Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

dottxt-ai/outlines

https://github.com/dottxt-ai/outlines · scanned 2026-07-23 10:40 UTC (1 month, 2 weeks ago)

305 raw signals (0 security + 305 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 1 month, 2 weeks ago · v5 · last Δ +16.1 (diff) · 305 actionable findings from 1 signal source. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Scan summary Repository scanned at 80.3/100 with 70.0% coverage. It contains 2062 nodes across 0 cross-layer flows, written primarily in mixed languages. Engine surfaced 305 findings — concentrated in dependencies (184), security (102), quality (10). Risk profile is high: 4 critical, 50 high, 215 medium. Recommended next step: open the dependencies layer findings first — that's where the highest-impact wins live.

Showing 303 of 305 actionable findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-fgcw-684q-jj6r
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-fgcw-684q-jj6r (aka CVE-2026-5241). huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path Aliases: CVE-2026-5241, G…
examples/bentoml/requirements.txt ScaOsvGhsa fgcw 684q jj6r
critical System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.57.1: GHSA-fgcw-684q-jj6r
OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by GHSA-fgcw-684q-jj6r (aka CVE-2026-5241). huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path Aliases: CVE-2026-5241, GHSA-fgcw-684q-jj6r, PYSEC-…
uv.lock ScaOsvGhsa fgcw 684q jj6r
critical System graph dependencies dependencies conf 0.90 Vulnerable dependency urllib3 2.5.0: GHSA-2xpw-w6gg-jr37
OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-2xpw-w6gg-jr37 (aka CVE-2025-66471). Note: `urllib3` is a transitive dependency — pulled in by another package, not declared directly in a manifest. urllib3 streaming API improperly handles highly compressed d…
uv.lock ScaOsvGhsa 2xpw w6gg jr37
critical System graph dependencies dependencies conf 0.90 Vulnerable dependency urllib3 2.5.0: GHSA-38jv-5279-wg99
OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-38jv-5279-wg99 (aka CVE-2026-21441). Note: `urllib3` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Decompression-bomb safeguards bypassed when following HTTP r…
uv.lock ScaOsvGhsa 38jv 5279 wg99
high System graph security Trivy conf 1.00 CVE-2024-11392: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary cod…
VulnCve 2024 11392
high System graph security Trivy conf 1.00 CVE-2024-11393: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…
VulnCve 2024 11393
high System graph security Trivy conf 1.00 CVE-2024-11394: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …
VulnCve 2024 11394
high System graph security Trivy conf 1.00 CVE-2025-66418: urllib3 2.5.0 — uv.lock
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimi…
VulnCve 2025 66418
high System graph security Trivy conf 1.00 CVE-2025-66471: urllib3 2.5.0 — uv.lock
urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handlin…
VulnCve 2025 66471
high System graph security Trivy conf 1.00 CVE-2025-69223: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a comp…
VulnCve 2025 69223
high System graph security Trivy conf 1.00 CVE-2026-0897: keras 3.12.0 — uv.lock
Keras: Keras: Denial of Service via crafted HDF5 weight loading file Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion…
VulnCve 2026 0897
high System graph security Trivy conf 1.00 CVE-2026-0994: protobuf 6.33.1 — uv.lock
python: protobuf: Protobuf: Denial of Service due to recursion depth bypass A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing rec…
VulnCve 2026 0994
high System graph security Trivy conf 1.00 CVE-2026-1462: keras 3.12.0 — uv.lock
keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypas…
VulnCve 2026 1462
high System graph security Trivy conf 1.00 CVE-2026-1669: keras 3.12.0 — uv.lock
keras: Keras: Information disclosure via arbitrary file read in model loading mechanism Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive inform…
VulnCve 2026 1669
high System graph security Trivy conf 1.00 CVE-2026-21441: urllib3 2.5.0 — uv.lock
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loadin…
VulnCve 2026 21441
high System graph security Trivy conf 1.00 CVE-2026-23490: pyasn1 0.6.1 — uv.lock
pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnera…
VulnCve 2026 23490
high System graph security Trivy conf 1.00 CVE-2026-24049: wheel 0.45.1 — uv.lock
wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mi…
VulnCve 2026 24049
high System graph security Trivy conf 1.00 CVE-2026-25048: xgrammar 0.1.27 — uv.lock
xgrammar: xgrammar: Denial of Service via multi-level nested syntax xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in versi…
VulnCve 2026 25048
high System graph security Trivy conf 1.00 CVE-2026-25087: pyarrow 22.0.0 — uv.lock
apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) wi…
VulnCve 2026 25087
high System graph security Trivy conf 1.00 CVE-2026-25990: pillow 12.0.0 — uv.lock
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: pillow Installed: 12.0.0 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.1 — uv.lock
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-40192: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-42311: pillow 12.0.0 — uv.lock
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-4372: transformers 4.38.2 — examples/bentoml/requirements.txt
HuggingFace transformers vulnerable to remote code execution A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_impl…
VulnCve 2026 4372
high System graph security Trivy conf 1.00 CVE-2026-4372: transformers 4.57.1 — uv.lock
HuggingFace transformers vulnerable to remote code execution A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_impl…
VulnCve 2026 4372
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.5.0 — uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-5241: transformers 4.38.2 — examples/bentoml/requirements.txt
python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initial…
VulnCve 2026 5241
high System graph security Trivy conf 1.00 CVE-2026-5241: transformers 4.57.1 — uv.lock
python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initial…
VulnCve 2026 5241
high System graph security Trivy conf 1.00 CVE-2026-54058: pillow 12.0.0 — uv.lock
Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride small…
VulnCve 2026 54058
high System graph security Trivy conf 1.00 CVE-2026-54059: pillow 12.0.0 — uv.lock
python-pillow: Pillow: Denial of Service via crafted PCF font data Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_chec…
VulnCve 2026 54059
high System graph security Trivy conf 1.00 CVE-2026-54060: pillow 12.0.0 — uv.lock
python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._d…
VulnCve 2026 54060
high System graph security Trivy conf 1.00 CVE-2026-55379: pillow 12.0.0 — uv.lock
python-pillow: Pillow: Denial of Service via crafted BDF font file Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompressi…
VulnCve 2026 55379
high System graph security Trivy conf 1.00 CVE-2026-55380: pillow 12.0.0 — uv.lock
python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing …
VulnCve 2026 55380
high System graph security Trivy conf 1.00 CVE-2026-59197: pillow 12.0.0 — uv.lock
Pillow: Pillow: Native heap out-of-bounds write Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2…
VulnCve 2026 59197
