 41.2 django 3.2.0 3.2.23 python GHSA-qmf9-6jqf-j8fq High 49.8% (98th) 38.8 django 3.2.0 3.2.12 python GHSA-6cw3-g6wv-c2xv High 49.5% (98th) 38.6 django 3.2.0 3.2.17 python GHSA-q2jf-h9jm-m7p4 High 47.4% (98th) 37.0 django 3.2.0 4.2.26 python GHSA-frmv-pr5f-9mcr Critical 19.4% (97th) 17.6 django 3.2.0 3.2.13 python GHSA-2gwj-7jmv-h26r Critical 18.7% (97th) 17.3 django 3.2.0 4.2.24 python GHSA-6w2r-r2m5-xq5w High 15.7% (96th) 11.4 requests 2.19.1 2.20.0 python GHSA-x84v-xcm2-53pg High 7.4% (94th) 5.6 pyyaml 5.3 5.4 python GHSA-8q59-q68h-6hv4 Critical 6.0% (92nd) 5.6 pyyaml 5.3 5.3.1 python GHSA-6757-jp84-gxfx Critical 5.4% (92nd) 5.0 django 3.2.0 3.2.1 python GHSA-rxjp-mfm9-w4wr High 5.3% (92nd) 4.2 django 3.2.0 3.2.4 python GHSA-p99v-5w3c-jqq9 High 5.3% (92nd) 4.1 django 3.2.0 3.2.13 python GHSA-w24h-v9qh-8gxj Critical 2.9% (86th) 2.7 django 3.2.0 3.2.16 python GHSA-qrw5-5h28-6cmg High 3.0% (86th) 2.3 django 3.2.0 3.2.20 python GHSA-jh3w-4vvf-mjgr High 3.0% (86th) 2.3 django 3.2.0 3.2.11 python GHSA-53qw-q765-4fww High 2.4% (83rd) 1.9 django 3.2.0 3.2.12 python GHSA-95rw-fx8r-36v6 Medium 3.4% (87th) 1.8 django 3.2.0 3.2.2 python GHSA-qm57-vhq3-3fwf Medium 3.2% (87th) 1.7 requests 2.19.1 2.31.0 python GHSA-j8r2-6x86-q33q Medium 3.0% (86th) 1.7 django 3.2.0 3.2.4 python GHSA-68w8-qjq3-2gfm Medium 2.7% (85th) 1.5 django 3.2.0 3.2.11 python GHSA-8c5j-9r9f-c6w8 High 1.9% (77th) 1.4 django 3.2.0 4.2.26 python GHSA-qw25-v68c-qjf3 High 1.9% (78th) 1.4 django 3.2.0 3.2.10 python GHSA-v6rh-hp5x-86rv Medium 2.3% (82nd) 1.4 django 3.2.0 3.2.11 python GHSA-jrh2-hc4r-7jwx Medium 2.4% (83rd) 1.3 django 3.2.0 3.2.19 python GHSA-r3xc-prgr-mg9p Critical 1.4% (70th) 1.3 django 3.2.0 3.2.24 python GHSA-xxj9-f6rv-m3x4 High 1.6% (74th) 1.2 django 3.2.0 3.2.25 python GHSA-vm8q-m57g-pff3 Medium 1.9% (77th) 1.0 django 3.2.0 3.2.22 python GHSA-h8gc-pgj2-vjm3 High 1.2% (67th) 0.9 django 3.2.0 3.2.21 python GHSA-7h4p-27mh-hmrw Medium 1.5% (73rd) 0.8 django 3.2.0 3.2.15 python GHSA-8x94-hmjh-97hq High 0.8% (55th) 0.7 requests 2.19.1 2.32.4 python GHSA-9hjg-9r4m-mvj7 Medium 1.0% (60th) 0.5 django 3.2.0 4.2.16 python GHSA-rrqc-c2jx-6jgv Medium 0.8% (54th) 0.4 django 3.2.0 4.2.22 python GHSA-7xr5-9hcq-chf9 Medium 0.8% (52nd) 0.3 django 3.2.0 5.2.16 python GHSA-crhf-3pfg-w68w Medium 0.4% (36th) 0.2 requests 2.19.1 2.32.0 python GHSA-9wx4-h78v-vm56 Medium 0.3% (27th) 0.2 django 3.2.0 5.2.16 python GHSA-8qcx-xf44-272x Medium 0.3% (25th) 0.2 django 3.2.0 5.2.16 python GHSA-3h9f-r86x-qvjx Low 0.4% (36th) 0.1 django 3.2.0 5.2.15 python GHSA-923m-gv2p-w5qp Low 0.4% (29th) 0.1 requests 2.19.1 2.33.0 python GHSA-gc5v-m9x4-r6x2 Medium 0.2% (7th) < 0.1 django 3.2.0 5.2.15 python GHSA-8cjm-8mp7-r2xf Low 0.3% (20th) < 0.1 django 3.2.0 5.2.15 python GHSA-h7pc-vwp9-298g Low 0.2% (15th) < 0.1 ==== trivy fs /tmp/tmp.1BLdqIRLwi/vulnerable ==== 2026-09-11T14:13:02Z INFO Loaded file_path="/etc/devsecops/trivy.yaml" 2026-09-11T14:13:02Z INFO [vuln] Vulnerability scanning is enabled 2026-09-11T14:13:02Z INFO [misconfig] Misconfiguration scanning is enabled 2026-09-11T14:13:02Z INFO [checks-client] No downloadable checks were loaded as --skip-check-update is enabled, loading from existing cache... 2026-09-11T14:13:02Z INFO [secret] Secret scanning is enabled 2026-09-11T14:13:02Z INFO [secret] If your scanning is slow, please try '--scanners vuln,misconfig' to disable secret scanning 2026-09-11T14:13:02Z INFO [secret] Please see https://trivy.dev/docs/v0.74/guide/scanner/secret#recommendation for faster secret detection 2026-09-11T14:13:02Z WARN [pip] Unable to find python `site-packages` directory. License detection is skipped. err="unable to find path to Python executable" 2026-09-11T14:13:02Z INFO Number of language-specific files num=1 2026-09-11T14:13:02Z INFO [pip] Detecting vulnerabilities... 