{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-a017476ef4558071", "name": "Possibly dead Python function: split_into_steps", "shortDescription": {"text": "Possibly dead Python function: split_into_steps"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97a166bdedab4a4d", "name": "Possibly dead Python function: fill_in_the_blanks", "shortDescription": {"text": "Possibly dead Python function: fill_in_the_blanks"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb0c07736512004f", "name": "Possibly dead Python function: ask_an_expert", "shortDescription": {"text": "Possibly dead Python function: ask_an_expert"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0204f9ffe1f87c1e", "name": "Possibly dead Python function: ask_an_expert_simple", "shortDescription": {"text": "Possibly dead Python function: ask_an_expert_simple"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-756c61dddbb62eef", "name": "Possibly dead Python function: load_models", "shortDescription": {"text": "Possibly dead Python function: load_models"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99853f0922ec56af", "name": "Possibly dead Python function: decorator", "shortDescription": {"text": "Possibly dead Python function: decorator"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca71927fbdaee9e5", "name": "Possibly dead Python function: wrapper", "shortDescription": {"text": "Possibly dead Python function: wrapper"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2dadf8d9881e71f6", "name": "var in href \u2014 docs/overrides/home.html:130", "shortDescription": {"text": "var in href \u2014 docs/overrides/home.html:130"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ded532a6d2eecd7", "name": "eval detected \u2014 examples/math_generate_code.py:36", "shortDescription": {"text": "eval detected \u2014 examples/math_generate_code.py:36"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6e1ed806eba9ad1", "name": "CVE-2024-11392: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2024-11392: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability\n\nHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-sup\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.48.0\nSeverity: HIGH\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30ef5b34f7078c6d", "name": "CVE-2024-11393: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2024-11393: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability\n\nHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplie\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.48.0\nSeverity: HIGH\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c4b20bea2d2fa3d", "name": "CVE-2024-11394: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2024-11394: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability\n\nHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied dat\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.48.0\nSeverity: HIGH\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dd7ebc1fd24e5e2d", "name": "CVE-2026-4372: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2026-4372: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "HuggingFace transformers vulnerable to remote code execution\n\nA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's re\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 5.3.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b8f3b6956ab9d40", "name": "CVE-2026-5241: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2026-5241: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting\n\nA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `Lig\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 5.5.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0280a07cee802dca", "name": "CVE-2024-12720: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2024-12720: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "Transformers Regular Expression Denial of Service (ReDoS) vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. The issue stems from the regex exhibiting exponential time complexity under certain conditions, leading to excessive backtracking. This can result in significantly high CPU usage and potential applicatio\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.48.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.48.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c98c4d2f4400df0d", "name": "CVE-2025-1194: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-1194: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "Transformers Regular Expression Denial of Service (ReDoS) vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially crafted inputs. The issue stems from a regex exhibiting exponential complexity under certain conditions, leading to excessive backtracking. This can result in high CPU usage and pote\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.50.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.50.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-196d23f2e4e632ee", "name": "CVE-2025-2099: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-2099: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and \n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.50.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.50.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5507af014b9896c", "name": "CVE-2025-3263: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-3263: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is resolved in version 4.51.0. The vulnerability arises from the use of a regular expression pattern `config\\.(.*)\\.json` that can be exploited to cause excessive CPU consumption through crafted input strings, leading to catas\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.51.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.51.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f56f81e907cb4c7c", "name": "CVE-2025-3264: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-3264: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regular expression pattern `\\s*try\\s*:.*?except.*?:` used to filter out try/except blocks from Python code, which can be exploited to cause excessive CPU consumption through crafted input strings due to c\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.51.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.51.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d41a4087256b958", "name": "CVE-2025-3933: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-3933: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern `<s_(.*?)>` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption,\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.52.1\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.52.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-640a4338ee2af8cc", "name": "CVE-2025-5197: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-5197: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Transformers ReDoS Vulnerability\n\nA Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. The vulnerability affects versions up to 4.51.3 and is fixed in vers\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b691a46fb6c886d", "name": "CVE-2025-6051: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-6051: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This vulnerability impac\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4a3f75952f444a7c", "name": "CVE-2025-6638: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-6638: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nA Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11b14a6b879e7bf3", "name": "CVE-2025-6921: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-6921: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers\n\nThe huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in the include_in_weight_decay and exclude_from_weight_decay lists. Malicious regular expressions can cause catastrophic backtracking during the re.search call, leading to 100% CPU utilization and a denial of service. This is\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.53.0\nSeverity: MEDIUM\nFix: Upgrade transformers to 4.53.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28d3d4f1b7feb174", "name": "CVE-2026-1839: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2026-1839: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file\n\nA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vul\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 5.0.0rc3\nSeverity: MEDIUM\nFix: Upgrade transformers to 5.0.0rc3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91a998ea7f4caa58", "name": "CVE-2025-3777: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt", "shortDescription": {"text": "CVE-2025-3777: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "fullDescription": {"text": "transformers: Improper Input Validation in huggingface/transformers\n\nHugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1\n\nPackage: transformers\nInstalled: 4.38.2\nFixed in: 4.52.1\nSeverity: LOW\nFix: Upgrade transformers to 4.52.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01f0b7c38ecdb71f", "name": "CVE-2025-69223: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69223: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: HIGH\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-adc21fc6f1c81765", "name": "CVE-2025-69227: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69227: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are enabled (-O or PYTHONOPTIMIZE=1), and the application includes a handler that uses the Request.post() method, then an attacker may be able to execute a DoS attack with a specially crafted message. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91d95123c0b5f441", "name": "CVE-2025-69228: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69228: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e500b4d6f200e36", "name": "CVE-2025-69229: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69229: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would \n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7d05e8129acab9ee", "name": "CVE-2026-22815: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-22815: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d036f5215d9e0da7", "name": "CVE-2026-34515: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34515: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-929815d8bf9592b6", "name": "CVE-2026-34516: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34516: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a55eb5eb79baaf4a", "name": "CVE-2026-34525: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34525: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Security bypass via multiple Host headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bbe36dce6f89c610", "name": "CVE-2026-34993: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34993: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0779ad2938fd4cb", "name": "CVE-2026-47265: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-47265: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee54dfb8a3084055", "name": "CVE-2026-54273: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54273: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed5a22bbf7d3a361", "name": "CVE-2026-54274: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54274: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba1b69aa2916260b", "name": "CVE-2026-54276: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54276: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36bc5c7f59ba3066", "name": "CVE-2026-54277: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54277: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32cfa23890fda16e", "name": "CVE-2026-54278: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54278: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-201524e473cd2d80", "name": "CVE-2025-69224: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69224: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling via non-ASCII characters in HTTP parser\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-270aaac517e6a692", "name": "CVE-2025-69225: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69225: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66be1bfc0c008807", "name": "CVE-2025-69226: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69226: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure of path components via static file path normalization\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cdfcb39e89dc313", "name": "CVE-2025-69230: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69230: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via specially crafted invalid cookies\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.3\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d01e31edad3fb7a", "name": "CVE-2026-34513: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34513: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a83079cd9a6bfcfb", "name": "CVE-2026-34514: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34514: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bbb1fd4937a36e88", "name": "CVE-2026-34517: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34517: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via large multipart form fields\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-550bf94fdacafca1", "name": "CVE-2026-34518: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34518: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57a623b71bc84bed", "name": "CVE-2026-34519: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34519: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Header injection vulnerability via reason parameter\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cb9c5b798fbebdf", "name": "CVE-2026-34520: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34520: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edee7ab35ea6a666", "name": "CVE-2026-50269: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-50269: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: CRLF injection in multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerabi\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.0\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94f5fda98e9896a2", "name": "CVE-2026-54275: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54275: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d6aa05e64963f13", "name": "CVE-2026-54279: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54279: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99c4c895f15b8a32", "name": "CVE-2026-54280: aiohttp 3.13.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54280: aiohttp 3.13.2 \u2014 uv.lock"}, "fullDescription": {"text": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.2\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0aa9c400e1b6984", "name": "CVE-2025-69872: diskcache 5.6.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-69872: diskcache 5.6.3 \u2014 uv.lock"}, "fullDescription": {"text": "python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization\n\nDiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.\n\nPackage: diskcache\nInstalled: 5.6.3\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8281760769efa259", "name": "CVE-2025-68146: filelock 3.20.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-68146: filelock 3.20.0 \u2014 uv.lock"}, "fullDescription": {"text": "filelock: filelock: Time-of-Check-Time-of-Use (TOCTOU) race condition and symlink attack allows arbitrary file corruption or truncation\n\nfilelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock checks if a file exists before opening it with O_TRUNC. An attacker can create a symlink pointing to a victim file in the time gap between the check and open, causing os.open() to follow\n\nPackage: filelock\nInstalled: 3.20.0\nFixed in: 3.20.1\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6881f0d9e8fde8bc", "name": "CVE-2026-22701: filelock 3.20.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-22701: filelock 3.20.0 \u2014 uv.lock"}, "fullDescription": {"text": "filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock\n\nfilelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission c\n\nPackage: filelock\nInstalled: 3.20.0\nFixed in: 3.20.3\nSeverity: MEDIUM\nFix: Upgrade filelock to 3.20.