high System graph security Trivy conf 1.00 CVE-2026-59199: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.…
VulnCve 2026 59199
high System graph security Trivy conf 1.00 CVE-2026-59200: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of service via crafted PDF stream Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a c…
VulnCve 2026 59200
high System graph security Trivy conf 1.00 CVE-2026-59204: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 fi…
VulnCve 2026 59204
high System graph security Trivy conf 1.00 CVE-2026-59205: pillow 12.0.0 — uv.lock
Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode …
VulnCve 2026 59205
high System graph security Trivy conf 1.00 CVE-2026-59885: pyasn1 0.6.1 — uv.lock
pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted p…
VulnCve 2026 59885
high System graph security Trivy conf 1.00 CVE-2026-59886: pyasn1 0.6.1 — uv.lock
pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a f…
VulnCve 2026 59886
high System graph security Trivy conf 1.00 GHSA-6v7p-g79w-8964: msgpack 1.1.2 — uv.lock
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error ### Impact If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerab…
VulnGhsa 6v7p g79w 8964
high System graph dependencies dependencies conf 0.90 Vulnerable dependency keras 3.12.0: GHSA-3m4q-jmj6-r34q
OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by GHSA-3m4q-jmj6-r34q (aka CVE-2026-1669). Note: `keras` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Keras has a Local File Disclosure via HDF5 External Storage Duri…
uv.lock ScaOsvGhsa 3m4q jmj6 r34q
high System graph dependencies dependencies conf 0.90 Vulnerable dependency keras 3.12.0: GHSA-4f3f-g24h-fr8m
OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by GHSA-4f3f-g24h-fr8m (aka CVE-2026-1462). Note: `keras` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Keras has an untrusted deserialization vulnerability Aliases: C…
uv.lock ScaOsvGhsa 4f3f g24h fr8m
high System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-45hq-cxwh-f6vc
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-45hq-cxwh-f6vc (aka CVE-2026-55379). Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading Aliases: BIT-pillow-2026-55379, CVE-2026-55379, …
uv.lock ScaOsvGhsa 45hq cxwh f6vc
high System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-5x94-69rx-g8h2
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-5x94-69rx-g8h2 (aka CVE-2026-54060). Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` Aliases: BIT-pillow-2026-54060, CVE-2026-54060, PYSEC-2026-2254 Advisory: https://…
uv.lock ScaOsvGhsa 5x94 69rx g8h2
high System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-62p4-gmf7-7g93
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-62p4-gmf7-7g93 (aka CVE-2026-54058). Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) Aliases: BIT-pillow-2026-54058, CVE-2026-54058 Advisory: https://os…
uv.lock ScaOsvGhsa 62p4 gmf7 7g93
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-29pf-2h5f-8g72
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-29pf-2h5f-8g72 (aka CVE-2026-4372). HuggingFace transformers vulnerable to remote code execution Aliases: CVE-2026-4372, GHSA-29pf-2h5f-8g72, PYSEC-2026-2289 Advisory: https://…
examples/bentoml/requirements.txt ScaOsvGhsa 29pf 2h5f 8g72
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-69w3-r845-3855
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-69w3-r845-3855 (aka CVE-2026-1839). HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class Aliases: CVE-2026-1839, GHSA-69w3-r845-3855, PYSEC-2026-…
examples/bentoml/requirements.txt ScaOsvGhsa 69w3 r845 3855
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-217
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-217 (aka CVE-2025-14929). No summary published yet. Aliases: CVE-2025-14929 Advisory: https://osv.dev/vulnerability/PYSEC-2025-217 Fix: upgrade `transformers` past the af…
examples/bentoml/requirements.txt ScaOsvPysec 2025 217
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-218
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-218 (aka CVE-2025-14930). No summary published yet. Aliases: CVE-2025-14930 Advisory: https://osv.dev/vulnerability/PYSEC-2025-218 Fix: upgrade `transformers` past the af…
examples/bentoml/requirements.txt ScaOsvPysec 2025 218
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.57.1: GHSA-29pf-2h5f-8g72
OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by GHSA-29pf-2h5f-8g72 (aka CVE-2026-4372). HuggingFace transformers vulnerable to remote code execution Aliases: CVE-2026-4372, GHSA-29pf-2h5f-8g72, PYSEC-2026-2289 Advisory: https://osv.dev/vulnerability/GHSA…
uv.lock ScaOsvGhsa 29pf 2h5f 8g72
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.57.1: GHSA-69w3-r845-3855
OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by GHSA-69w3-r845-3855 (aka CVE-2026-1839). HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class Aliases: CVE-2026-1839, GHSA-69w3-r845-3855, PYSEC-2026-2288 Advisory: https://osv…
uv.lock ScaOsvGhsa 69w3 r845 3855
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.57.1: PYSEC-2025-217
OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by PYSEC-2025-217 (aka CVE-2025-14929). No summary published yet. Aliases: CVE-2025-14929 Advisory: https://osv.dev/vulnerability/PYSEC-2025-217 Fix: upgrade `transformers` past the affected range per the advis…
uv.lock ScaOsvPysec 2025 217
high System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.57.1: PYSEC-2025-218
OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by PYSEC-2025-218 (aka CVE-2025-14930). No summary published yet. Aliases: CVE-2025-14930 Advisory: https://osv.dev/vulnerability/PYSEC-2025-218 Fix: upgrade `transformers` past the affected range per the advis…
uv.lock ScaOsvPysec 2025 218
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph security Trivy conf 1.00 CVE-2024-12720: transformers 4.38.2 — examples/bentoml/requirements.txt
Transformers Regular Expression Denial of Service (ReDoS) vulnerability A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() f…
VulnCve 2024 12720
medium System graph security Trivy conf 1.00 CVE-2025-1194: transformers 4.38.2 — examples/bentoml/requirements.txt
Transformers Regular Expression Denial of Service (ReDoS) vulnerability A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerabilit…
VulnCve 2025 1194
medium System graph security Trivy conf 1.00 CVE-2025-2099: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The …
VulnCve 2025 2099
medium System graph security Trivy conf 1.00 CVE-2025-2999: torch 2.9.0 — uv.lock
A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ... A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requi…
VulnCve 2025 2999
medium System graph security Trivy conf 1.00 CVE-2025-3263: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuratio…
VulnCve 2025 3263
medium System graph security Trivy conf 1.00 CVE-2025-3264: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerabi…
VulnCve 2025 3264
medium System graph security Trivy conf 1.00 CVE-2025-3933: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affe…
VulnCve 2025 3933
medium System graph security Trivy conf 1.00 CVE-2025-5197: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Transformers ReDoS Vulnerability A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names …
VulnCve 2025 5197
