github.com/ggml-org/llama.cpp
Submitted 8/4/2026, 10:25:53 AM · Status: ok
Risk grade
F
100 / 100
Findings
828
18 critical41 high766 medium3 low0 info0 on CISA KEV0ATT&CK
Showing 828 of 828 findings
Findings
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/zendnn.Dockerfile:100
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/vulkan.Dockerfile:121
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/vulkan.Dockerfile:110
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/s390x.Dockerfile:141
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/s390x.Dockerfile:127
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/rocm.Dockerfile:141
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/rocm.Dockerfile:130
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/musa.Dockerfile:129
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/musa.Dockerfile:118
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/intel.Dockerfile:156
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/intel.Dockerfile:144
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/cuda.Dockerfile:127
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/cuda.Dockerfile:116
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/cann.Dockerfile:159
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/cann.Dockerfile:148
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/cpu.Dockerfile:118
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/cpu.Dockerfile:107
- COPY with more than two arguments not ending with slashWhen a COPY command has more than two arguments, the last one should end with a slash.trivy.devops/zendnn.Dockerfile:111
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)semgreptools/ui/src/lib/vendors/nerdamer-prime/nerdamer.core.js:6248
- subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list ansubprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list and shell=False. (First-party socbox; Apache-2.0.)semgreptools/server/bench/bench.py:229
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/vulkan.Dockerfile:67
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/vulkan.Dockerfile:89
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/rocm.Dockerfile:94
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/rocm.Dockerfile:111
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/rocm.Dockerfile:42
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/openvino.Dockerfile:130
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/musa.Dockerfile:82
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/musa.Dockerfile:99
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/intel.Dockerfile:27
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/intel.Dockerfile:120
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/intel.Dockerfile:104
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/cuda.Dockerfile:34
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/cuda.Dockerfile:79
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/cuda.Dockerfile:96
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/zendnn.Dockerfile:22
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/zendnn.Dockerfile:64
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/zendnn.Dockerfile:81
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/musa.Dockerfile:32
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/cpu.Dockerfile:24
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/cpu.Dockerfile:88
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivy.devops/cpu.Dockerfile:71
- 'yum clean all' missingYou should use 'yum clean all' after using a 'yum install' command to clean package cached data and reduce image size.trivy.devops/llama-cli-cann.Dockerfile:12
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/zendnn.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/vulkan.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/s390x.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/rocm.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/openvino.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/musa.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/llama-cli-cann.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/intel.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/cuda.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/cann.Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivy.devops/cpu.Dockerfile:0
- urllib3: urllib3 Streaming API improperly handles highly compressed dataurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…trivyCVE-2025-66471
- urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…trivyCVE-2026-21441
- urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.trivyCVE-2026-44431
- urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…trivyCVE-2025-66418
This report is public.