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-206a6aeb11dedddf", "name": "CVE-2026-45409: idna 3.11 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.11 \u2014 uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.11\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7377f6edcfb94cd9", "name": "CVE-2026-0897: keras 3.12.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-0897: keras 3.12.0 \u2014 uv.lock"}, "fullDescription": {"text": "Keras: Keras: Denial of Service via crafted HDF5 weight loading file\n\nAllocation of Resources Without Limits or Throttling in the HDF5 weight loading component\u00a0in Google\u00a0Keras\u00a03.0.0 through 3.13.0\u00a0on all platforms\u00a0allows a remote attacker\u00a0to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter\u00a0via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.\n\nPackage: keras\nInstalled: 3.12.0\nFixed in: 3.12.1, 3.13.2\nSeverity: HIGH\nFix: Upgrade keras to 3.12.1, 3.13.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70db4b65fcbd9060", "name": "CVE-2026-1462: keras 3.12.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-1462: keras 3.12.0 \u2014 uv.lock"}, "fullDescription": {"text": "keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode\n\nA vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file path\n\nPackage: keras\nInstalled: 3.12.0\nFixed in: 3.13.2\nSeverity: HIGH\nFix: Upgrade keras to 3.13.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-947e18581208fd5b", "name": "CVE-2026-1669: keras 3.12.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-1669: keras 3.12.0 \u2014 uv.lock"}, "fullDescription": {"text": "keras: Keras: Information disclosure via arbitrary file read in model loading mechanism\n\nArbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.\n\nPackage: keras\nInstalled: 3.12.0\nFixed in: 3.13.2, 3.12.1\nSeverity: HIGH\nFix: Upgrade keras to 3.13.2, 3.12.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be7e775aaa4eb632", "name": "GHSA-6v7p-g79w-8964: msgpack 1.1.2 \u2014 uv.lock", "shortDescription": {"text": "GHSA-6v7p-g79w-8964: msgpack 1.1.2 \u2014 uv.lock"}, "fullDescription": {"text": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error\n\n### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct da\n\nPackage: msgpack\nInstalled: 1.1.2\nFixed in: 1.2.1\nSeverity: HIGH\nFix: Upgrade msgpack to 1.2.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c965c7c648447d6", "name": "CVE-2026-25990: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-25990: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image\n\nPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.1.1\nSeverity: HIGH\nFix: Upgrade pillow to 12.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c196fd55a04f419d", "name": "CVE-2026-40192: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-40192: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0928fd92486590de", "name": "CVE-2026-42311: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42311: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1fcbf3b09a9ca431", "name": "CVE-2026-54058: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54058: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4cce00c99ee16f6", "name": "CVE-2026-54059: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54059: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0392549ef1a953b5", "name": "CVE-2026-54060: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54060: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d98f7c7c31d4e37", "name": "CVE-2026-55379: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55379: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2741239de2fb938", "name": "CVE-2026-55380: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55380: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9cf4d8884e4632da", "name": "CVE-2026-59197: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59197: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-67d671343dc8c196", "name": "CVE-2026-59199: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59199: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81b80a980c1cae63", "name": "CVE-2026-59200: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59200: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ebf31894255f500", "name": "CVE-2026-59204: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59204: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4e1b552b1305a526", "name": "CVE-2026-59205: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59205: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a31f4a1decdc56c", "name": "CVE-2026-42308: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42308: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b08ea9c0a9ceae2d", "name": "CVE-2026-42309: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42309: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via specially crafted coordinate input\n\nPillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ad096488c39fdc1", "name": "CVE-2026-42310: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42310: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f3a82cb2e3eb519", "name": "CVE-2026-55798: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55798: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b33e6336231cd3ff", "name": "CVE-2026-59198: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59198: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0afd92c4d29ae48", "name": "CVE-2026-59203: pillow 12.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59203: pillow 12.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted EPS file\n\nPillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.0.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5568545505b9756", "name": "CVE-2026-0994: protobuf 6.33.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-0994: protobuf 6.33.1 \u2014 uv.lock"}, "fullDescription": {"text": "python: protobuf: Protobuf: Denial of Service due to recursion depth bypass\n\nA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.\n\nDue to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python\u2019s recursion stack and causing a RecursionError.\n\nPackage: protobuf\nInstalled: 6.33.1\nFixed in: 6.33.5, 5.29.6\nSeverity: HIGH\nFix: Upgrade protobuf to 6.33.5, 5.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8a68cdbf221d82b2", "name": "CVE-2026-25087: pyarrow 22.0.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-25087: pyarrow 22.0.0 \u2014 uv.lock"}, "fullDescription": {"text": "apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files\n\nUse After Free vulnerability in Apache Arrow C++.\n\nThis issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shar\n\nPackage: pyarrow\nInstalled: 22.0.0\nFixed in: 23.0.1\nSeverity: HIGH\nFix: Upgrade pyarrow to 23.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a66a46b30aafdf4e", "name": "CVE-2026-23490: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.2\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eaf386c6a405e5a9", "name": "CVE-2026-30922: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b16f1d147b41ab9", "name": "CVE-2026-59885: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f56dfa97d69c0517", "name": "CVE-2026-59886: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0da8a15114591082", "name": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.19.2\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b47aa9185ac1b713", "name": "CVE-2025-71176: pytest 9.0.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-71176: pytest 9.0.1 \u2014 uv.lock"}, "fullDescription": {"text": "pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling\n\npytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.\n\nPackage: pytest\nInstalled: 9.0.1\nFixed in: 9.0.3\nSeverity: MEDIUM\nFix: Upgrade pytest to 9.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0bc6a832539e0bf", "name": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.5\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f97e28c76c35d3d4", "name": "CVE-2026-59890: setuptools 80.9.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59890: setuptools 80.9.0 \u2014 uv.lock"}, "fullDescription": {"text": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.\n\nPackage: setuptools\nInstalled: 80.9.0\nFixed in: 83.0.0\nSeverity: MEDIUM\nFix: Upgrade setuptools to 83.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d54924d203c3ae9d", "name": "CVE-2025-2999: torch 2.9.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-2999: torch 2.9.0 \u2014 uv.lock"}, "fullDescription": {"text": "A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...\n\nA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.9.0\nFixed in: 2.9.1\nSeverity: MEDIUM\nFix: Upgrade torch to 2.9.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af2374746d25de68", "name": "CVE-2025-3000: torch 2.9.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-3000: torch 2.9.0 \u2014 uv.lock"}, "fullDescription": {"text": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...\n\nA vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.9.0\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade torch to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17dde6ce6efaad6b", "name": "CVE-2025-3001: torch 2.9.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-3001: torch 2.9.0 \u2014 uv.lock"}, "fullDescription": {"text": "A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ...\n\nA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.9.0\nFixed in: 2.10.0\nSeverity: LOW\nFix: Upgrade torch to 2.10.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ddb55eb11841979", "name": "CVE-2026-4372: transformers 4.57.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-4372: transformers 4.57.1 \u2014 uv.lock"}, "fullDescription": {"text": "HuggingFace transformers vulnerable to remote code execution\n\nA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's re\n\nPackage: transformers\nInstalled: 4.57.1\nFixed in: 5.3.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1a23dbbc424f0c72", "name": "CVE-2026-5241: transformers 4.57.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-5241: transformers 4.57.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting\n\nA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `Lig\n\nPackage: transformers\nInstalled: 4.57.1\nFixed in: 5.5.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b9bd2ec862f0e86", "name": "CVE-2026-1839: transformers 4.57.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-1839: transformers 4.57.1 \u2014 uv.lock"}, "fullDescription": {"text": "transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file\n\nA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vul\n\nPackage: transformers\nInstalled: 4.57.1\nFixed in: 5.0.0rc3\nSeverity: MEDIUM\nFix: Upgrade transformers to 5.0.0rc3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ce2e929f54e2a70", "name": "CVE-2025-66418: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b32d2265f744fa8b", "name": "CVE-2025-66471: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e01e826fca9ae59b", "name": "CVE-2026-21441: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-79d12b66c3169372", "name": "CVE-2026-44431: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ff150d8f9eed9fa", "name": "CVE-2026-22702: virtualenv 20.35.4 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-22702: virtualenv 20.35.4 \u2014 uv.lock"}, "fullDescription": {"text": "virtualenv: virtualenv: Local attacker can redirect file operations via TOCTOU race condition\n\nvirtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a race condition between directory existence checks and creation to redirect virtualenv's app_data and lock file operations to attacker-controlled locations. This issue has been patched in version 20.36.1.\n\nPackage: virtualenv\nInstalled: 20.35.4\nFixed in: 20.36.1\nSeverity: MEDIUM\nFix: Upgrade virtualenv to 20.36.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ee0c7ae87775871", "name": "CVE-2025-66221: werkzeug 3.1.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-66221: werkzeug 3.1.3 \u2014 uv.lock"}, "fullDescription": {"text": "Werkzeug: Werkzeug: Denial of service via Windows device names in path segments\n\nWerkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be\n\nPackage: werkzeug\nInstalled: 3.1.3\nFixed in: 3.1.4\nSeverity: MEDIUM\nFix: Upgrade werkzeug to 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0eb732a83b553b3d", "name": "CVE-2026-21860: werkzeug 3.1.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-21860: werkzeug 3.1.3 \u2014 uv.lock"}, "fullDescription": {"text": " Werkzeug safe_join() allows Windows special device names with compound extensions\n\nWerkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. This issue has been patched in version 3.1.5.\n\nPackage: werkzeug\nInstalled: 3.1.3\nFixed in: 3.1.5\nSeverity: MEDIUM\nFix: Upgrade werkzeug to 3.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-07d52e44376aa875", "name": "CVE-2026-27199: werkzeug 3.1.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-27199: werkzeug 3.1.3 \u2014 uv.lock"}, "fullDescription": {"text": " Werkzeug safe_join() allows Windows special device names\n\nWerkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported as GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact that safe_join accepts paths with multiple segments, such as example/NUL. The function send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is\n\nPackage: werkzeug\nInstalled: 3.1.3\nFixed in: 3.1.6\nSeverity: MEDIUM\nFix: Upgrade werkzeug to 3.1.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb8981ac7565d9fa", "name": "CVE-2026-24049: wheel 0.45.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-24049: wheel 0.45.1 \u2014 uv.lock"}, "fullDescription": {"text": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking\n\nwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of c\n\nPackage: wheel\nInstalled: 0.45.1\nFixed in: 0.46.2\nSeverity: HIGH\nFix: Upgrade wheel to 0.46.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ffb49f99e2501401", "name": "CVE-2026-25048: xgrammar 0.1.27 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-25048: xgrammar 0.1.27 \u2014 uv.lock"}, "fullDescription": {"text": "xgrammar: xgrammar: Denial of Service via multi-level nested syntax\n\nxgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.\n\nPackage: xgrammar\nInstalled: 0.1.27\nFixed in: 0.1.32\nSeverity: HIGH\nFix: Upgrade xgrammar to 0.1.32"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ed72a17da887dd6", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c6527446b73129cf", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 27 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b29c6102daa67e3", "name": "Commented-code block (6 lines) in tests/models/test_provider_exceptions.py:187", "shortDescription": {"text": "Commented-code block (6 lines) in tests/models/test_provider_exceptions.py:187"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0b103e666a9255fa", "name": "Network/subprocess call without timeout or try/except \u2014 examples/react.py:47", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 examples/react.py:47"}, "fullDescription": {"text": "`requests.get(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aadb3c6adec7e21c", "name": "Commented-code block (5 lines) in src/outlines/templates.py:332", "shortDescription": {"text": "Commented-code block (5 lines) in src/outlines/templates.py:332"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7239f3b39b14a545", "name": "Stub function `get_device` (body is just `pass`/`return`) \u2014 src/outlines/processors/tensor_adapters/numpy.py:35", "shortDescription": {"text": "Stub function `get_device` (body is just `pass`/`return`) \u2014 src/outlines/processors/tensor_adapters/numpy.py:35"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-182c43abfa3ff74b", "name": "Stub function `get_device` (body is just `pass`/`return`) \u2014 src/outlines/processors/tensor_adapters/mlx.py:45", "shortDescription": {"text": "Stub function `get_device` (body is just `pass`/`return`) \u2014 src/outlines/processors/tensor_adapters/mlx.py:45"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/outlines/generator.py:batch, src/outlines/generator.py:batch, src/outlines/generator.py:batch\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/outlines/caching.py:wrapper, src/outlines/caching.py:wrapper\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-380b7cb95b387b9c", "name": "Near-duplicate function bodies in 11 places", "shortDescription": {"text": "Near-duplicate function bodies in 11 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/outlines/models/openai.py:generate_batch, src/outlines/models/openai.py:generate_batch, src/outlines/models/tgi.py:generate_batch, src/outlines/models/tgi.py:generate_batch\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-454bb594c55998a9", "name": "Vulnerable dependency diskcache 5.6.3: GHSA-w8v5-vhqr-4h9v", "shortDescription": {"text": "Vulnerable dependency diskcache 5.6.3: GHSA-w8v5-vhqr-4h9v"}, "fullDescription": {"text": "OSV.dev reports `diskcache` at version `5.6.3` (resolved in `uv.lock`) is affected by GHSA-w8v5-vhqr-4h9v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w8v5-vhqr-4h9v\nFix: upgrade `diskcache` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62c4287e167b0d2d", "name": "Vulnerable dependency diskcache 5.6.3: PYSEC-2026-2447", "shortDescription": {"text": "Vulnerable dependency diskcache 5.6.3: PYSEC-2026-2447"}, "fullDescription": {"text": "OSV.dev reports `diskcache` at version `5.