2026-09-11T14:13:02Z INFO Detected config files num=1 requirements.txt (pip) ====================== Total: 43 (UNKNOWN: 0, LOW: 4, MEDIUM: 15, HIGH: 16, CRITICAL: 8) ┌──────────┬────────────────┬──────────┬────────┬───────────────────┬────────────────────────┬──────────────────────────────────────────────────────────────┐ │ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │ ├──────────┼────────────────┼──────────┼────────┼───────────────────┼────────────────────────┼──────────────────────────────────────────────────────────────┤ │ Django │ CVE-2021-35042 │ CRITICAL │ fixed │ 3.2.0 │ 3.2.5, 3.1.13 │ django: potential SQL injection via unsanitized │ │ │ │ │ │ │ │ QuerySet.order_by() input │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-35042 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-28346 │ │ │ │ 2.2.28, 3.2.13, 4.0.4 │ Django: SQL injection in QuerySet.annotate(),aggregate() and │ │ │ │ │ │ │ │ extra() │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-28346 │ │ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-28347 │ │ │ │ │ Django: SQL injection via QuerySet.explain(options) on │ │ │ │ │ │ │ │ PostgreSQL │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-28347 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-34265 │ │ │ │ 3.2.14, 4.0.6 │ python-django: Potential SQL injection via Trunc(kind) and │ │ │ │ │ │ │ │ Extract(lookup_name) arguments │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-34265 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-31047 │ │ │ │ 3.2.19, 4.1.9, 4.2.1 │ python-django: Potential bypass of validation when uploading │ │ │ │ │ │ │ │ multiple files using one form... │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-31047 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2025-64459 │ │ │ │ 5.2.8, 5.1.14, 4.2.26 │ django: Django SQL injection │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-64459 │ │ ├────────────────┼──────────┤ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-31542 │ HIGH │ │ │ 2.2.21, 3.1.9, 3.2.1 │ django: Potential directory-traversal via uploaded files │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-31542 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-33571 │ │ │ │ 2.2.24, 3.1.12, 3.2.4 │ django: Possible indeterminate SSRF, RFI, and LFI attacks │ │ │ │ │ │ │ │ since validators accepted leading... │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-33571 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-45115 │ │ │ │ 2.2.26, 3.2.11, 4.0.1 │ django: Denial-of-service possibility in │ │ │ │ │ │ │ │ UserAttributeSimilarityValidator │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-45115 │ │ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-45116 │ │ │ │ │ django: Potential information disclosure in dictsort │ │ │ │ │ │ │ │ template filter │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-45116 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-23833 │ │ │ │ 2.2.27, 3.2.12, 4.0.2 │ django: Denial-of-service possibility in file uploads │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23833 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-36359 │ │ │ │ 3.2.15, 4.0.7 │ An issue was discovered in the HTTP FileResponse class in │ │ │ │ │ │ │ │ Django 3.2... │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-36359 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-41323 │ │ │ │ 3.2.16, 4.0.8, 4.1.2 │ python-django: Potential denial-of-service vulnerability in │ │ │ │ │ │ │ │ internationalized URLs │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-41323 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-23969 │ │ │ │ 3.2.17, 4.0.9, 4.1.6 │ python-django: Potential denial-of-service via │ │ │ │ │ │ │ │ Accept-Language headers │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-23969 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-24580 │ │ │ │ 3.2.18, 4.1.7, 4.0.10 │ python-django: Potential denial-of-service vulnerability in │ │ │ │ │ │ │ │ file uploads │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-24580 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-36053 │ │ │ │ 3.2.20, 4.1.10, 4.2.3 │ python-django: Potential regular expression denial of │ │ │ │ │ │ │ │ service vulnerability in EmailValidator/URLValidator │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-36053 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-43665 │ │ │ │ 3.2.22, 4.1.12, 4.2.6 │ python-django: Denial-of-service possibility in │ │ │ │ │ │ │ │ django.utils.text.Truncator │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-43665 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-46695 │ │ │ │ 3.2.23, 4.1.13, 4.2.7 │ python-django: Potential denial of service vulnerability in │ │ │ │ │ │ │ │ UsernameField on Windows │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-46695 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2024-24680 │ │ │ │ 3.2.24, 4.2.10, 5.0.2 │ Django: denial-of-service in ``intcomma`` template filter │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-24680 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2025-57833 │ │ │ │ 4.2.24, 5.1.12, 5.2.6 │ django: Django SQL injection in FilteredRelation column │ │ │ │ │ │ │ │ aliases │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-57833 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2025-64458 │ │ │ │ 5.2.8, 5.1.14, 4.2.26 │ Django: Denial-of-service vulnerability in Django on Windows │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-64458 │ │ ├────────────────┼──────────┤ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-32052 │ MEDIUM │ │ │ 2.2.22, 3.1.10, 3.2.2 │ django: header injection possibility since URLValidator │ │ │ │ │ │ │ │ accepted newlines in input on Python... │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-32052 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-33203 │ │ │ │ 2.2.24, 3.1.12, 3.2.4 │ django: Potential directory traversal via ``admindocs`` │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-33203 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-44420 │ │ │ │ 2.2.25, 3.1.14, 3.2.10 │ django: potential bypass of an upstream access control based │ │ │ │ │ │ │ │ on URL paths... │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-44420 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2021-45452 │ │ │ │ 2.2.26, 3.2.11, 4.0.1 │ django: Potential directory-traversal via Storage.save() │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-45452 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2022-22818 │ │ │ │ 2.2.27, 3.2.12, 4.0.2 │ django: Possible XSS via '{% debug %}' template tag │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-22818 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-41164 │ │ │ │ 3.2.21, 4.1.11, 4.2.5 │ python-django: Potential denial of service vulnerability in │ │ │ │ │ │ │ │ ``django.utils.encoding.uri_to_iri()`` │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-41164 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2024-27351 │ │ │ │ 3.2.25, 4.2.11, 5.0.3 │ python-django: Potential regular expression │ │ │ │ │ │ │ │ denial-of-service in django.utils.text.Truncator.words() │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-27351 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2024-45231 │ │ │ │ 5.1.1, 5.0.9, 4.2.16 │ python-django: Potential user email enumeration via response │ │ │ │ │ │ │ │ status on password reset │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-45231 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2025-48432 │ │ │ │ 5.2.2, 5.1.10, 4.2.22 │ django: Django Path Injection Vulnerability │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-48432 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-53877 │ │ │ │ 5.2.16, 6.0.7 │ django: Django: Information disclosure via heap buffer │ │ │ │ │ │ │ │ over-read in GDALRaster │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-53877 │ │ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-53878 │ │ │ │ │ django: Django: HTTP header injection via │ │ │ │ │ │ │ │ DomainNameValidator accepting newlines │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-53878 │ │ ├────────────────┼──────────┤ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-48587 │ LOW │ │ │ 5.2.15, 6.0.6 │ django: Django: Information disclosure via improper handling │ │ │ │ │ │ │ │ of Vary header whitespace │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-48587 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-48588 │ │ │ │ 5.2.16, 6.0.7 │ django: Django: Information disclosure due to improper │ │ │ │ │ │ │ │ caching of Set-Cookie responses │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-48588 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-6873 │ │ │ │ 5.2.15, 6.0.6 │ python-django: Django: Information disclosure via │ │ │ │ │ │ │ │ non-injective cookie salt derivation │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-6873 │ │ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-8404 │ │ │ │ │ Django: Django: Information disclosure due to improper │ │ │ │ │ │ │ │ handling of Cache-Control directives │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-8404 │ ├──────────┼────────────────┼──────────┤ ├───────────────────┼────────────────────────┼──────────────────────────────────────────────────────────────┤ │ PyYAML │ CVE-2020-14343 │ CRITICAL │ │ 5.3 │ 5.4 │ PyYAML: incomplete fix for CVE-2020-1747 │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2020-14343 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2020-1747 │ │ │ │ 5.3.1 │ PyYAML: arbitrary command execution through │ │ │ │ │ │ │ │ python/object/new when FullLoader is used │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2020-1747 │ ├──────────┼────────────────┼──────────┤ ├───────────────────┼────────────────────────┼──────────────────────────────────────────────────────────────┤ │ requests │ CVE-2018-18074 │ HIGH │ │ 2.19.1 │ 2.20.0 │ python-requests: Redirect from HTTPS to HTTP does not remove │ │ │ │ │ │ │ │ Authorization header │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2018-18074 │ │ ├────────────────┼──────────┤ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2023-32681 │ MEDIUM │ │ │ 2.31.0 │ python-requests: Unintended leak of Proxy-Authorization │ │ │ │ │ │ │ │ header │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-32681 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2024-35195 │ │ │ │ 2.32.0 │ requests: subsequent requests to the same host ignore cert │ │ │ │ │ │ │ │ verification │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-35195 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2024-47081 │ │ │ │ 2.32.4 │ requests: Requests vulnerable to .netrc credentials leak via │ │ │ │ │ │ │ │ malicious URLs │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-47081 │ │ ├────────────────┤ │ │ ├────────────────────────┼──────────────────────────────────────────────────────────────┤ │ │ CVE-2026-25645 │ │ │ │ 2.33.0 │ requests: Requests: Security bypass due to predictable │ │ │ │ │ │ │ │ temporary file creation │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-25645 │ └──────────┴────────────────┴──────────┴────────┴───────────────────┴────────────────────────┴──────────────────────────────────────────────────────────────┘ Dockerfile (dockerfile) ======================= Tests: 3 (SUCCESSES: 0, FAILURES: 3) Failures: 3 (UNKNOWN: 0, LOW: 1, MEDIUM: 1, HIGH: 1, CRITICAL: 0) DS-0001 (MEDIUM): Specify a tag in the 'FROM' statement for image 'registry.access.redhat.com/ubi9/ubi-minimal' ════════════════════════════════════════ When using a 'FROM' statement you should use a specific tag to avoid uncontrolled behavior when the image is updated. See https://avd.aquasec.com/misconfig/ds-0001 ──────────────────────────────────────── Dockerfile:1 ──────────────────────────────────────── 1 [ FROM registry.access.redhat.com/ubi9/ubi-minimal ──────────────────────────────────────── DS-0002 (HIGH): Specify at least 1 USER command in Dockerfile with non-root user as argument ════════════════════════════════════════ Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile. See https://avd.aquasec.com/misconfig/ds-0002 ──────────────────────────────────────── DS-0026 (LOW): Add HEALTHCHECK instruction in your Dockerfile ════════════════════════════════════════ You should add HEALTHCHECK instruction in your docker container images to perform the health check on running containers. See https://avd.aquasec.com/misconfig/ds-0026 ──────────────────────────────────────── settings.py (secrets) ===================== Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 1) CRITICAL: GitHub (github-pat) ════════════════════════════════════════ GitHub Personal Access Token ──────────────────────────────────────── settings.py:1 (offset: 9 bytes) ──────────────────────────────────────── 1 [ token = "****************************************p" 2 ──────────────────────────────────────── ==== summary (rows per source and severity) ==== misconfig:trivy-fs HIGH 1 misconfig:trivy-fs LOW 1 misconfig:trivy-fs MEDIUM 1 secret:trivy-fs CRITICAL 1 vuln:grype CRITICAL 8 vuln:grype HIGH 16 vuln:grype LOW 4 vuln:grype MEDIUM 15 vuln:trivy-fs CRITICAL 8 vuln:trivy-fs HIGH 16 vuln:trivy-fs LOW 4 vuln:trivy-fs MEDIUM 15 policy: vulnerabilities>=high, misconfig>=high, secrets=true ==== BLOCKING findings (50) ==== misconfig:trivy-fs HIGH DS-0002 Image user should not be 'root' - -> no fix (Dockerfile) secret:trivy-fs CRITICAL github-pat GitHub Personal Access Token line 1 -> no fix (settings.py) vuln:grype CRITICAL GHSA-2gwj-7jmv-h26r django 3.2.0 -> 3.2.13 (/requirements.txt) vuln:grype CRITICAL GHSA-6757-jp84-gxfx pyyaml 5.3 -> 5.3.1 (/requirements.txt) vuln:grype CRITICAL GHSA-8q59-q68h-6hv4 pyyaml 5.3 -> 5.4 (/requirements.txt) vuln:grype CRITICAL GHSA-frmv-pr5f-9mcr django 3.2.0 -> 4.2.26 (/requirements.txt) vuln:grype CRITICAL GHSA-p64x-8rxx-wf6q django 3.2.0 -> 3.2.14 (/requirements.txt) vuln:grype CRITICAL GHSA-r3xc-prgr-mg9p django 3.2.0 -> 3.2.19 (/requirements.txt) vuln:grype CRITICAL GHSA-w24h-v9qh-8gxj django 3.2.0 -> 3.2.13 (/requirements.txt) vuln:grype CRITICAL GHSA-xpfp-f569-q3p2 django 3.2.0 -> 3.2.5 (/requirements.txt) vuln:grype HIGH GHSA-2hrw-hx67-34x6 django 3.2.0 -> 3.2.18 (/requirements.txt) vuln:grype HIGH GHSA-53qw-q765-4fww django 3.2.0 -> 3.2.11 (/requirements.txt) vuln:grype HIGH GHSA-6cw3-g6wv-c2xv django 3.2.0 -> 3.2.12 (/requirements.txt) vuln:grype HIGH GHSA-6w2r-r2m5-xq5w django 3.2.0 -> 4.2.24 (/requirements.txt) vuln:grype HIGH GHSA-8c5j-9r9f-c6w8 django 3.2.0 -> 3.2.11 (/requirements.txt) vuln:grype HIGH GHSA-8x94-hmjh-97hq django 3.2.0 -> 3.2.15 (/requirements.txt) vuln:grype HIGH GHSA-h8gc-pgj2-vjm3 django 3.2.0 -> 3.2.22 (/requirements.txt) vuln:grype HIGH GHSA-jh3w-4vvf-mjgr django 3.2.0 -> 3.2.20 (/requirements.txt) vuln:grype HIGH GHSA-p99v-5w3c-jqq9 django 3.2.0 -> 3.2.4 (/requirements.txt) vuln:grype HIGH GHSA-q2jf-h9jm-m7p4 django 3.2.0 -> 3.2.17 (/requirements.txt) vuln:grype HIGH GHSA-qmf9-6jqf-j8fq django 3.2.0 -> 3.2.23 (/requirements.txt) vuln:grype HIGH GHSA-qrw5-5h28-6cmg