medium System graph security Trivy conf 1.00 CVE-2025-6051: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This v…
VulnCve 2025 6051
medium System graph security Trivy conf 1.00 CVE-2025-66221: werkzeug 3.1.3 — uv.lock
Werkzeug: Werkzeug: Denial of service via Windows device names in path segments Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AU…
VulnCve 2025 66221
medium System graph security Trivy conf 1.00 CVE-2025-6638: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerabil…
VulnCve 2025 6638
medium System graph security Trivy conf 1.00 CVE-2025-68146: filelock 3.20.0 — uv.lock
filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncation filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers t…
VulnCve 2025 68146
medium System graph security Trivy conf 1.00 CVE-2025-6921: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_de…
VulnCve 2025 6921
medium System graph security Trivy conf 1.00 CVE-2025-69227: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Denial of Service via specially crafted POST request AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST…
VulnCve 2025 69227
medium System graph security Trivy conf 1.00 CVE-2025-69228: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during p…
VulnCve 2025 69228
medium System graph security Trivy conf 1.00 CVE-2025-69229: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large numbe…
VulnCve 2025 69229
medium System graph security Trivy conf 1.00 CVE-2025-69872: diskcache 5.6.3 — uv.lock
python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim appli…
VulnCve 2025 69872
medium System graph security Trivy conf 1.00 CVE-2025-71176: pytest 9.0.1 — uv.lock
pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges. Package: pytest In…
VulnCve 2025 71176
medium System graph security Trivy conf 1.00 CVE-2026-1839: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line …
VulnCve 2026 1839
medium System graph security Trivy conf 1.00 CVE-2026-1839: transformers 4.57.1 — uv.lock
transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line …
VulnCve 2026 1839
medium System graph security Trivy conf 1.00 CVE-2026-21860: werkzeug 3.1.3 — uv.lock
Werkzeug safe_join() allows Windows special device names with compound extensions Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows…
VulnCve 2026 21860
medium System graph security Trivy conf 1.00 CVE-2026-22701: filelock 3.20.0 — uv.lock
filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access …
VulnCve 2026 22701
medium System graph security Trivy conf 1.00 CVE-2026-22702: virtualenv 20.35.4 — uv.lock
virtualenv: virtualenv: Local attacker can redirect file operations via TOCTOU race condition virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-…
VulnCve 2026 22702
medium System graph security Trivy conf 1.00 CVE-2026-22815: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched …
VulnCve 2026 22815
medium System graph security Trivy conf 1.00 CVE-2026-25645: requests 2.32.5 — uv.lock
requests: Requests: Security bypass due to predictable temporary file creation Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. …
VulnCve 2026 25645
medium System graph security Trivy conf 1.00 CVE-2026-27199: werkzeug 3.1.3 — uv.lock
Werkzeug safe_join() allows Windows special device names Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported as GHSA-hgf8-39gv-g3f2, but…
VulnCve 2026 27199
medium System graph security Trivy conf 1.00 CVE-2026-34515: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been pat…
VulnCve 2026 34515
medium System graph security Trivy conf 1.00 CVE-2026-34516: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Denial of Service via excessive multipart headers AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowin…
VulnCve 2026 34516
medium System graph security Trivy conf 1.00 CVE-2026-34525: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Security bypass via multiple Host headers AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4. Package: aiohttp Installed: 3.13.2 Fix…
VulnCve 2026 34525
medium System graph security Trivy conf 1.00 CVE-2026-34993: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using th…
VulnCve 2026 34993
medium System graph security Trivy conf 1.00 CVE-2026-42308: pillow 12.0.0 — uv.lock
Pillow: python: Pillow: Denial of Service via integer overflow in font processing Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This i…
VulnCve 2026 42308
medium System graph security Trivy conf 1.00 CVE-2026-42309: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of Service via specially crafted coordinate input Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw…
VulnCve 2026 42309
medium System graph security Trivy conf 1.00 CVE-2026-42310: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of Service via malicious PDF processing Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issu…
VulnCve 2026 42310
medium System graph security Trivy conf 1.00 CVE-2026-45409: idna 3.11 — uv.lock
python-idna: idna: Denial of Service via specially crafted long inputs Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as …
VulnCve 2026 45409
medium System graph security Trivy conf 1.00 CVE-2026-47265: aiohttp 3.13.2 — uv.lock
python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cr…
VulnCve 2026 47265
medium System graph security Trivy conf 1.00 CVE-2026-54273: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to …
VulnCve 2026 54273
medium System graph security Trivy conf 1.00 CVE-2026-54274: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory …
VulnCve 2026 54274
medium System graph security Trivy conf 1.00 CVE-2026-54276: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This like…
VulnCve 2026 54276
medium System graph security Trivy conf 1.00 CVE-2026-54277: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using…
VulnCve 2026 54277
medium System graph security Trivy conf 1.00 CVE-2026-54278: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one ch…
VulnCve 2026 54278
medium System graph security Trivy conf 1.00 CVE-2026-55798: pillow 12.0.0 — uv.lock
python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result t…
VulnCve 2026 55798
medium System graph security Trivy conf 1.00 CVE-2026-59198: pillow 12.0.0 — uv.lock
Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copie…
VulnCve 2026 59198
medium System graph security Trivy conf 1.00 CVE-2026-59203: pillow 12.0.0 — uv.lock
Pillow: Pillow: Denial of Service via crafted EPS file Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to t…
VulnCve 2026 59203
medium System graph security Trivy conf 1.00 CVE-2026-59890: setuptools 80.9.0 — uv.lock
setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursiv…
VulnCve 2026 59890
medium System graph dependencies dependencies conf 0.90 Dependency datasets is two or more major versions behind
`datasets` is pinned at `2.18.0` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `5.0.0` — 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `datasets…
examples/bentoml/requirements.txt FreshnessOutdated
medium System graph security Semgrep conf 1.00 eval detected — examples/math_generate_code.py:36
Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. Rule: python.lang.security.audit.eval-detected.…
SecurityPython
medium System graph cicd CI/CD security conf 1.00 GitHub Actions workflow grants broad write permissions
CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions.