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2447.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2447\nFix: upgrade `diskcache` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2234d8706200df0", "name": "Vulnerable dependency pillow 12.0.0: GHSA-45hq-cxwh-f6vc", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-45hq-cxwh-f6vc"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-45hq-cxwh-f6vc (aka CVE-2026-55379).\n\nPillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` \u2014 bomb protection bypass via font loading\n\nAliases: BIT-pillow-2026-55379, CVE-2026-55379, PYSEC-2026-2255\nAdvisory: https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb77fb9871b23298", "name": "Vulnerable dependency pillow 12.0.0: GHSA-4x4j-2g7c-83w6", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-4x4j-2g7c-83w6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-4x4j-2g7c-83w6 (aka CVE-2026-55798).\n\nPillow: WindowsViewer.get_command() OS command injection via unescaped shell path\n\nAliases: BIT-pillow-2026-55798, CVE-2026-55798, PYSEC-2026-2257\nAdvisory: https://osv.dev/vulnerability/GHSA-4x4j-2g7c-83w6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-879f300e6812613f", "name": "Vulnerable dependency pillow 12.0.0: GHSA-5x94-69rx-g8h2", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-5x94-69rx-g8h2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-5x94-69rx-g8h2 (aka CVE-2026-54060).\n\nPillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`\n\nAliases: BIT-pillow-2026-54060, CVE-2026-54060, PYSEC-2026-2254\nAdvisory: https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c2bee2f22beac5e", "name": "Vulnerable dependency pillow 12.0.0: GHSA-5xmw-vc9v-4wf2", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-5xmw-vc9v-4wf2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-5xmw-vc9v-4wf2 (aka CVE-2026-42309).\n\nPillow has a heap buffer overflow with nested list coordinates\n\nAliases: BIT-pillow-2026-42309, CVE-2026-42309, PYSEC-2026-2251\nAdvisory: https://osv.dev/vulnerability/GHSA-5xmw-vc9v-4wf2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0435fea082da18b9", "name": "Vulnerable dependency pillow 12.0.0: GHSA-62p4-gmf7-7g93", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-62p4-gmf7-7g93"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-62p4-gmf7-7g93 (aka CVE-2026-54058).\n\nPillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)\n\nAliases: BIT-pillow-2026-54058, CVE-2026-54058\nAdvisory: https://osv.dev/vulnerability/GHSA-62p4-gmf7-7g93\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-724d6b29c2511ce7", "name": "Vulnerable dependency pillow 12.0.0: GHSA-6r8x-57c9-28j4", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-6r8x-57c9-28j4"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-6r8x-57c9-28j4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e1d9694a3f09bc34", "name": "Vulnerable dependency pillow 12.0.0: GHSA-8v84-f9pq-wr9x", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-8v84-f9pq-wr9x"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-8v84-f9pq-wr9x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-660cd5fe4c56ed91", "name": "Vulnerable dependency pillow 12.0.0: GHSA-9hw9-ch79-4vh6", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-9hw9-ch79-4vh6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-9hw9-ch79-4vh6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ad047b7af1d9dc5", "name": "Vulnerable dependency pillow 12.0.0: GHSA-cfh3-3jmp-rvhc", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-cfh3-3jmp-rvhc"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-cfh3-3jmp-rvhc.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cfh3-3jmp-rvhc\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-18e69d1d468f1e8a", "name": "Vulnerable dependency pillow 12.0.0: GHSA-fj7v-r99m-22gq", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-fj7v-r99m-22gq"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-fj7v-r99m-22gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e0823373d260e38", "name": "Vulnerable dependency pillow 12.0.0: GHSA-jjj6-mw9f-p565", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-jjj6-mw9f-p565"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-jjj6-mw9f-p565.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-713beded503cb483", "name": "Vulnerable dependency pillow 12.0.0: GHSA-pg7v-jwj7-p798", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-pg7v-jwj7-p798"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-pg7v-jwj7-p798.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pg7v-jwj7-p798\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ecc356499f7b4d49", "name": "Vulnerable dependency pillow 12.0.0: GHSA-phj9-mv4w-65pm", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-phj9-mv4w-65pm"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-phj9-mv4w-65pm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9bb9b826e9656bb5", "name": "Vulnerable dependency pillow 12.0.0: GHSA-pwv6-vv43-88gr", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-pwv6-vv43-88gr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-pwv6-vv43-88gr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pwv6-vv43-88gr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30f99617ddce4271", "name": "Vulnerable dependency pillow 12.0.0: GHSA-r73j-pqj5-w3x7", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-r73j-pqj5-w3x7"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-r73j-pqj5-w3x7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r73j-pqj5-w3x7\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58d89c4cb8b58e24", "name": "Vulnerable dependency pillow 12.0.0: GHSA-vjc4-5qp5-m44j", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-vjc4-5qp5-m44j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-vjc4-5qp5-m44j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-449b54de0838e577", "name": "Vulnerable dependency pillow 12.0.0: GHSA-whj4-6x5x-4v2j", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-whj4-6x5x-4v2j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-whj4-6x5x-4v2j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-whj4-6x5x-4v2j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f6668a6db53da45", "name": "Vulnerable dependency pillow 12.0.0: GHSA-wjx4-4jcj-g98j", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-wjx4-4jcj-g98j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-wjx4-4jcj-g98j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-681c056e31cdd578", "name": "Vulnerable dependency pillow 12.0.0: GHSA-xj96-63gp-2gmr", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-xj96-63gp-2gmr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by GHSA-xj96-63gp-2gmr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-caabfcd306e461cc", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-165", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-165"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-165.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-165\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b47d979db8a7de5", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2249", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2249"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2249.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2249\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e1d439870761e64", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2250", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2250"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2250.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2250\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2bb25340b5bafbe0", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2252", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2252"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2252.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2252\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-220ff3525bb6e774", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2253", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2253"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2253.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2253\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76997a6562028410", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2256", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2256"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2256.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2256\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc0edbaf1effcfc3", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2874", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2874"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2874.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2874\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-724cb91666a357a2", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3451", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3451"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3451.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3451\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7413a251bee65b6", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3452", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3452"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3452.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3452\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-08a775c3c1cb84c8", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3453", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3453"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3453.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3453\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0f9858210bf81be", "name": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3454", "shortDescription": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3454"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3454.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3454\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86e90a44c46470c6", "name": "Vulnerable dependency pytest 9.0.1: GHSA-6w46-j5rx-g56g", "shortDescription": {"text": "Vulnerable dependency pytest 9.0.1: GHSA-6w46-j5rx-g56g"}, "fullDescription": {"text": "OSV.dev reports `pytest` at version `9.0.1` (resolved in `uv.lock`) is affected by GHSA-6w46-j5rx-g56g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g\nFix: upgrade `pytest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-66b76c887f6fe91f", "name": "Vulnerable dependency pytest 9.0.1: PYSEC-2026-1845", "shortDescription": {"text": "Vulnerable dependency pytest 9.0.1: PYSEC-2026-1845"}, "fullDescription": {"text": "OSV.dev reports `pytest` at version `9.0.1` (resolved in `uv.lock`) is affected by PYSEC-2026-1845.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1845\nFix: upgrade `pytest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8957f21465289c5d", "name": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.5` (resolved in `uv.lock`) is affected by GHSA-gc5v-m9x4-r6x2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-be4852e49573b162", "name": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275", "shortDescription": {"text": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.5` (resolved in `uv.lock`) is affected by PYSEC-2026-2275.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2275\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4fbe3d554af2f9fd", "name": "Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c", "shortDescription": {"text": "Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `80.9.0` (resolved in `uv.lock`) is affected by GHSA-h35f-9h28-mq5c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h35f-9h28-mq5c\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a00f58b07f3bd972", "name": "Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447", "shortDescription": {"text": "Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `80.9.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3447.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3447\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6e29b64e3a3e2d57", "name": "Vulnerable dependency torch 2.9.0: GHSA-qfhq-4f3w-5fph", "shortDescription": {"text": "Vulnerable dependency torch 2.9.0: GHSA-qfhq-4f3w-5fph"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by GHSA-qfhq-4f3w-5fph.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qfhq-4f3w-5fph\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-955ab8685f1453bc", "name": "Vulnerable dependency torch 2.9.0: GHSA-rrmf-rvhw-rf47", "shortDescription": {"text": "Vulnerable dependency torch 2.9.0: GHSA-rrmf-rvhw-rf47"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by GHSA-rrmf-rvhw-rf47.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-39e93bc03b60b645", "name": "Vulnerable dependency torch 2.9.0: GHSA-vgrw-7cvw-pwgx", "shortDescription": {"text": "Vulnerable dependency torch 2.9.0: GHSA-vgrw-7cvw-pwgx"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by GHSA-vgrw-7cvw-pwgx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vgrw-7cvw-pwgx\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-33df912565fbd4d3", "name": "Vulnerable dependency torch 2.9.0: PYSEC-2026-139", "shortDescription": {"text": "Vulnerable dependency torch 2.9.0: PYSEC-2026-139"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by PYSEC-2026-139.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-139\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-65095b6697e0e22f", "name": "Vulnerable dependency torch 2.9.0: PYSEC-2026-2286", "shortDescription": {"text": "Vulnerable dependency torch 2.9.0: PYSEC-2026-2286"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2286.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2286\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f87a9cfc89873592", "name": "Vulnerable dependency transformers 4.57.1: GHSA-29pf-2h5f-8g72", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.1: GHSA-29pf-2h5f-8g72"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by GHSA-29pf-2h5f-8g72 (aka CVE-2026-4372).\n\nHuggingFace transformers vulnerable to remote code execution\n\nAliases: CVE-2026-4372, GHSA-29pf-2h5f-8g72, PYSEC-2026-2289\nAdvisory: https://osv.dev/vulnerability/GHSA-29pf-2h5f-8g72\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6dc3733717193612", "name": "Vulnerable dependency transformers 4.57.1: GHSA-69w3-r845-3855", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.1: GHSA-69w3-r845-3855"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by GHSA-69w3-r845-3855 (aka CVE-2026-1839).\n\nHuggingFace Transformers allows for arbitrary code execution in the `Trainer` class\n\nAliases: CVE-2026-1839, GHSA-69w3-r845-3855, PYSEC-2026-2288\nAdvisory: https://osv.dev/vulnerability/GHSA-69w3-r845-3855\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c63e23ee4c3ea4f", "name": "Vulnerable dependency transformers 4.57.1: GHSA-fgcw-684q-jj6r", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.1: GHSA-fgcw-684q-jj6r"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by GHSA-fgcw-684q-jj6r (aka CVE-2026-5241).