django 3.2.0 -> 3.2.16 (/requirements.txt) vuln:grype HIGH GHSA-qw25-v68c-qjf3 django 3.2.0 -> 4.2.26 (/requirements.txt) vuln:grype HIGH GHSA-rxjp-mfm9-w4wr django 3.2.0 -> 3.2.1 (/requirements.txt) vuln:grype HIGH GHSA-x84v-xcm2-53pg requests 2.19.1 -> 2.20.0 (/requirements.txt) vuln:grype HIGH GHSA-xxj9-f6rv-m3x4 django 3.2.0 -> 3.2.24 (/requirements.txt) vuln:trivy-fs CRITICAL CVE-2020-14343 PyYAML 5.3 -> 5.4 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2020-1747 PyYAML 5.3 -> 5.3.1 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2021-35042 Django 3.2.0 -> 3.2.5, 3.1.13 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2022-28346 Django 3.2.0 -> 2.2.28, 3.2.13, 4.0.4 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2022-28347 Django 3.2.0 -> 2.2.28, 3.2.13, 4.0.4 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2022-34265 Django 3.2.0 -> 3.2.14, 4.0.6 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2023-31047 Django 3.2.0 -> 3.2.19, 4.1.9, 4.2.1 (requirements.txt) vuln:trivy-fs CRITICAL CVE-2025-64459 Django 3.2.0 -> 5.2.8, 5.1.14, 4.2.26 (requirements.txt) vuln:trivy-fs HIGH CVE-2018-18074 requests 2.19.1 -> 2.20.0 (requirements.txt) vuln:trivy-fs HIGH CVE-2021-31542 Django 3.2.0 -> 2.2.21, 3.1.9, 3.2.1 (requirements.txt) vuln:trivy-fs HIGH CVE-2021-33571 Django 3.2.0 -> 2.2.24, 3.1.12, 3.2.4 (requirements.txt) vuln:trivy-fs HIGH CVE-2021-45115 Django 3.2.0 -> 2.2.26, 3.2.11, 4.0.1 (requirements.txt) vuln:trivy-fs HIGH CVE-2021-45116 Django 3.2.0 -> 2.2.26, 3.2.11, 4.0.1 (requirements.txt) vuln:trivy-fs HIGH CVE-2022-23833 Django 3.2.0 -> 2.2.27, 3.2.12, 4.0.2 (requirements.txt) vuln:trivy-fs HIGH CVE-2022-36359 Django 3.2.0 -> 3.2.15, 4.0.7 (requirements.txt) vuln:trivy-fs HIGH CVE-2022-41323 Django 3.2.0 -> 3.2.16, 4.0.8, 4.1.2 (requirements.txt) vuln:trivy-fs HIGH CVE-2023-23969 Django 3.2.0 -> 3.2.17, 4.0.9, 4.1.6 (requirements.txt) vuln:trivy-fs HIGH CVE-2023-24580 Django 3.2.0 -> 3.2.18, 4.1.7, 4.0.10 (requirements.txt) vuln:trivy-fs HIGH CVE-2023-36053 Django 3.2.0 -> 3.2.20, 4.1.10, 4.2.3 (requirements.txt) vuln:trivy-fs HIGH CVE-2023-43665 Django 3.2.0 -> 3.2.22, 4.1.12, 4.2.6 (requirements.txt) vuln:trivy-fs HIGH CVE-2023-46695 Django 3.2.0 -> 3.2.23, 4.1.13, 4.2.7 (requirements.txt) vuln:trivy-fs HIGH CVE-2024-24680 Django 3.2.0 -> 3.2.24, 4.2.10, 5.0.2 (requirements.txt) vuln:trivy-fs HIGH CVE-2025-57833 Django 3.2.0 -> 4.2.24, 5.1.12, 5.2.6 (requirements.txt) vuln:trivy-fs HIGH CVE-2025-64458 Django 3.2.0 -> 5.2.8, 5.1.14, 4.2.26 (requirements.txt) SECURITY GATE: FAIL ==== syft dir:/tmp/tmp.1BLdqIRLwi/clean ==== packages catalogued: 0 ==== grype sbom:/tmp/tmp.1BLdqIRLwi/r-clean/sbom.syft.json ==== No vulnerabilities found ==== trivy fs /tmp/tmp.1BLdqIRLwi/clean ==== 2026-09-11T14:13:04Z INFO Loaded file_path="/etc/devsecops/trivy.yaml" 2026-09-11T14:13:04Z INFO [vuln] Vulnerability scanning is enabled 2026-09-11T14:13:04Z INFO [misconfig] Misconfiguration scanning is enabled 2026-09-11T14:13:04Z INFO [checks-client] No downloadable checks were loaded as --skip-check-update is enabled, loading from existing cache... 2026-09-11T14:13:05Z INFO [secret] Secret scanning is enabled 2026-09-11T14:13:05Z INFO [secret] If your scanning is slow, please try '--scanners vuln,misconfig' to disable secret scanning 2026-09-11T14:13:05Z INFO [secret] Please see https://trivy.dev/docs/v0.74/guide/scanner/secret#recommendation for faster secret detection 2026-09-11T14:13:05Z INFO Number of language-specific files num=0 2026-09-11T14:13:05Z INFO Detected config files num=0 ==== summary (rows per source and severity) ==== (no findings) policy: vulnerabilities>=high, misconfig>=high, secrets=true SECURITY GATE: PASS SMOKE TEST: PASS (vulnerable fixture blocked, clean fixture passed)