.github/workflows/deploy_documentation.yml CI/CD securitySupply chainGithub actions
medium System graph cicd CI/CD security conf 1.00 GitHub Actions workflow grants broad write permissions
CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions.
.github/workflows/publish_documentation.yml CI/CD securitySupply chainGithub actions
medium System graph quality Integrity conf 1.00 Network/subprocess call without timeout or try/except — examples/react.py:47
`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
runtime safetyRobustness
medium System graph security Coverage conf 1.00 No auth library detected
The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing.
auth
medium System graph security Semgrep conf 1.00 var in href — docs/overrides/home.html:130
Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely…
SecurityHtml templates
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-2fqr-mr3j-6wp8
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279). Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. aiohttp: Host-Only Cookies Become Domain Cookies After Cook…
uv.lock ScaOsvGhsa 2fqr mr3j 6wp8
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-2vrm-gr82-f7m5
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514). Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. AIOHTTP has CRLF injection through multipart part content t…
uv.lock ScaOsvGhsa 2vrm gr82 f7m5
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-3wq7-rqq7-wx6j
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517). Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. AIOHTTP has late size enforcement for non-file multipart fi…
uv.lock ScaOsvGhsa 3wq7 rqq7 wx6j
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-4fvr-rgm6-gqmc
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273). Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. aiohttp: HTTP/1 Pipelined Requests Queue Without Limit Ali…
uv.lock ScaOsvGhsa 4fvr rgm6 gqmc
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-4m7w-qmgq-4wj5
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275). Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. aiohttp: TLS Server Hostname Override Is Ignored When Reusi…
uv.lock ScaOsvGhsa 4m7w qmgq 4wj5
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-54jq-c3m8-4m76
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-54jq-c3m8-4m76 (aka CVE-2025-69226). Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. AIOHTTP vulnerable to brute-force leak of internal static fi…
uv.lock ScaOsvGhsa 54jq c3m8 4m76
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-63hf-3vf5-4wqf
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-63hf-3vf5-4wqf. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-63hf-3vf…
uv.lock ScaOsvGhsa 63hf 3vf5 4wqf
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-63hw-fmq6-xxg2
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-63hw-fmq6-xxg2. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-63hw-fmq…
uv.lock ScaOsvGhsa 63hw fmq6 xxg2
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-69f9-5gxw-wvc2
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-69f9-5gxw-wvc2. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-69f9-5gx…
uv.lock ScaOsvGhsa 69f9 5gxw wvc2
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-6jhg-hg63-jvvf
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-6jhg-hg63-jvvf. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6jhg-hg6…
uv.lock ScaOsvGhsa 6jhg hg63 jvvf
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-6mq8-rvhq-8wgg
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-6mq8-rvhq-8wgg. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6mq8-rvh…
uv.lock ScaOsvGhsa 6mq8 rvhq 8wgg
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-966j-vmvw-g2g9
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-966j-vmvw-g2g9. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-966j-vmv…
uv.lock ScaOsvGhsa 966j vmvw g2g9
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-9x8q-7h8h-wcw9
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8…
uv.lock ScaOsvGhsa 9x8q 7h8h wcw9
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-c427-h43c-vf67
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-c427-h43c-vf67. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-c427-h43…
uv.lock ScaOsvGhsa c427 h43c vf67
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-fh55-r93g-j68g
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-fh55-r93g-j68g. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-fh55-r93…
uv.lock ScaOsvGhsa fh55 r93g j68g
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-g3cq-j2xw-wf74
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-g3cq-j2xw-wf74. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-g3cq-j2x…
uv.lock ScaOsvGhsa g3cq j2xw wf74
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-g84x-mcqj-x9qq
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-g84x-mcqj-x9qq. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-g84x-mcq…
uv.lock ScaOsvGhsa g84x mcqj x9qq
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-hcc4-c3v8-rx92
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-hcc4-c3v8-rx92. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hcc4-c3v…
uv.lock ScaOsvGhsa hcc4 c3v8 rx92
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-hg6j-4rv6-33pg
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-hg6j-4rv6-33pg. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hg6j-4rv…
uv.lock ScaOsvGhsa hg6j 4rv6 33pg
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-hpj7-wq8m-9hgp
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-hpj7-wq8m-9hgp. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hpj7-wq8…
uv.lock ScaOsvGhsa hpj7 wq8m 9hgp
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-jg22-mg44-37j8
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-jg22-mg44-37j8. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jg22-mg4…
uv.lock ScaOsvGhsa jg22 mg44 37j8
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-jj3x-wxrx-4x23
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-jj3x-wxrx-4x23. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jj3x-wxr…
uv.lock ScaOsvGhsa jj3x wxrx 4x23
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-m5qp-6w8w-w647
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-m5qp-6w8w-w647. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-m5qp-6w8…
uv.lock ScaOsvGhsa m5qp 6w8w w647
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-m6qw-4cw2-hm4m
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-m6qw-4cw2-hm4m. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-m6qw-4cw…
uv.lock ScaOsvGhsa m6qw 4cw2 hm4m
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-mqqc-3gqh-h2x8
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-mqqc-3gqh-h2x8. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-mqqc-3gq…
uv.lock ScaOsvGhsa mqqc 3gqh h2x8
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-mwh4-6h8g-pg8w
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-mwh4-6h8g-pg8w. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-mwh4-6h8…
uv.lock ScaOsvGhsa mwh4 6h8g pg8w
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-p998-jp59-783m
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-p998-jp59-783m. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-p998-jp5…
uv.lock ScaOsvGhsa p998 jp59 783m
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-w2fm-2cpv-w7v5
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-w2fm-2cpv-w7v5. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-w2fm-2cp…
uv.lock ScaOsvGhsa w2fm 2cpv w7v5
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: GHSA-xcgm-r5h9-7989
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-xcgm-r5h9-7989. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-xcgm-r5h…
uv.lock ScaOsvGhsa xcgm r5h9 7989
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1099
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1099. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1099 F…
uv.lock ScaOsvPysec 2026 1099
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1100
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1100. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1100 F…
uv.lock ScaOsvPysec 2026 1100
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1101
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1101. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1101 F…
uv.lock ScaOsvPysec 2026 1101
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1105
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1105. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1105 F…
uv.lock ScaOsvPysec 2026 1105
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1106
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1106. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1106 F…
uv.lock ScaOsvPysec 2026 1106
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1107
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1107. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1107 F…
uv.lock ScaOsvPysec 2026 1107
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1109
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1109. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1109 F…
uv.lock ScaOsvPysec 2026 1109
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2094
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2094. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2094 F…
uv.lock ScaOsvPysec 2026 2094
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2095