\n\nhuggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path\n\nAliases: CVE-2026-5241, GHSA-fgcw-684q-jj6r, PYSEC-2026-2290\nAdvisory: https://osv.dev/vulnerability/GHSA-fgcw-684q-jj6r\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-5028ff324e4ef715", "name": "Vulnerable dependency transformers 4.57.1: PYSEC-2025-217", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.1: PYSEC-2025-217"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by PYSEC-2025-217 (aka CVE-2025-14929).\n\nNo summary published yet.\n\nAliases: CVE-2025-14929\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-217\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b2e23509d770c38", "name": "Vulnerable dependency transformers 4.57.1: PYSEC-2025-218", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.1: PYSEC-2025-218"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.1` (resolved in `uv.lock`) is affected by PYSEC-2025-218 (aka CVE-2025-14930).\n\nNo summary published yet.\n\nAliases: CVE-2025-14930\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-218\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6e5c35098055b5f3", "name": "Vulnerable dependency xgrammar 0.1.27: GHSA-7rgv-gqhr-fxg3", "shortDescription": {"text": "Vulnerable dependency xgrammar 0.1.27: GHSA-7rgv-gqhr-fxg3"}, "fullDescription": {"text": "OSV.dev reports `xgrammar` at version `0.1.27` (resolved in `uv.lock`) is affected by GHSA-7rgv-gqhr-fxg3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7rgv-gqhr-fxg3\nFix: upgrade `xgrammar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b7a93544dfebbb63", "name": "Vulnerable dependency xgrammar 0.1.27: PYSEC-2026-2322", "shortDescription": {"text": "Vulnerable dependency xgrammar 0.1.27: PYSEC-2026-2322"}, "fullDescription": {"text": "OSV.dev reports `xgrammar` at version `0.1.27` (resolved in `uv.lock`) is affected by PYSEC-2026-2322.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2322\nFix: upgrade `xgrammar` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-60b35af4940466df", "name": "Vulnerable dependency transformers 4.38.2: GHSA-29pf-2h5f-8g72", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-29pf-2h5f-8g72"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-29pf-2h5f-8g72 (aka CVE-2026-4372).\n\nHuggingFace transformers vulnerable to remote code execution\n\nAliases: CVE-2026-4372, GHSA-29pf-2h5f-8g72, PYSEC-2026-2289\nAdvisory: https://osv.dev/vulnerability/GHSA-29pf-2h5f-8g72\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81f6537a3a07e248", "name": "Vulnerable dependency transformers 4.38.2: GHSA-37mw-44qp-f5jm", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-37mw-44qp-f5jm"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-37mw-44qp-f5jm (aka CVE-2025-3933).\n\nTransformers is vulnerable to ReDoS attack through its DonutProcessor class\n\nAliases: CVE-2025-3933, PYSEC-2026-1977\nAdvisory: https://osv.dev/vulnerability/GHSA-37mw-44qp-f5jm\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5f981f98c612e913", "name": "Vulnerable dependency transformers 4.38.2: GHSA-4w7r-h757-3r74", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-4w7r-h757-3r74"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-4w7r-h757-3r74 (aka CVE-2025-6921).\n\nHugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer\n\nAliases: CVE-2025-6921, PYSEC-2026-1980\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7r-h757-3r74\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-64219c906f4fa365", "name": "Vulnerable dependency transformers 4.38.2: GHSA-59p9-h35m-wg4g", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-59p9-h35m-wg4g"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-59p9-h35m-wg4g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-59p9-h35m-wg4g\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3fc49f27141b3a8b", "name": "Vulnerable dependency transformers 4.38.2: GHSA-69w3-r845-3855", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-69w3-r845-3855"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-69w3-r845-3855 (aka CVE-2026-1839).\n\nHuggingFace Transformers allows for arbitrary code execution in the `Trainer` class\n\nAliases: CVE-2026-1839, GHSA-69w3-r845-3855, PYSEC-2026-2288\nAdvisory: https://osv.dev/vulnerability/GHSA-69w3-r845-3855\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f97c5a1f0c1f174", "name": "Vulnerable dependency transformers 4.38.2: GHSA-6rvg-6v2m-4j46", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-6rvg-6v2m-4j46"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-6rvg-6v2m-4j46.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6rvg-6v2m-4j46\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9814c09e7771b0f", "name": "Vulnerable dependency transformers 4.38.2: GHSA-9356-575x-2w9m", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-9356-575x-2w9m"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-9356-575x-2w9m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9356-575x-2w9m\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e547164f571bf87", "name": "Vulnerable dependency transformers 4.38.2: GHSA-fgcw-684q-jj6r", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-fgcw-684q-jj6r"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-fgcw-684q-jj6r (aka CVE-2026-5241).\n\nhuggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path\n\nAliases: CVE-2026-5241, GHSA-fgcw-684q-jj6r, PYSEC-2026-2290\nAdvisory: https://osv.dev/vulnerability/GHSA-fgcw-684q-jj6r\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-86d5a4f2c9fa7920", "name": "Vulnerable dependency transformers 4.38.2: GHSA-fpwr-67px-3qhx", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-fpwr-67px-3qhx"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-fpwr-67px-3qhx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fpwr-67px-3qhx\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd3c12685c306887", "name": "Vulnerable dependency transformers 4.38.2: GHSA-hxxf-235m-72v3", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-hxxf-235m-72v3"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-hxxf-235m-72v3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hxxf-235m-72v3\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-768cb22612581c8b", "name": "Vulnerable dependency transformers 4.38.2: GHSA-jjph-296x-mrcr", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-jjph-296x-mrcr"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-jjph-296x-mrcr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jjph-296x-mrcr\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e411af040f6e2cc", "name": "Vulnerable dependency transformers 4.38.2: GHSA-phhr-52qp-3mj4", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-phhr-52qp-3mj4"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-phhr-52qp-3mj4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-phhr-52qp-3mj4\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8fb5d62388a73db1", "name": "Vulnerable dependency transformers 4.38.2: GHSA-q2wp-rjmx-x6x9", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-q2wp-rjmx-x6x9"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-q2wp-rjmx-x6x9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q2wp-rjmx-x6x9\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f600ab3bd32b812", "name": "Vulnerable dependency transformers 4.38.2: GHSA-qq3j-4f4f-9583", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-qq3j-4f4f-9583"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-qq3j-4f4f-9583.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qq3j-4f4f-9583\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c3a0c0ecd8e8912c", "name": "Vulnerable dependency transformers 4.38.2: GHSA-qxrp-vhvm-j765", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-qxrp-vhvm-j765"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-qxrp-vhvm-j765.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qxrp-vhvm-j765\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33e017ee26ecf658", "name": "Vulnerable dependency transformers 4.38.2: GHSA-rcv9-qm8p-9p6j", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-rcv9-qm8p-9p6j"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-rcv9-qm8p-9p6j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rcv9-qm8p-9p6j\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ade649933827b025", "name": "Vulnerable dependency transformers 4.38.2: GHSA-wrfc-pvp9-mr9g", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-wrfc-pvp9-mr9g"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by GHSA-wrfc-pvp9-mr9g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wrfc-pvp9-mr9g\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b85ccead2217f05", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-227", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-227"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2024-227.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2024-227\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5492f8157b75fe15", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-228", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-228"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2024-228.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2024-228\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d6878964d21d9b1f", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-229", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-229"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2024-229.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2024-229\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2fccdfec4c2388fc", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-211", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-211"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-211.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-211\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9e3c624b1710e25", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-212", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-212"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-212.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-212\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc05e0dc730420f7", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-213", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-213"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-213.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-213\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b758aa54532710a", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-214", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-214"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-214.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-214\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a591030e3f8aae87", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-215", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-215"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-215.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-215\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37ca66577652059b", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-216", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-216"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-216.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-216\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d43fced2347ecceb", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-217", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-217"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-217 (aka CVE-2025-14929).\n\nNo summary published yet.\n\nAliases: CVE-2025-14929\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-217\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-69afdeb128ddfd8c", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-218", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-218"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-218 (aka CVE-2025-14930).\n\nNo summary published yet.\n\nAliases: CVE-2025-14930\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-218\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8182189c19ffd18b", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-40", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-40"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2025-40.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-40\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8cc9f8098b139427", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1981", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1981"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1981.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1981\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d709da3b1ba0f00a", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1982", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1982"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1982.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1982\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1eef0df1ce296277", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1983", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1983"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1983.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1983\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e45d98dea3a0ced", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1984", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1984"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1984.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1984\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67774b4495581432", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1985", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1985"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1985.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1985\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-719d44a820de1d0a", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1986", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1986"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1986.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1986\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c84a4a1a5590ca0", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1987", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1987"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1987.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1987\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-815768951bedaaf6", "name": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1988", "shortDescription": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1988"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.38.2` (declared in `examples/bentoml/requirements.txt`) is affected by PYSEC-2026-1988.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1988\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eae7ada9cac371f6", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-2fqr-mr3j-6wp8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-2fqr-mr3j-6wp8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279).\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\naiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAliases: CVE-2026-54279, PYSEC-2026-2112\nAdvisory: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ffdebb971b87150e", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-2vrm-gr82-f7m5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-2vrm-gr82-f7m5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514).\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAIOHTTP has CRLF injection through multipart part content type header construction\n\nAliases: CVE-2026-34514, PYSEC-2026-2096\nAdvisory: https://osv.dev/vulnerability/GHSA-2vrm-gr82-f7m5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-091453a6655803e6", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-3wq7-rqq7-wx6j", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-3wq7-rqq7-wx6j"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517).\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS\n\nAliases: CVE-2026-34517, PYSEC-2026-2099\nAdvisory: https://osv.dev/vulnerability/GHSA-3wq7-rqq7-wx6j\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e3bbeec4e01e6757", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-4fvr-rgm6-gqmc", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-4fvr-rgm6-gqmc"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273).\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\naiohttp: HTTP/1 Pipelined Requests Queue Without Limit\n\nAliases: CVE-2026-54273, PYSEC-2026-2107\nAdvisory: https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f21ebac622135391", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-4m7w-qmgq-4wj5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-4m7w-qmgq-4wj5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275).\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\naiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections\n\nAliases: CVE-2026-54275, PYSEC-2026-237\nAdvisory: https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-077933dad46d3093", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-54jq-c3m8-4m76", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-54jq-c3m8-4m76"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-54jq-c3m8-4m76 (aka CVE-2025-69226).\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAIOHTTP vulnerable to brute-force leak of internal static \ufb01le path components\n\nAliases: CVE-2025-69226, PYSEC-2026-1097\nAdvisory: https://osv.dev/vulnerability/GHSA-54jq-c3m8-4m76\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e9a68d80b7355017", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-63hf-3vf5-4wqf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-63hf-3vf5-4wqf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-63hf-3vf5-4wqf.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hf-3vf5-4wqf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-72a89562bc148031", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-63hw-fmq6-xxg2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-63hw-fmq6-xxg2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-63hw-fmq6-xxg2.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-27c26d6cc2433628", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-69f9-5gxw-wvc2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-69f9-5gxw-wvc2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-69f9-5gxw-wvc2.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-69f9-5gxw-wvc2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f887eedc570d3b30", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-6jhg-hg63-jvvf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-6jhg-hg63-jvvf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-6jhg-hg63-jvvf.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6jhg-hg63-jvvf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9adcf7fb40e47a3f", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-6mq8-rvhq-8wgg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-6mq8-rvhq-8wgg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-6mq8-rvhq-8wgg.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6mq8-rvhq-8wgg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-af1cc70cc991275e", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-966j-vmvw-g2g9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-966j-vmvw-g2g9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-966j-vmvw-g2g9.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-966j-vmvw-g2g9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-bf7f2af425fe3a69", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-9x8q-7h8h-wcw9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-9x8q-7h8h-wcw9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7f5d7517036e31ce", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-c427-h43c-vf67", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-c427-h43c-vf67"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-c427-h43c-vf67.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c427-h43c-vf67\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-028ea7374734d8f6", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-fh55-r93g-j68g", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-fh55-r93g-j68g"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-fh55-r93g-j68g.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fh55-r93g-j68g\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4f520a0158b23449", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-g3cq-j2xw-wf74", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-g3cq-j2xw-wf74"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-g3cq-j2xw-wf74.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-712de8187d5e3a88", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-g84x-mcqj-x9qq", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-g84x-mcqj-x9qq"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-g84x-mcqj-x9qq.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g84x-mcqj-x9qq\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-79d01376606c73d0", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-hcc4-c3v8-rx92", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-hcc4-c3v8-rx92"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-hcc4-c3v8-rx92.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcc4-c3v8-rx92\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2e28cc8de7cda91c", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-hg6j-4rv6-33pg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-hg6j-4rv6-33pg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-hg6j-4rv6-33pg.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-45338a95299b5df8", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-hpj7-wq8m-9hgp", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-hpj7-wq8m-9hgp"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-hpj7-wq8m-9hgp.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-37786c667930c3f6", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-jg22-mg44-37j8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-jg22-mg44-37j8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-jg22-mg44-37j8.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-97b3e90e9f21932d", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-jj3x-wxrx-4x23", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-jj3x-wxrx-4x23"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-jj3x-wxrx-4x23.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jj3x-wxrx-4x23\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1624a8cd3ab59e8b", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-m5qp-6w8w-w647", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-m5qp-6w8w-w647"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-m5qp-6w8w-w647.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m5qp-6w8w-w647\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-035f474fce230892", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-m6qw-4cw2-hm4m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-m6qw-4cw2-hm4m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-m6qw-4cw2-hm4m.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-345a4b4666389d0a", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-mqqc-3gqh-h2x8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-mqqc-3gqh-h2x8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-mqqc-3gqh-h2x8.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mqqc-3gqh-h2x8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4f2c4860a207cc18", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-mwh4-6h8g-pg8w", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-mwh4-6h8g-pg8w"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-mwh4-6h8g-pg8w.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwh4-6h8g-pg8w\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0cec972590d02dd3", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-p998-jp59-783m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-p998-jp59-783m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-p998-jp59-783m.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p998-jp59-783m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9fbe8fedce994400", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-w2fm-2cpv-w7v5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-w2fm-2cpv-w7v5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-w2fm-2cpv-w7v5.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w2fm-2cpv-w7v5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-baaf24460054879a", "name": "Vulnerable dependency aiohttp 3.13.2: GHSA-xcgm-r5h9-7989", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-xcgm-r5h9-7989"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by GHSA-xcgm-r5h9-7989.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7c5cb834d4f6c6cd", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1099", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1099"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1099.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1099\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d2eb3862902c2d8a", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1100.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e4498dc7a6c8ec1f", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1101.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9281f6d12abc6e31", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1105.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7197a0a1456b8578", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1106.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-87513ebf796fdbe7", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1107", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1107"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1107.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1107\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e3a9b01c4b20d4a3", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1109.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-754937e92f9208f9", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2094", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2094"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2094.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2094\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8799c88835f71b4e", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2095", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2095"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2095.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2095\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7ecc289f961b6262", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2097.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-541eea135abcd2af", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2098", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2098"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2098.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2098\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-547fb63d5ecde297", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2100.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-024dd211dcefc148", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2101.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c3e0ffaafbb1e9ec", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2102", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2102"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2102.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2102\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-58da7510b0829ca0", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2103", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2103"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2103.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2103\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-639ec948ecb97e82", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2104.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d78811ab8ff655d6", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2105.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-92b860ec31ad82ae", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2106.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b653df191f378ad9", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2108", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2108"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2108.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2108\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-47e29690d67c7abe", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2109.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-14e88ba0f4f88fda", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2110", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2110"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2110.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2110\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-56d86ab728bdcc91", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2111", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2111"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2111.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2111\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9c6f8ea962bb5a94", "name": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2113", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2113"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.2` (resolved in `uv.lock`) is affected by PYSEC-2026-2113.\nNote: `aiohttp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2113\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e12ad07bf9e97352", "name": "Vulnerable dependency click 8.2.1: PYSEC-2026-2132", "shortDescription": {"text": "Vulnerable dependency click 8.2.1: PYSEC-2026-2132"}, "fullDescription": {"text": "OSV.dev reports `click` at version `8.2.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2132.\nNote: `click` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2132\nFix: upgrade `click` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0f8b65b1cea4f40f", "name": "Vulnerable dependency filelock 3.20.0: GHSA-qmgc-5h2g-mvrw", "shortDescription": {"text": "Vulnerable dependency filelock 3.20.0: GHSA-qmgc-5h2g-mvrw"}, "fullDescription": {"text": "OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by GHSA-qmgc-5h2g-mvrw.\nNote: `filelock` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qmgc-5h2g-mvrw\nFix: upgrade `filelock` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5a27f36b095d4ce2", "name": "Vulnerable dependency filelock 3.20.0: GHSA-w853-jp5j-5j7f", "shortDescription": {"text": "Vulnerable dependency filelock 3.20.0: GHSA-w853-jp5j-5j7f"}, "fullDescription": {"text": "OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by GHSA-w853-jp5j-5j7f.\nNote: `filelock` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w853-jp5j-5j7f\nFix: upgrade `filelock` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b07637bfa7516ab9", "name": "Vulnerable dependency filelock 3.20.0: PYSEC-2026-1374", "shortDescription": {"text": "Vulnerable dependency filelock 3.20.0: PYSEC-2026-1374"}, "fullDescription": {"text": "OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by PYSEC-2026-1374.\nNote: `filelock` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1374\nFix: upgrade `filelock` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-dad01c1a900eae48", "name": "Vulnerable dependency filelock 3.20.0: PYSEC-2026-1375", "shortDescription": {"text": "Vulnerable dependency filelock 3.20.0: PYSEC-2026-1375"}, "fullDescription": {"text": "OSV.dev reports `filelock` at version `3.20.0` (resolved in `uv.lock`) is affected by PYSEC-2026-1375.\nNote: `filelock` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1375\nFix: upgrade `filelock` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9eb78ac091ef83de", "name": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx", "shortDescription": {"text": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx"}, "fullDescription": {"text": "OSV.dev reports `idna` at version `3.11` (resolved in `uv.lock`) is affected by GHSA-65pc-fj4g-8rjx (aka CVE-2026-45409).