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2095. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2095 F…
uv.lock ScaOsvPysec 2026 2095
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2097
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2097. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2097 F…
uv.lock ScaOsvPysec 2026 2097
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2098
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2098. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2098 F…
uv.lock ScaOsvPysec 2026 2098
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2100
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2100. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2100 F…
uv.lock ScaOsvPysec 2026 2100
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2101
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2101. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2101 F…
uv.lock ScaOsvPysec 2026 2101
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2102
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2102. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2102 F…
uv.lock ScaOsvPysec 2026 2102
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2103
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2103. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2103 F…
uv.lock ScaOsvPysec 2026 2103
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2104
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2104. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2104 F…
uv.lock ScaOsvPysec 2026 2104
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2105
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2105. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2105 F…
uv.lock ScaOsvPysec 2026 2105
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2106
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2106. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2106 F…
uv.lock ScaOsvPysec 2026 2106
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2108
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2108. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2108 F…
uv.lock ScaOsvPysec 2026 2108
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2109
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2109. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2109 F…
uv.lock ScaOsvPysec 2026 2109
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2110
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2110. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2110 F…
uv.lock ScaOsvPysec 2026 2110
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2111
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2111. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2111 F…
uv.lock ScaOsvPysec 2026 2111
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2113
OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2113. Note: `aiohttp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2113 F…
uv.lock ScaOsvPysec 2026 2113
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency click 8.2.1: PYSEC-2026-2132
OSV.dev reports `click` at version `8.2.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2132. Note: `click` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2132 Fix: u…
uv.lock ScaOsvPysec 2026 2132
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency diskcache 5.6.3: GHSA-w8v5-vhqr-4h9v
OSV.dev reports `diskcache` at version `5.6.3` (resolved in `uv.lock`) is affected by GHSA-w8v5-vhqr-4h9v. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-w8v5-vhqr-4h9v Fix: upgrade `diskcache` past the affected range per the advisory.
uv.lock ScaOsvGhsa w8v5 vhqr 4h9v
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency diskcache 5.6.3: PYSEC-2026-2447
OSV.dev reports `diskcache` at version `5.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2447. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2447 Fix: upgrade `diskcache` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2447
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency filelock 3.20.0: GHSA-qmgc-5h2g-mvrw
OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by GHSA-qmgc-5h2g-mvrw. Note: `filelock` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qmgc-5…
uv.lock ScaOsvGhsa qmgc 5h2g mvrw
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency filelock 3.20.0: GHSA-w853-jp5j-5j7f
OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by GHSA-w853-jp5j-5j7f. Note: `filelock` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-w853-j…
uv.lock ScaOsvGhsa w853 jp5j 5j7f
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency filelock 3.20.0: PYSEC-2026-1374
OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by PYSEC-2026-1374. Note: `filelock` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1374…
uv.lock ScaOsvPysec 2026 1374
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency filelock 3.20.0: PYSEC-2026-1375
OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by PYSEC-2026-1375. Note: `filelock` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1375…
uv.lock ScaOsvPysec 2026 1375
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx
OSV.dev reports `idna` at version `3.11` (resolved in `uv.lock`) is affected by GHSA-65pc-fj4g-8rjx (aka CVE-2026-45409). Note: `idna` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Internationalized Domain Names in Applications (IDNA): Specially cr…
uv.lock ScaOsvGhsa 65pc fj4g 8rjx
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency keras 3.12.0: GHSA-mgx6-5cf9-rr43
OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by GHSA-mgx6-5cf9-rr43. Note: `keras` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-mgx6-5cf9-rr…
uv.lock ScaOsvGhsa mgx6 5cf9 rr43
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency keras 3.12.0: PYSEC-2026-2324
OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2324. Note: `keras` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2324 Fix: …
uv.lock ScaOsvPysec 2026 2324
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency keras 3.12.0: PYSEC-2026-73
OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by PYSEC-2026-73. Note: `keras` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-73 Fix: upgr…
uv.lock ScaOsvPysec 2026 73
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency msgpack 1.1.2: GHSA-6v7p-g79w-8964
OSV.dev reports `msgpack` at version `1.1.2` (resolved in `uv.lock`) is affected by GHSA-6v7p-g79w-8964. Note: `msgpack` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6v7p-g79w…
uv.lock ScaOsvGhsa 6v7p g79w 8964
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-4x4j-2g7c-83w6
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-4x4j-2g7c-83w6 (aka CVE-2026-55798). Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path Aliases: BIT-pillow-2026-55798, CVE-2026-55798, PYSEC-2026-2257 Advisory: https://osv.dev…
uv.lock ScaOsvGhsa 4x4j 2g7c 83w6
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-5xmw-vc9v-4wf2
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-5xmw-vc9v-4wf2 (aka CVE-2026-42309). Pillow has a heap buffer overflow with nested list coordinates Aliases: BIT-pillow-2026-42309, CVE-2026-42309, PYSEC-2026-2251 Advisory: https://osv.dev/vulnerability/GHSA…
uv.lock ScaOsvGhsa 5xmw vc9v 4wf2
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-6r8x-57c9-28j4
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-6r8x-57c9-28j4. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa 6r8x 57c9 28j4
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-8v84-f9pq-wr9x
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-8v84-f9pq-wr9x. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa 8v84 f9pq wr9x
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-9hw9-ch79-4vh6
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-9hw9-ch79-4vh6. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa 9hw9 ch79 4vh6
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-cfh3-3jmp-rvhc
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-cfh3-3jmp-rvhc. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-cfh3-3jmp-rvhc Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa cfh3 3jmp rvhc
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-fj7v-r99m-22gq
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-fj7v-r99m-22gq. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa fj7v r99m 22gq
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-jjj6-mw9f-p565
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-jjj6-mw9f-p565. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa jjj6 mw9f p565
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-pg7v-jwj7-p798
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-pg7v-jwj7-p798. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pg7v-jwj7-p798 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa pg7v jwj7 p798
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-phj9-mv4w-65pm
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-phj9-mv4w-65pm. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa phj9 mv4w 65pm
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-pwv6-vv43-88gr
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-pwv6-vv43-88gr. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pwv6-vv43-88gr Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa pwv6 vv43 88gr
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-r73j-pqj5-w3x7
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-r73j-pqj5-w3x7. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-r73j-pqj5-w3x7 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa r73j pqj5 w3x7
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-vjc4-5qp5-m44j
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-vjc4-5qp5-m44j. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa vjc4 5qp5 m44j
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-whj4-6x5x-4v2j
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-whj4-6x5x-4v2j. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-whj4-6x5x-4v2j Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa whj4 6x5x 4v2j
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-wjx4-4jcj-g98j
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-wjx4-4jcj-g98j. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa wjx4 4jcj g98j
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: GHSA-xj96-63gp-2gmr
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-xj96-63gp-2gmr. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvGhsa xj96 63gp 2gmr
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-165
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-165. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-165 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 165
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-2249
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2249. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2249 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2249
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-2250
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2250. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2250 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2250
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-2252
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2252. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2252 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2252
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-2253
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2253. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2253 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2253
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-2256
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2256. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2256 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2256
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-2874
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2874. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2874 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2874
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-3451
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3451. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3451 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 3451
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-3452
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3452. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3452 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 3452
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-3453
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3453. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3453 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 3453
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.0.0: PYSEC-2026-3454
OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3454. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3454 Fix: upgrade `pillow` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 3454
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency protobuf 6.33.1: GHSA-7gcm-g887-7qv7
OSV.dev reports `protobuf` at version `6.33.1` (resolved in `uv.lock`) is affected by GHSA-7gcm-g887-7qv7. Note: `protobuf` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-7gcm-g…
uv.lock ScaOsvGhsa 7gcm g887 7qv7
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency protobuf 6.33.1: PYSEC-2026-1805
OSV.dev reports `protobuf` at version `6.33.1` (resolved in `uv.lock`) is affected by PYSEC-2026-1805. Note: `protobuf` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1805…
uv.lock ScaOsvPysec 2026 1805
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyarrow 22.0.0: GHSA-rgxp-2hwp-jwgg
OSV.dev reports `pyarrow` at version `22.0.0` (resolved in `uv.lock`) is affected by GHSA-rgxp-2hwp-jwgg. Note: `pyarrow` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-rgxp-2hw…
uv.lock ScaOsvGhsa rgxp 2hwp jwgg
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyarrow 22.0.0: PYSEC-2026-113
OSV.dev reports `pyarrow` at version `22.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-113. Note: `pyarrow` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-113 Fix…
uv.lock ScaOsvPysec 2026 113
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-63vm-454h-vhhq. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-63vm-454h-v…
uv.lock ScaOsvGhsa 63vm 454h vhhq
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-8ppf-4f7h-5ppj. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-8ppf-4f7h-5…
uv.lock ScaOsvGhsa 8ppf 4f7h 5ppj
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-hm4w-wwcw-mr6r. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hm4w-wwcw-m…
uv.lock ScaOsvGhsa hm4w wwcw mr6r
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-jr27-m4p2-rc6r. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jr27-m4p2-r…
uv.lock ScaOsvGhsa jr27 m4p2 rc6r
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-1810. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1810 Fix:…
uv.lock ScaOsvPysec 2026 1810
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2263. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2263 Fix:…
uv.lock ScaOsvPysec 2026 2263
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3455. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3455 Fix:…
uv.lock ScaOsvPysec 2026 3455
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3456. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3456 Fix:…
uv.lock ScaOsvPysec 2026 3456
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457
OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3457. Note: `pyasn1` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3457 Fix:…
uv.lock ScaOsvPysec 2026 3457
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq
OSV.dev reports `pygments` at version `2.19.2` (resolved in `uv.lock`) is affected by GHSA-5239-wwwm-4pmq (aka CVE-2026-4539). Note: `pygments` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Pygments has Regular Expression Denial of Service (ReDoS) …
uv.lock ScaOsvGhsa 5239 wwwm 4pmq
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pytest 9.0.1: GHSA-6w46-j5rx-g56g
OSV.dev reports `pytest` at version `9.0.1` (resolved in `uv.lock`) is affected by GHSA-6w46-j5rx-g56g. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g Fix: upgrade `pytest` past the affected range per the advisory.
uv.lock ScaOsvGhsa 6w46 j5rx g56g
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency pytest 9.0.1: PYSEC-2026-1845
OSV.dev reports `pytest` at version `9.0.1` (resolved in `uv.lock`) is affected by PYSEC-2026-1845. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1845 Fix: upgrade `pytest` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 1845
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2
OSV.dev reports `requests` at version `2.32.5` (resolved in `uv.lock`) is affected by GHSA-gc5v-m9x4-r6x2. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2 Fix: upgrade `requests` past the affected range per the advisory.
uv.lock ScaOsvGhsa gc5v m9x4 r6x2
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency requests 2.32.5: PYSEC-2026-2275
OSV.dev reports `requests` at version `2.32.5` (resolved in `uv.lock`) is affected by PYSEC-2026-2275. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2275 Fix: upgrade `requests` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2275
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c
OSV.dev reports `setuptools` at version `80.9.0` (resolved in `uv.lock`) is affected by GHSA-h35f-9h28-mq5c. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-h35f-9h28-mq5c Fix: upgrade `setuptools` past the affected range per the advisory.
uv.lock ScaOsvGhsa h35f 9h28 mq5c
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447
OSV.dev reports `setuptools` at version `80.9.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3447. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-3447 Fix: upgrade `setuptools` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 3447
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency torch 2.9.0: GHSA-qfhq-4f3w-5fph
OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by GHSA-qfhq-4f3w-5fph. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qfhq-4f3w-5fph Fix: upgrade `torch` past the affected range per the advisory.
uv.lock ScaOsvGhsa qfhq 4f3w 5fph
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency torch 2.9.0: GHSA-rrmf-rvhw-rf47
OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by GHSA-rrmf-rvhw-rf47. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47 Fix: upgrade `torch` past the affected range per the advisory.
uv.lock ScaOsvGhsa rrmf rvhw rf47
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency torch 2.9.0: GHSA-vgrw-7cvw-pwgx
OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by GHSA-vgrw-7cvw-pwgx. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-vgrw-7cvw-pwgx Fix: upgrade `torch` past the affected range per the advisory.