\nNote: `idna` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nInternationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix\n\nAliases: CVE-2026-45409, PYSEC-2026-215\nAdvisory: https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx\nFix: upgrade `idna` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-53908982d0b4fca2", "name": "Vulnerable dependency keras 3.12.0: GHSA-3m4q-jmj6-r34q", "shortDescription": {"text": "Vulnerable dependency keras 3.12.0: GHSA-3m4q-jmj6-r34q"}, "fullDescription": {"text": "OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by GHSA-3m4q-jmj6-r34q (aka CVE-2026-1669).\nNote: `keras` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nKeras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading\n\nAliases: CVE-2026-1669, PYSEC-2026-2546\nAdvisory: https://osv.dev/vulnerability/GHSA-3m4q-jmj6-r34q\nFix: upgrade `keras` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b4ab84f115c226d4", "name": "Vulnerable dependency keras 3.12.0: GHSA-4f3f-g24h-fr8m", "shortDescription": {"text": "Vulnerable dependency keras 3.12.0: GHSA-4f3f-g24h-fr8m"}, "fullDescription": {"text": "OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by GHSA-4f3f-g24h-fr8m (aka CVE-2026-1462).\nNote: `keras` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nKeras has an untrusted deserialization vulnerability\n\nAliases: CVE-2026-1462, PYSEC-2026-2547\nAdvisory: https://osv.dev/vulnerability/GHSA-4f3f-g24h-fr8m\nFix: upgrade `keras` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c5e466c7ddc74087", "name": "Vulnerable dependency keras 3.12.0: GHSA-mgx6-5cf9-rr43", "shortDescription": {"text": "Vulnerable dependency keras 3.12.0: GHSA-mgx6-5cf9-rr43"}, "fullDescription": {"text": "OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by GHSA-mgx6-5cf9-rr43.\nNote: `keras` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mgx6-5cf9-rr43\nFix: upgrade `keras` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c6cda58e2141e680", "name": "Vulnerable dependency keras 3.12.0: PYSEC-2026-2324", "shortDescription": {"text": "Vulnerable dependency keras 3.12.0: PYSEC-2026-2324"}, "fullDescription": {"text": "OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2324.\nNote: `keras` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2324\nFix: upgrade `keras` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-cce7de344341cace", "name": "Vulnerable dependency keras 3.12.0: PYSEC-2026-73", "shortDescription": {"text": "Vulnerable dependency keras 3.12.0: PYSEC-2026-73"}, "fullDescription": {"text": "OSV.dev reports `keras` at version `3.12.0` (resolved in `uv.lock`) is affected by PYSEC-2026-73.\nNote: `keras` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-73\nFix: upgrade `keras` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c77c4d1b2675bd17", "name": "Vulnerable dependency msgpack 1.1.2: GHSA-6v7p-g79w-8964", "shortDescription": {"text": "Vulnerable dependency msgpack 1.1.2: GHSA-6v7p-g79w-8964"}, "fullDescription": {"text": "OSV.dev reports `msgpack` at version `1.1.2` (resolved in `uv.lock`) is affected by GHSA-6v7p-g79w-8964.\nNote: `msgpack` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6v7p-g79w-8964\nFix: upgrade `msgpack` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-720e9bb3ab4fbb20", "name": "Vulnerable dependency protobuf 6.33.1: GHSA-7gcm-g887-7qv7", "shortDescription": {"text": "Vulnerable dependency protobuf 6.33.1: GHSA-7gcm-g887-7qv7"}, "fullDescription": {"text": "OSV.dev reports `protobuf` at version `6.33.1` (resolved in `uv.lock`) is affected by GHSA-7gcm-g887-7qv7.\nNote: `protobuf` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7gcm-g887-7qv7\nFix: upgrade `protobuf` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fb57110b590e3e07", "name": "Vulnerable dependency protobuf 6.33.1: PYSEC-2026-1805", "shortDescription": {"text": "Vulnerable dependency protobuf 6.33.1: PYSEC-2026-1805"}, "fullDescription": {"text": "OSV.dev reports `protobuf` at version `6.33.1` (resolved in `uv.lock`) is affected by PYSEC-2026-1805.\nNote: `protobuf` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1805\nFix: upgrade `protobuf` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-bdaac34b4de2d066", "name": "Vulnerable dependency pyarrow 22.0.0: GHSA-rgxp-2hwp-jwgg", "shortDescription": {"text": "Vulnerable dependency pyarrow 22.0.0: GHSA-rgxp-2hwp-jwgg"}, "fullDescription": {"text": "OSV.dev reports `pyarrow` at version `22.0.0` (resolved in `uv.lock`) is affected by GHSA-rgxp-2hwp-jwgg.\nNote: `pyarrow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rgxp-2hwp-jwgg\nFix: upgrade `pyarrow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-169ad7e54fab5d25", "name": "Vulnerable dependency pyarrow 22.0.0: PYSEC-2026-113", "shortDescription": {"text": "Vulnerable dependency pyarrow 22.0.0: PYSEC-2026-113"}, "fullDescription": {"text": "OSV.dev reports `pyarrow` at version `22.0.0` (resolved in `uv.lock`) is affected by PYSEC-2026-113.\nNote: `pyarrow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-113\nFix: upgrade `pyarrow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-364dc785056399f2", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-63vm-454h-vhhq.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63vm-454h-vhhq\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1f5e54aaea81621a", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-8ppf-4f7h-5ppj.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8ppf-4f7h-5ppj\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0ea10d916c48959f", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-hm4w-wwcw-mr6r.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm4w-wwcw-mr6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-28d657c37832bf9f", "name": "Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by GHSA-jr27-m4p2-rc6r.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jr27-m4p2-rc6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-3bba52511a4f5462", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-1810.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1810\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6870757873e4f752", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2263.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2263\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e134a151ed33c523", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3455.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3455\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0ece961f56587673", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3456.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3456\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0a7c9d28fb64f89d", "name": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3457.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3457\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2f35e24090839556", "name": "Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq", "shortDescription": {"text": "Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq"}, "fullDescription": {"text": "OSV.dev reports `pygments` at version `2.19.2` (resolved in `uv.lock`) is affected by GHSA-5239-wwwm-4pmq (aka CVE-2026-4539).\nNote: `pygments` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching\n\nAliases: CVE-2026-4539, PYSEC-2026-2987\nAdvisory: https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq\nFix: upgrade `pygments` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ff57d7ec3600d392", "name": "Vulnerable dependency urllib3 2.5.0: GHSA-2xpw-w6gg-jr37", "shortDescription": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-2xpw-w6gg-jr37"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-2xpw-w6gg-jr37 (aka CVE-2025-66471).\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nurllib3 streaming API improperly handles highly compressed data\n\nAliases: CVE-2025-66471, PYSEC-2026-1994\nAdvisory: https://osv.dev/vulnerability/GHSA-2xpw-w6gg-jr37\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "critical", "confidence": 0.9}}, {"id": "scanner-c3b6909cf7cc1f1c", "name": "Vulnerable dependency urllib3 2.5.0: GHSA-38jv-5279-wg99", "shortDescription": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-38jv-5279-wg99"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-38jv-5279-wg99 (aka CVE-2026-21441).\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDecompression-bomb safeguards bypassed when following HTTP redirects (streaming API)\n\nAliases: CVE-2026-21441, PYSEC-2026-1996\nAdvisory: https://osv.dev/vulnerability/GHSA-38jv-5279-wg99\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "critical", "confidence": 0.9}}, {"id": "scanner-b0a64e27a9c3ea75", "name": "Vulnerable dependency urllib3 2.5.0: GHSA-gm62-xv2j-4w53", "shortDescription": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-gm62-xv2j-4w53"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-gm62-xv2j-4w53.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gm62-xv2j-4w53\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0b3395f8792655a7", "name": "Vulnerable dependency urllib3 2.5.0: GHSA-qccp-gfcp-xxvc", "shortDescription": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-qccp-gfcp-xxvc"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by GHSA-qccp-gfcp-xxvc.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qccp-gfcp-xxvc\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-cf64d0c2fef2c33e", "name": "Vulnerable dependency urllib3 2.5.0: PYSEC-2026-141", "shortDescription": {"text": "Vulnerable dependency urllib3 2.5.0: PYSEC-2026-141"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by PYSEC-2026-141.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-141\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a17785bbee94419f", "name": "Vulnerable dependency urllib3 2.5.0: PYSEC-2026-1998", "shortDescription": {"text": "Vulnerable dependency urllib3 2.5.0: PYSEC-2026-1998"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.5.0` (resolved in `uv.lock`) is affected by PYSEC-2026-1998.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1998\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c036f1c93ce7d800", "name": "Vulnerable dependency virtualenv 20.35.4: GHSA-597g-3phw-6986", "shortDescription": {"text": "Vulnerable dependency virtualenv 20.35.4: GHSA-597g-3phw-6986"}, "fullDescription": {"text": "OSV.dev reports `virtualenv` at version `20.35.4` (resolved in `uv.lock`) is affected by GHSA-597g-3phw-6986.\nNote: `virtualenv` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-597g-3phw-6986\nFix: upgrade `virtualenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-46f2064f27a58a3e", "name": "Vulnerable dependency virtualenv 20.35.4: PYSEC-2026-2009", "shortDescription": {"text": "Vulnerable dependency virtualenv 20.35.4: PYSEC-2026-2009"}, "fullDescription": {"text": "OSV.dev reports `virtualenv` at version `20.35.4` (resolved in `uv.lock`) is affected by PYSEC-2026-2009.\nNote: `virtualenv` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2009\nFix: upgrade `virtualenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-364553bfa1c3729d", "name": "Vulnerable dependency werkzeug 3.1.3: GHSA-29vq-49wr-vm6x", "shortDescription": {"text": "Vulnerable dependency werkzeug 3.1.3: GHSA-29vq-49wr-vm6x"}, "fullDescription": {"text": "OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by GHSA-29vq-49wr-vm6x (aka CVE-2026-27199).\nNote: `werkzeug` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nWerkzeug safe_join() allows Windows special device names\n\nAliases: CVE-2026-27199, PYSEC-2026-2320\nAdvisory: https://osv.dev/vulnerability/GHSA-29vq-49wr-vm6x\nFix: upgrade `werkzeug` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fd265773b23790de", "name": "Vulnerable dependency werkzeug 3.1.3: GHSA-87hc-h4r5-73f7", "shortDescription": {"text": "Vulnerable dependency werkzeug 3.1.3: GHSA-87hc-h4r5-73f7"}, "fullDescription": {"text": "OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by GHSA-87hc-h4r5-73f7.\nNote: `werkzeug` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-87hc-h4r5-73f7\nFix: upgrade `werkzeug` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a693300e4d3e2c0a", "name": "Vulnerable dependency werkzeug 3.1.3: GHSA-hgf8-39gv-g3f2", "shortDescription": {"text": "Vulnerable dependency werkzeug 3.1.3: GHSA-hgf8-39gv-g3f2"}, "fullDescription": {"text": "OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by GHSA-hgf8-39gv-g3f2.\nNote: `werkzeug` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hgf8-39gv-g3f2\nFix: upgrade `werkzeug` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5f697d954eabfc57", "name": "Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2044", "shortDescription": {"text": "Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2044"}, "fullDescription": {"text": "OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2044.\nNote: `werkzeug` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2044\nFix: upgrade `werkzeug` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a392e4fcc405ed0d", "name": "Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2046", "shortDescription": {"text": "Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2046"}, "fullDescription": {"text": "OSV.dev reports `werkzeug` at version `3.1.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2046.\nNote: `werkzeug` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2046\nFix: upgrade `werkzeug` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4851d74e368ed96e", "name": "Vulnerable dependency wheel 0.45.1: GHSA-8rrh-rw8j-w5fx", "shortDescription": {"text": "Vulnerable dependency wheel 0.45.1: GHSA-8rrh-rw8j-w5fx"}, "fullDescription": {"text": "OSV.dev reports `wheel` at version `0.45.1` (resolved in `uv.lock`) is affected by GHSA-8rrh-rw8j-w5fx.\nNote: `wheel` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8rrh-rw8j-w5fx\nFix: upgrade `wheel` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fdd5e04247a812d8", "name": "Vulnerable dependency wheel 0.45.1: PYSEC-2026-2047", "shortDescription": {"text": "Vulnerable dependency wheel 0.45.1: PYSEC-2026-2047"}, "fullDescription": {"text": "OSV.dev reports `wheel` at version `0.45.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2047.\nNote: `wheel` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2047\nFix: upgrade `wheel` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8f0b665aa20127d3", "name": "Dependency accelerate is a major version behind", "shortDescription": {"text": "Dependency accelerate is a major version behind"}, "fullDescription": {"text": "`accelerate` is pinned at `0.27.2` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `1.14.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `accelerate` to `1.14.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-2e06d72b13e6f2d4", "name": "Dependency datasets is two or more major versions behind", "shortDescription": {"text": "Dependency datasets is two or more major versions behind"}, "fullDescription": {"text": "`datasets` is pinned at `2.18.0` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `5.0.0` \u2014 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `datasets` to `5.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4b6e0f8a84512616", "name": "Dependency outlines is a major version behind", "shortDescription": {"text": "Dependency outlines is a major version behind"}, "fullDescription": {"text": "`outlines` is pinned at `0.0.37` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `1.3.2` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `outlines` to `1.3.2`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-38a60fdad0eca540", "name": "Dependency transformers is a major version behind", "shortDescription": {"text": "Dependency transformers is a major version behind"}, "fullDescription": {"text": "`transformers` is pinned at `4.38.2` in `examples/bentoml/requirements.txt` while the latest release on the pypi registry is `5.14.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `transformers` to `5.14.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30763"}, "properties": {"repository": "dottxt-ai/outlines", "repoUrl": "https://github.com/dottxt-ai/outlines", "branch": "main"}, "results": [{"ruleId": "scanner-a017476ef4558071", "level": "note", "message": {"text": "Possibly dead Python function: split_into_steps"}, "properties": {"repobilityId": "62c97ce93f3e354b", "scanner": "scanner-primary", "fingerprint": "a017476ef4558071", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/meta_prompting.