uv.lock ScaOsvGhsa vgrw 7cvw pwgx
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency torch 2.9.0: PYSEC-2026-139
OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by PYSEC-2026-139. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-139 Fix: upgrade `torch` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 139
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency torch 2.9.0: PYSEC-2026-2286
OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2286. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2286 Fix: upgrade `torch` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2286
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-37mw-44qp-f5jm
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-37mw-44qp-f5jm (aka CVE-2025-3933). Transformers is vulnerable to ReDoS attack through its DonutProcessor class Aliases: CVE-2025-3933, PYSEC-2026-1977 Advisory: https://osv.de…
examples/bentoml/requirements.txt ScaOsvGhsa 37mw 44qp f5jm
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-4w7r-h757-3r74
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-4w7r-h757-3r74 (aka CVE-2025-6921). Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer Aliases: CVE-2025-6921…
examples/bentoml/requirements.txt ScaOsvGhsa 4w7r h757 3r74
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-59p9-h35m-wg4g
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-59p9-h35m-wg4g. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-59p9-h35m-wg4g Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa 59p9 h35m wg4g
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-6rvg-6v2m-4j46
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-6rvg-6v2m-4j46. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6rvg-6v2m-4j46 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa 6rvg 6v2m 4j46
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-9356-575x-2w9m
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-9356-575x-2w9m. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9356-575x-2w9m Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa 9356 575x 2w9m
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-fpwr-67px-3qhx
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-fpwr-67px-3qhx. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-fpwr-67px-3qhx Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa fpwr 67px 3qhx
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-hxxf-235m-72v3
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-hxxf-235m-72v3. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hxxf-235m-72v3 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa hxxf 235m 72v3
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-jjph-296x-mrcr
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-jjph-296x-mrcr. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jjph-296x-mrcr Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa jjph 296x mrcr
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-phhr-52qp-3mj4
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-phhr-52qp-3mj4. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-phhr-52qp-3mj4 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa phhr 52qp 3mj4
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-q2wp-rjmx-x6x9
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-q2wp-rjmx-x6x9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-q2wp-rjmx-x6x9 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa q2wp rjmx x6x9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-qq3j-4f4f-9583
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-qq3j-4f4f-9583. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qq3j-4f4f-9583 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa qq3j 4f4f 9583
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-qxrp-vhvm-j765
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-qxrp-vhvm-j765. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qxrp-vhvm-j765 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa qxrp vhvm j765
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-rcv9-qm8p-9p6j
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-rcv9-qm8p-9p6j. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-rcv9-qm8p-9p6j Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa rcv9 qm8p 9p6j
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: GHSA-wrfc-pvp9-mr9g
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-wrfc-pvp9-mr9g. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-wrfc-pvp9-mr9g Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvGhsa wrfc pvp9 mr9g
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2024-227
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2024-227. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2024-227 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2024 227
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2024-228
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2024-228. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2024-228 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2024 228
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2024-229
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2024-229. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2024-229 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2024 229
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-211
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-211. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-211 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 211
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-212
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-212. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-212 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 212
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-213
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-213. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-213 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 213
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-214
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-214. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-214 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 214
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-215
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-215. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-215 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 215
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-216
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-216. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-216 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 216
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2025-40
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-40. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2025-40 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2025 40
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1981
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1981. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1981 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1981
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1982
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1982. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1982 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1982
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1983
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1983. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1983 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1983
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1984
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1984. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1984 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1984
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1985
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1985. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1985 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1985
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1986
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1986. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1986 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1986
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1987
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1987. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1987 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1987
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency transformers 4.38.2: PYSEC-2026-1988
OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1988. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1988 Fix: upgrade `transformers` past the affected range per the advisory.
examples/bentoml/requirements.txt ScaOsvPysec 2026 1988
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency urllib3 2.5.0: GHSA-gm62-xv2j-4w53
OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-gm62-xv2j-4w53. Note: `urllib3` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-gm62-xv2j…
uv.lock ScaOsvGhsa gm62 xv2j 4w53
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency urllib3 2.5.0: GHSA-qccp-gfcp-xxvc
OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-qccp-gfcp-xxvc. Note: `urllib3` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qccp-gfcp…
uv.lock ScaOsvGhsa qccp gfcp xxvc
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency urllib3 2.5.0: PYSEC-2026-141
OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by PYSEC-2026-141. Note: `urllib3` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-141 Fix:…
uv.lock ScaOsvPysec 2026 141
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency urllib3 2.5.0: PYSEC-2026-1998
OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by PYSEC-2026-1998. Note: `urllib3` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-1998 Fi…
uv.lock ScaOsvPysec 2026 1998
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency virtualenv 20.35.4: GHSA-597g-3phw-6986
OSV.dev reports `virtualenv` at version `20.35.4` (resolved in `uv.lock`) is affected by GHSA-597g-3phw-6986. Note: `virtualenv` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-5…
uv.lock ScaOsvGhsa 597g 3phw 6986
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency virtualenv 20.35.4: PYSEC-2026-2009
OSV.dev reports `virtualenv` at version `20.35.4` (resolved in `uv.lock`) is affected by PYSEC-2026-2009. Note: `virtualenv` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026…
uv.lock ScaOsvPysec 2026 2009
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency werkzeug 3.1.3: GHSA-29vq-49wr-vm6x
OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by GHSA-29vq-49wr-vm6x (aka CVE-2026-27199). Note: `werkzeug` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Werkzeug safe_join() allows Windows special device names …
uv.lock ScaOsvGhsa 29vq 49wr vm6x
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency werkzeug 3.1.3: GHSA-87hc-h4r5-73f7
OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by GHSA-87hc-h4r5-73f7. Note: `werkzeug` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-87hc-h4…
uv.lock ScaOsvGhsa 87hc h4r5 73f7
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency werkzeug 3.1.3: GHSA-hgf8-39gv-g3f2
OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by GHSA-hgf8-39gv-g3f2. Note: `werkzeug` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hgf8-39…
uv.lock ScaOsvGhsa hgf8 39gv g3f2
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2044
OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2044. Note: `werkzeug` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2044 …
uv.lock ScaOsvPysec 2026 2044
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2046
OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2046. Note: `werkzeug` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2046 …
uv.lock ScaOsvPysec 2026 2046
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency wheel 0.45.1: GHSA-8rrh-rw8j-w5fx
OSV.dev reports `wheel` at version `0.45.1` (resolved in `uv.lock`) is affected by GHSA-8rrh-rw8j-w5fx. Note: `wheel` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-8rrh-rw8j-w5…
uv.lock ScaOsvGhsa 8rrh rw8j w5fx
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency wheel 0.45.1: PYSEC-2026-2047
OSV.dev reports `wheel` at version `0.45.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2047. Note: `wheel` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2047 Fix: …
uv.lock ScaOsvPysec 2026 2047
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency xgrammar 0.1.27: GHSA-7rgv-gqhr-fxg3
OSV.dev reports `xgrammar` at version `0.1.27` (resolved in `uv.lock`) is affected by GHSA-7rgv-gqhr-fxg3. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-7rgv-gqhr-fxg3 Fix: upgrade `xgrammar` past the affected range per the advisory.
uv.lock ScaOsvGhsa 7rgv gqhr fxg3
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency xgrammar 0.1.27: PYSEC-2026-2322
OSV.dev reports `xgrammar` at version `0.1.27` (resolved in `uv.lock`) is affected by PYSEC-2026-2322. No summary published yet. Advisory: https://osv.dev/vulnerability/PYSEC-2026-2322 Fix: upgrade `xgrammar` past the affected range per the advisory.
uv.lock ScaOsvPysec 2026 2322
low System graph security Trivy conf 1.00 CVE-2025-3000: torch 2.9.0 — uv.lock
A vulnerability classified as critical has been found in PyTorch 2.6.0 ... A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exp…
VulnCve 2025 3000
low System graph security Trivy conf 1.00 CVE-2025-3001: torch 2.9.0 — uv.lock
A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ... A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit…
VulnCve 2025 3001
low System graph security Trivy conf 1.00 CVE-2025-3777: transformers 4.38.2 — examples/bentoml/requirements.txt
transformers: Improper Input Validation in huggingface/transformers Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which …
VulnCve 2025 3777
low System graph security Trivy conf 1.00 CVE-2025-69224: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Request smuggling via non-ASCII characters in HTTP parser AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure …
VulnCve 2025 69224
low System graph security Trivy conf 1.00 CVE-2025-69225: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no kno…
VulnCve 2025 69225
low System graph security Trivy conf 1.00 CVE-2025-69226: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Information disclosure of path components via static file path normalization AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normal…
VulnCve 2025 69226
low System graph security Trivy conf 1.00 CVE-2025-69230: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Denial of Service via specially crafted invalid cookies AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an applicati…
VulnCve 2025 69230
low System graph security Trivy conf 1.00 CVE-2026-34513: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched i…
VulnCve 2026 34513
low System graph security Trivy conf 1.00 CVE-2026-34514: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar explo…
VulnCve 2026 34514
low System graph security Trivy conf 1.00 CVE-2026-34517: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Denial of Service via large multipart form fields AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has bee…
VulnCve 2026 34517
low System graph security Trivy conf 1.00 CVE-2026-34518: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization hea…
VulnCve 2026 34518
low System graph security Trivy conf 1.00 CVE-2026-34519: aiohttp 3.13.2 — uv.lock
aiohttp: aiohttp: Header injection vulnerability via reason parameter AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar explo…
VulnCve 2026 34519
low System graph security Trivy conf 1.00 CVE-2026-34520: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. …
VulnCve 2026 34520
low System graph security Trivy conf 1.00 CVE-2026-4539: pygments 2.19.2 — uv.lock
pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expr…
VulnCve 2026 4539
low System graph security Trivy conf 1.00 CVE-2026-50269: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: CRLF injection in multipart headers AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the u…
VulnCve 2026 50269
low System graph security Trivy conf 1.00 CVE-2026-54275: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the sam…
VulnCve 2026 54275
low System graph security Trivy conf 1.00 CVE-2026-54279: aiohttp 3.13.2 — uv.lock
aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their hos…
VulnCve 2026 54279
low System graph security Trivy conf 1.00 CVE-2026-54280: aiohttp 3.13.2 — uv.lock
AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ... AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open f…
VulnCve 2026 54280
low System graph quality Debug conf 1.00 Debug logging residue appears in source files
Found 27 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup.
CleanupRepo hardeningGenerated repo pattern
low System graph dependencies dependencies conf 0.90 Dependency accelerate is a major version behind
`accelerate` is pinned at `0.27.2` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `1.14.0` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `accel…
examples/bentoml/requirements.txt FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency outlines is a major version behind
`outlines` is pinned at `0.0.37` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `1.3.2` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `outlines…
examples/bentoml/requirements.txt FreshnessOutdated
low System graph dependencies dependencies conf 0.90 Dependency transformers is a major version behind
`transformers` is pinned at `4.38.2` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `5.14.1` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `tra…
examples/bentoml/requirements.txt FreshnessOutdated
low System graph quality Integrity conf 1.00 Near-duplicate function bodies in 11 places
Functions with the same first-5-line body hash: src/outlines/models/openai.py:generate_batch, src/outlines/models/openai.py:generate_batch, src/outlines/models/tgi.py:generate_batch, src/outlines/models/tgi.py:generate_batch This is *the* AI-coder failure mode (4× more duplication in vibe-coded re…
duplicatesduplication
low System graph quality Integrity conf 1.00 Near-duplicate function bodies in 2 places
Functions with the same first-5-line body hash: src/outlines/caching.py:wrapper, src/outlines/caching.py:wrapper This is *the* AI-coder failure mode (4× more duplication in vibe-coded repos — see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate.
duplicatesduplication
low System graph quality Integrity conf 1.00 Near-duplicate function bodies in 3 places
Functions with the same first-5-line body hash: src/outlines/generator.py:batch, src/outlines/generator.py:batch, src/outlines/generator.py:batch This is *the* AI-coder failure mode (4× more duplication in vibe-coded repos — see https://jw.hn/ai-code-hygiene). Consolidate or document why they're s…
duplicatesduplication
low System graph software Dead code conf 1.00 Possibly dead Python function: ask_an_expert
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
examples/meta_prompting.py:66
low System graph software Dead code conf 1.00 Possibly dead Python function: ask_an_expert_simple
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
examples/meta_prompting.py:105
low System graph software Dead code conf 1.00 Possibly dead Python function: decorator
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
src/outlines/caching.py:108
low System graph software Dead code conf 1.00 Possibly dead Python function: fill_in_the_blanks
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
examples/meta_prompting.py:45
low System graph software Dead code conf 1.00 Possibly dead Python function: load_models
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
examples/beam-cloud/app.py:11
low System graph software Dead code conf 1.00 Possibly dead Python function: split_into_steps
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
examples/meta_prompting.py:24

Showing first 300 of 303. Refine filters or use the findings page for deep search.

For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/f8ad4bb0-828f-4472-b03b-a63e56bb3308/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/f8ad4bb0-828f-4472-b03b-a63e56bb3308/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.