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97a166bdedab4a4d", "level": "note", "message": {"text": "Possibly dead Python function: fill_in_the_blanks"}, "properties": {"repobilityId": "bb961c0f61606838", "scanner": "scanner-primary", "fingerprint": "97a166bdedab4a4d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/meta_prompting.py:45"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb0c07736512004f", "level": "note", "message": {"text": "Possibly dead Python function: ask_an_expert"}, "properties": {"repobilityId": "cb63cfd332d30016", "scanner": "scanner-primary", "fingerprint": "cb0c07736512004f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/meta_prompting.py:66"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0204f9ffe1f87c1e", "level": "note", "message": {"text": "Possibly dead Python function: ask_an_expert_simple"}, "properties": {"repobilityId": "ac837706cfaaa66e", "scanner": "scanner-primary", "fingerprint": "0204f9ffe1f87c1e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/meta_prompting.py:105"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-756c61dddbb62eef", "level": "note", "message": {"text": "Possibly dead Python function: load_models"}, "properties": {"repobilityId": "417af327d206961c", "scanner": "scanner-primary", "fingerprint": "756c61dddbb62eef", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/beam-cloud/app.py:11"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-99853f0922ec56af", "level": "note", "message": {"text": "Possibly dead Python function: decorator"}, "properties": {"repobilityId": "ffbcbc9bc189af1c", "scanner": "scanner-primary", "fingerprint": "99853f0922ec56af", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/outlines/caching.py:108"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca71927fbdaee9e5", "level": "note", "message": {"text": "Possibly dead Python function: wrapper"}, "properties": {"repobilityId": "1dc9acbcc8ce537d", "scanner": "scanner-primary", "fingerprint": "ca71927fbdaee9e5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/outlines/caching.py:130"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2dadf8d9881e71f6", "level": "warning", "message": {"text": "var in href \u2014 docs/overrides/home.html:130"}, "properties": {"repobilityId": "f224e148d7710728", "scanner": "scanner-primary", "fingerprint": "2dadf8d9881e71f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "html-templates"]}}, {"ruleId": "scanner-7ded532a6d2eecd7", "level": "warning", "message": {"text": "eval detected \u2014 examples/math_generate_code.py:36"}, "properties": {"repobilityId": "19df25eece27793a", "scanner": "scanner-primary", "fingerprint": "7ded532a6d2eecd7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-e6e1ed806eba9ad1", "level": "error", "message": {"text": "CVE-2024-11392: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "917045e783709afd", "scanner": "scanner-primary", "fingerprint": "e6e1ed806eba9ad1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-11392"]}}, {"ruleId": "scanner-30ef5b34f7078c6d", "level": "error", "message": {"text": "CVE-2024-11393: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "8601f8dd81f07a6a", "scanner": "scanner-primary", "fingerprint": "30ef5b34f7078c6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-11393"]}}, {"ruleId": "scanner-7c4b20bea2d2fa3d", "level": "error", "message": {"text": "CVE-2024-11394: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "83d3e02cb179c09b", "scanner": "scanner-primary", "fingerprint": "7c4b20bea2d2fa3d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-11394"]}}, {"ruleId": "scanner-dd7ebc1fd24e5e2d", "level": "error", "message": {"text": "CVE-2026-4372: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "2f015bb031c9af80", "scanner": "scanner-primary", "fingerprint": "dd7ebc1fd24e5e2d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4372"]}}, {"ruleId": "scanner-5b8f3b6956ab9d40", "level": "error", "message": {"text": "CVE-2026-5241: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "e8737a1d00f83398", "scanner": "scanner-primary", "fingerprint": "5b8f3b6956ab9d40", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5241"]}}, {"ruleId": "scanner-0280a07cee802dca", "level": "warning", "message": {"text": "CVE-2024-12720: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "5b92f82fed434d66", "scanner": "scanner-primary", "fingerprint": "0280a07cee802dca", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-12720"]}}, {"ruleId": "scanner-c98c4d2f4400df0d", "level": "warning", "message": {"text": "CVE-2025-1194: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "0fe6a214ce1c8e65", "scanner": "scanner-primary", "fingerprint": "c98c4d2f4400df0d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-1194"]}}, {"ruleId": "scanner-196d23f2e4e632ee", "level": "warning", "message": {"text": "CVE-2025-2099: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "4333b494f82c24f1", "scanner": "scanner-primary", "fingerprint": "196d23f2e4e632ee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2099"]}}, {"ruleId": "scanner-a5507af014b9896c", "level": "warning", "message": {"text": "CVE-2025-3263: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "db2101ea4e7cb5cd", "scanner": "scanner-primary", "fingerprint": "a5507af014b9896c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3263"]}}, {"ruleId": "scanner-f56f81e907cb4c7c", "level": "warning", "message": {"text": "CVE-2025-3264: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "617234009d0396e0", "scanner": "scanner-primary", "fingerprint": "f56f81e907cb4c7c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3264"]}}, {"ruleId": "scanner-9d41a4087256b958", "level": "warning", "message": {"text": "CVE-2025-3933: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "934ddb66c8450a75", "scanner": "scanner-primary", "fingerprint": "9d41a4087256b958", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3933"]}}, {"ruleId": "scanner-640a4338ee2af8cc", "level": "warning", "message": {"text": "CVE-2025-5197: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "51aad1f25beeb95b", "scanner": "scanner-primary", "fingerprint": "640a4338ee2af8cc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5197"]}}, {"ruleId": "scanner-5b691a46fb6c886d", "level": "warning", "message": {"text": "CVE-2025-6051: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "016587455bb0e2ff", "scanner": "scanner-primary", "fingerprint": "5b691a46fb6c886d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6051"]}}, {"ruleId": "scanner-4a3f75952f444a7c", "level": "warning", "message": {"text": "CVE-2025-6638: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "8a4febe0309608a4", "scanner": "scanner-primary", "fingerprint": "4a3f75952f444a7c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6638"]}}, {"ruleId": "scanner-11b14a6b879e7bf3", "level": "warning", "message": {"text": "CVE-2025-6921: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "aa8ec6f5e2d7cd97", "scanner": "scanner-primary", "fingerprint": "11b14a6b879e7bf3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6921"]}}, {"ruleId": "scanner-28d3d4f1b7feb174", "level": "warning", "message": {"text": "CVE-2026-1839: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "d1999a7e12ff66ad", "scanner": "scanner-primary", "fingerprint": "28d3d4f1b7feb174", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1839"]}}, {"ruleId": "scanner-91a998ea7f4caa58", "level": "note", "message": {"text": "CVE-2025-3777: transformers 4.38.2 \u2014 examples/bentoml/requirements.txt"}, "properties": {"repobilityId": "4907ecad2f86c6ab", "scanner": "scanner-primary", "fingerprint": "91a998ea7f4caa58", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3777"]}}, {"ruleId": "scanner-01f0b7c38ecdb71f", "level": "error", "message": {"text": "CVE-2025-69223: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "14826ca52f8b6900", "scanner": "scanner-primary", "fingerprint": "01f0b7c38ecdb71f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69223"]}}, {"ruleId": "scanner-adc21fc6f1c81765", "level": "warning", "message": {"text": "CVE-2025-69227: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "b309239218c415d0", "scanner": "scanner-primary", "fingerprint": "adc21fc6f1c81765", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69227"]}}, {"ruleId": "scanner-91d95123c0b5f441", "level": "warning", "message": {"text": "CVE-2025-69228: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "57239831570df033", "scanner": "scanner-primary", "fingerprint": "91d95123c0b5f441", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69228"]}}, {"ruleId": "scanner-1e500b4d6f200e36", "level": "warning", "message": {"text": "CVE-2025-69229: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "c576636c4356201e", "scanner": "scanner-primary", "fingerprint": "1e500b4d6f200e36", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69229"]}}, {"ruleId": "scanner-7d05e8129acab9ee", "level": "warning", "message": {"text": "CVE-2026-22815: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "bf8fbc12565d7e15", "scanner": "scanner-primary", "fingerprint": "7d05e8129acab9ee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22815"]}}, {"ruleId": "scanner-d036f5215d9e0da7", "level": "warning", "message": {"text": "CVE-2026-34515: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "f7c844cd603d72b2", "scanner": "scanner-primary", "fingerprint": "d036f5215d9e0da7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34515"]}}, {"ruleId": "scanner-929815d8bf9592b6", "level": "warning", "message": {"text": "CVE-2026-34516: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "a7094e9184ed89ad", "scanner": "scanner-primary", "fingerprint": "929815d8bf9592b6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34516"]}}, {"ruleId": "scanner-a55eb5eb79baaf4a", "level": "warning", "message": {"text": "CVE-2026-34525: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "891d3fa7b34d2706", "scanner": "scanner-primary", "fingerprint": "a55eb5eb79baaf4a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34525"]}}, {"ruleId": "scanner-bbe36dce6f89c610", "level": "warning", "message": {"text": "CVE-2026-34993: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "e7977c365bb7bb0f", "scanner": "scanner-primary", "fingerprint": "bbe36dce6f89c610", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34993"]}}, {"ruleId": "scanner-a0779ad2938fd4cb", "level": "warning", "message": {"text": "CVE-2026-47265: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "7035166482a6d084", "scanner": "scanner-primary", "fingerprint": "a0779ad2938fd4cb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47265"]}}, {"ruleId": "scanner-ee54dfb8a3084055", "level": "warning", "message": {"text": "CVE-2026-54273: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "af0aae7929b420d3", "scanner": "scanner-primary", "fingerprint": "ee54dfb8a3084055", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54273"]}}, {"ruleId": "scanner-ed5a22bbf7d3a361", "level": "warning", "message": {"text": "CVE-2026-54274: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "7e10ded903752976", "scanner": "scanner-primary", "fingerprint": "ed5a22bbf7d3a361", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54274"]}}, {"ruleId": "scanner-ba1b69aa2916260b", "level": "warning", "message": {"text": "CVE-2026-54276: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "4eb50b27324e7d60", "scanner": "scanner-primary", "fingerprint": "ba1b69aa2916260b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54276"]}}, {"ruleId": "scanner-36bc5c7f59ba3066", "level": "warning", "message": {"text": "CVE-2026-54277: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "76d7edda54afad46", "scanner": "scanner-primary", "fingerprint": "36bc5c7f59ba3066", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54277"]}}, {"ruleId": "scanner-32cfa23890fda16e", "level": "warning", "message": {"text": "CVE-2026-54278: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "aebcc1b43ac4ed5e", "scanner": "scanner-primary", "fingerprint": "32cfa23890fda16e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54278"]}}, {"ruleId": "scanner-201524e473cd2d80", "level": "note", "message": {"text": "CVE-2025-69224: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "89f73e244c521b7c", "scanner": "scanner-primary", "fingerprint": "201524e473cd2d80", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69224"]}}, {"ruleId": "scanner-270aaac517e6a692", "level": "note", "message": {"text": "CVE-2025-69225: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "85173e03b1a4a8e7", "scanner": "scanner-primary", "fingerprint": "270aaac517e6a692", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69225"]}}, {"ruleId": "scanner-66be1bfc0c008807", "level": "note", "message": {"text": "CVE-2025-69226: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "f50705096992590c", "scanner": "scanner-primary", "fingerprint": "66be1bfc0c008807", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69226"]}}, {"ruleId": "scanner-9cdfcb39e89dc313", "level": "note", "message": {"text": "CVE-2025-69230: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "a3f547ef03a491df", "scanner": "scanner-primary", "fingerprint": "9cdfcb39e89dc313", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69230"]}}, {"ruleId": "scanner-0d01e31edad3fb7a", "level": "note", "message": {"text": "CVE-2026-34513: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "c025c7013e2d6258", "scanner": "scanner-primary", "fingerprint": "0d01e31edad3fb7a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34513"]}}, {"ruleId": "scanner-a83079cd9a6bfcfb", "level": "note", "message": {"text": "CVE-2026-34514: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "0e26789ce7cfab41", "scanner": "scanner-primary", "fingerprint": "a83079cd9a6bfcfb", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34514"]}}, {"ruleId": "scanner-bbb1fd4937a36e88", "level": "note", "message": {"text": "CVE-2026-34517: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "8b625e126d63cdd3", "scanner": "scanner-primary", "fingerprint": "bbb1fd4937a36e88", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34517"]}}, {"ruleId": "scanner-550bf94fdacafca1", "level": "note", "message": {"text": "CVE-2026-34518: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "6e4d0d2d8d1bc4f2", "scanner": "scanner-primary", "fingerprint": "550bf94fdacafca1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34518"]}}, {"ruleId": "scanner-57a623b71bc84bed", "level": "note", "message": {"text": "CVE-2026-34519: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "41c7fa5778d7981d", "scanner": "scanner-primary", "fingerprint": "57a623b71bc84bed", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34519"]}}, {"ruleId": "scanner-0cb9c5b798fbebdf", "level": "note", "message": {"text": "CVE-2026-34520: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "9e4aab615a3fb393", "scanner": "scanner-primary", "fingerprint": "0cb9c5b798fbebdf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34520"]}}, {"ruleId": "scanner-edee7ab35ea6a666", "level": "note", "message": {"text": "CVE-2026-50269: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "ecf7a91f3d433ba8", "scanner": "scanner-primary", "fingerprint": "edee7ab35ea6a666", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-50269"]}}, {"ruleId": "scanner-94f5fda98e9896a2", "level": "note", "message": {"text": "CVE-2026-54275: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "151d3b178324b38a", "scanner": "scanner-primary", "fingerprint": "94f5fda98e9896a2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54275"]}}, {"ruleId": "scanner-6d6aa05e64963f13", "level": "note", "message": {"text": "CVE-2026-54279: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "151a621396dd496c", "scanner": "scanner-primary", "fingerprint": "6d6aa05e64963f13", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54279"]}}, {"ruleId": "scanner-99c4c895f15b8a32", "level": "note", "message": {"text": "CVE-2026-54280: aiohttp 3.13.2 \u2014 uv.lock"}, "properties": {"repobilityId": "79293d0b4dfc10d1", "scanner": "scanner-primary", "fingerprint": "99c4c895f15b8a32", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54280"]}}, {"ruleId": "scanner-e0aa9c400e1b6984", "level": "warning", "message": {"text": "CVE-2025-69872: diskcache 5.6.3 \u2014 uv.lock"}, "properties": {"repobilityId": "35f4e51bda7ba150", "scanner": "scanner-primary", "fingerprint": "e0aa9c400e1b6984", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69872"]}}, {"ruleId": "scanner-8281760769efa259", "level": "warning", "message": {"text": "CVE-2025-68146: filelock 3.20.0 \u2014 uv.lock"}, "properties": {"repobilityId": "036b393ef41d0397", "scanner": "scanner-primary", "fingerprint": "8281760769efa259", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68146"]}}, {"ruleId": "scanner-6881f0d9e8fde8bc", "level": "warning", "message": {"text": "CVE-2026-22701: filelock 3.20.0 \u2014 uv.lock"}, "properties": {"repobilityId": "922541f8377a7190", "scanner": "scanner-primary", "fingerprint": "6881f0d9e8fde8bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22701"]}}, {"ruleId": "scanner-206a6aeb11dedddf", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.11 \u2014 uv.lock"}, "properties": {"repobilityId": "c2f0a4d128834c6b", "scanner": "scanner-primary", "fingerprint": "206a6aeb11dedddf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-7377f6edcfb94cd9", "level": "error", "message": {"text": "CVE-2026-0897: keras 3.12.0 \u2014 uv.lock"}, "properties": {"repobilityId": "d36115a0534e3cd7", "scanner": "scanner-primary", "fingerprint": "7377f6edcfb94cd9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0897"]}}, {"ruleId": "scanner-70db4b65fcbd9060", "level": "error", "message": {"text": "CVE-2026-1462: keras 3.12.0 \u2014 uv.lock"}, "properties": {"repobilityId": "6a581475021a63ad", "scanner": "scanner-primary", "fingerprint": "70db4b65fcbd9060", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1462"]}}, {"ruleId": "scanner-947e18581208fd5b", "level": "error", "message": {"text": "CVE-2026-1669: keras 3.12.0 \u2014 uv.lock"}, "properties": {"repobilityId": "59fad5ed785e748d", "scanner": "scanner-primary", "fingerprint": "947e18581208fd5b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1669"]}}, {"ruleId": "scanner-be7e775aaa4eb632", "level": "error", "message": {"text": "GHSA-6v7p-g79w-8964: msgpack 1.1.2 \u2014 uv.lock"}, "properties": {"repobilityId": "4e2920f6ee268cb0", "scanner": "scanner-primary", "fingerprint": "be7e775aaa4eb632", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-6v7p-g79w-8964"]}}, {"ruleId": "scanner-9c965c7c648447d6", "level": "error", "message": {"text": "CVE-2026-25990: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "8b305f86507315cf", "scanner": "scanner-primary", "fingerprint": "9c965c7c648447d6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25990"]}}, {"ruleId": "scanner-c196fd55a04f419d", "level": "error", "message": {"text": "CVE-2026-40192: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "17bb3e9b7f9a6514", "scanner": "scanner-primary", "fingerprint": "c196fd55a04f419d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-0928fd92486590de", "level": "error", "message": {"text": "CVE-2026-42311: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "c3ecdb07a2114f54", "scanner": "scanner-primary", "fingerprint": "0928fd92486590de", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-1fcbf3b09a9ca431", "level": "error", "message": {"text": "CVE-2026-54058: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "ad6b9031837af19d", "scanner": "scanner-primary", "fingerprint": "1fcbf3b09a9ca431", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-f4cce00c99ee16f6", "level": "error", "message": {"text": "CVE-2026-54059: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "4fd6401261d7b673", "scanner": "scanner-primary", "fingerprint": "f4cce00c99ee16f6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-0392549ef1a953b5", "level": "error", "message": {"text": "CVE-2026-54060: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "460c3dd8de6beb2a", "scanner": "scanner-primary", "fingerprint": "0392549ef1a953b5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-4d98f7c7c31d4e37", "level": "error", "message": {"text": "CVE-2026-55379: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "41cc2c5cfa0ab3e7", "scanner": "scanner-primary", "fingerprint": "4d98f7c7c31d4e37", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-e2741239de2fb938", "level": "error", "message": {"text": "CVE-2026-55380: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "f90615a9989f57bc", "scanner": "scanner-primary", "fingerprint": "e2741239de2fb938", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-9cf4d8884e4632da", "level": "error", "message": {"text": "CVE-2026-59197: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "b4fa5d22b574d8f3", "scanner": "scanner-primary", "fingerprint": "9cf4d8884e4632da", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-67d671343dc8c196", "level": "error", "message": {"text": "CVE-2026-59199: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "1c3986517b685ff4", "scanner": "scanner-primary", "fingerprint": "67d671343dc8c196", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-81b80a980c1cae63", "level": "error", "message": {"text": "CVE-2026-59200: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "278253220173941f", "scanner": "scanner-primary", "fingerprint": "81b80a980c1cae63", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-6ebf31894255f500", "level": "error", "message": {"text": "CVE-2026-59204: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "ad08bb4154b8a7b2", "scanner": "scanner-primary", "fingerprint": "6ebf31894255f500", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-4e1b552b1305a526", "level": "error", "message": {"text": "CVE-2026-59205: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "cc9b1626466d8587", "scanner": "scanner-primary", "fingerprint": "4e1b552b1305a526", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-4a31f4a1decdc56c", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "1792d2d9e870c1d3", "scanner": "scanner-primary", "fingerprint": "4a31f4a1decdc56c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-b08ea9c0a9ceae2d", "level": "warning", "message": {"text": "CVE-2026-42309: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "0bdeb519d4de6638", "scanner": "scanner-primary", "fingerprint": "b08ea9c0a9ceae2d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42309"]}}, {"ruleId": "scanner-0ad096488c39fdc1", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "4b1952d1b96a5fa0", "scanner": "scanner-primary", "fingerprint": "0ad096488c39fdc1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-0f3a82cb2e3eb519", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "d0d151cc4785c963", "scanner": "scanner-primary", "fingerprint": "0f3a82cb2e3eb519", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-b33e6336231cd3ff", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "4b734d961778b7aa", "scanner": "scanner-primary", "fingerprint": "b33e6336231cd3ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-e0afd92c4d29ae48", "level": "warning", "message": {"text": "CVE-2026-59203: pillow 12.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "23f54ff1326a45d7", "scanner": "scanner-primary", "fingerprint": "e0afd92c4d29ae48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59203"]}}, {"ruleId": "scanner-e5568545505b9756", "level": "error", "message": {"text": "CVE-2026-0994: protobuf 6.33.1 \u2014 uv.lock"}, "properties": {"repobilityId": "6a910a7bc0ac695f", "scanner": "scanner-primary", "fingerprint": "e5568545505b9756", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0994"]}}, {"ruleId": "scanner-8a68cdbf221d82b2", "level": "error", "message": {"text": "CVE-2026-25087: pyarrow 22.0.0 \u2014 uv.lock"}, "properties": {"repobilityId": "62a5e5f986c14ee0", "scanner": "scanner-primary", "fingerprint": "8a68cdbf221d82b2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25087"]}}, {"ruleId": "scanner-a66a46b30aafdf4e", "level": "error", "message": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "6b070504fcdbd211", "scanner": "scanner-primary", "fingerprint": "a66a46b30aafdf4e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23490"]}}, {"ruleId": "scanner-eaf386c6a405e5a9", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "6c9ab345c7ba843c", "scanner": "scanner-primary", "fingerprint": "eaf386c6a405e5a9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-3b16f1d147b41ab9", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "01feb8e00c6b8d6d", "scanner": "scanner-primary", "fingerprint": "3b16f1d147b41ab9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-f56dfa97d69c0517", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "f14e1a039e252f5b", "scanner": "scanner-primary", "fingerprint": "f56dfa97d69c0517", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-0da8a15114591082", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock"}, "properties": {"repobilityId": "f9fcbb5336951446", "scanner": "scanner-primary", "fingerprint": "0da8a15114591082", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-b47aa9185ac1b713", "level": "warning", "message": {"text": "CVE-2025-71176: pytest 9.0.1 \u2014 uv.lock"}, "properties": {"repobilityId": "a7eb384608a8d52c", "scanner": "scanner-primary", "fingerprint": "b47aa9185ac1b713", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-71176"]}}, {"ruleId": "scanner-f0bc6a832539e0bf", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock"}, "properties": {"repobilityId": "b5480ea7888fdcde", "scanner": "scanner-primary", "fingerprint": "f0bc6a832539e0bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-f97e28c76c35d3d4", "level": "warning", "message": {"text": "CVE-2026-59890: setuptools 80.9.0 \u2014 uv.lock"}, "properties": {"repobilityId": "e9190b412dfee1c0", "scanner": "scanner-primary", "fingerprint": "f97e28c76c35d3d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59890"]}}, {"ruleId": "scanner-d54924d203c3ae9d", "level": "warning", "message": {"text": "CVE-2025-2999: torch 2.9.0 \u2014 uv.lock"}, "properties": {"repobilityId": "35464be5c78537d9", "scanner": "scanner-primary", "fingerprint": "d54924d203c3ae9d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-2999"]}}, {"ruleId": "scanner-af2374746d25de68", "level": "note", "message": {"text": "CVE-2025-3000: torch 2.9.0 \u2014 uv.lock"}, "properties": {"repobilityId": "bffa8b22ac5138b3", "scanner": "scanner-primary", "fingerprint": "af2374746d25de68", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3000"]}}, {"ruleId": "scanner-17dde6ce6efaad6b", "level": "note", "message": {"text": "CVE-2025-3001: torch 2.9.0 \u2014 uv.lock"}, "properties": {"repobilityId": "16c1678337dfb8ff", "scanner": "scanner-primary", "fingerprint": "17dde6ce6efaad6b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3001"]}}, {"ruleId": "scanner-4ddb55eb11841979", "level": "error", "message": {"text": "CVE-2026-4372: transformers 4.57.1 \u2014 uv.lock"}, "properties": {"repobilityId": "f36ca49f12aa5a15", "scanner": "scanner-primary", "fingerprint": "4ddb55eb11841979", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4372"]}}, {"ruleId": "scanner-1a23dbbc424f0c72", "level": "error", "message": {"text": "CVE-2026-5241: transformers 4.57.1 \u2014 uv.lock"}, "properties": {"repobilityId": "0847e515b0b8498a", "scanner": "scanner-primary", "fingerprint": "1a23dbbc424f0c72", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5241"]}}, {"ruleId": "scanner-7b9bd2ec862f0e86", "level": "warning", "message": {"text": "CVE-2026-1839: transformers 4.57.1 \u2014 uv.lock"}, "properties": {"repobilityId": "94f283730a698165", "scanner": "scanner-primary", "fingerprint": "7b9bd2ec862f0e86", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1839"]}}, {"ruleId": "scanner-5ce2e929f54e2a70", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "dcb7e0bb7988e04d", "scanner": "scanner-primary", "fingerprint": "5ce2e929f54e2a70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-b32d2265f744fa8b", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "0c097a3351bee8fd", "scanner": "scanner-primary", "fingerprint": "b32d2265f744fa8b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-e01e826fca9ae59b", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "2c59e72d5030b432", "scanner": "scanner-primary", "fingerprint": "e01e826fca9ae59b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-79d12b66c3169372", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "3621668d4ee670ac", "scanner": "scanner-primary", "fingerprint": "79d12b66c3169372", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-8ff150d8f9eed9fa", "level": "warning", "message": {"text": "CVE-2026-22702: virtualenv 20.35.4 \u2014 uv.lock"}, "properties": {"repobilityId": "02ba988ad50ab148", "scanner": "scanner-primary", "fingerprint": "8ff150d8f9eed9fa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22702"]}}, {"ruleId": "scanner-9ee0c7ae87775871", "level": "warning", "message": {"text": "CVE-2025-66221: werkzeug 3.1.3 \u2014 uv.lock"}, "properties": {"repobilityId": "81a5ffa2d7d09554", "scanner": "scanner-primary", "fingerprint": "9ee0c7ae87775871", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66221"]}}, {"ruleId": "scanner-0eb732a83b553b3d", "level": "warning", "message": {"text": "CVE-2026-21860: werkzeug 3.1.3 \u2014 uv.lock"}, "properties": {"repobilityId": "854e5d82638097bd", "scanner": "scanner-primary", "fingerprint": "0eb732a83b553b3d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21860"]}}, {"ruleId": "scanner-07d52e44376aa875", "level": "warning", "message": {"text": "CVE-2026-27199: werkzeug 3.1.3 \u2014 uv.lock"}, "properties": {"repobilityId": "fbc1059e030aace8", "scanner": "scanner-primary", "fingerprint": "07d52e44376aa875", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27199"]}}, {"ruleId": "scanner-eb8981ac7565d9fa", "level": "error", "message": {"text": "CVE-2026-24049: wheel 0.45.1 \u2014 uv.lock"}, "properties": {"repobilityId": "4310e28d5dec0b74", "scanner": "scanner-primary", "fingerprint": "eb8981ac7565d9fa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24049"]}}, {"ruleId": "scanner-ffb49f99e2501401", "level": "error", "message": {"text": "CVE-2026-25048: xgrammar 0.1.27 \u2014 uv.lock"}, "properties": {"repobilityId": "fc34fd56baedb6df", "scanner": "scanner-primary", "fingerprint": "ffb49f99e2501401", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25048"]}}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-0ed72a17da887dd6", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "ece85a89eb9d5669", "scanner": "scanner-primary", "fingerprint": "0ed72a17da887dd6", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy_documentation.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c6527446b73129cf", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "5cfe6111b4aadbeb", "scanner": "scanner-primary", "fingerprint": "c6527446b73129cf", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish_documentation.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "20593f4c03c7cc60", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "84073fb7aa7fa475", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-9b29c6102daa67e3", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/models/test_provider_exceptions.py:187"}, "properties": {"repobilityId": "b1e6e9abd41829c5", "scanner": "scanner-primary", "fingerprint": "9b29c6102daa67e3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0b103e666a9255fa", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 examples/react.py:47"}, "properties": {"repobilityId": "ed7b0a5ec90ce8e2", "scanner": "scanner-primary", "fingerprint": "0b103e666a9255fa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-aadb3c6adec7e21c", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/outlines/templates.py:332"}, "properties": {"repobilityId": "0ad6fe8541c902e1", "scanner": "scanner-primary", "fingerprint": "aadb3c6adec7e21c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7239f3b39b14a545", "level": "note", "message": {"text": "Stub function `get_device` (body is just `pass`/`return`) \u2014 src/outlines/processors/tensor_adapters/numpy.py:35"}, "properties": {"repobilityId": "8e0ec11c98119f6b", "scanner": "scanner-primary", "fingerprint": "7239f3b39b14a545", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-182c43abfa3ff74b", "level": "note", "message": {"text": "Stub function `get_device` (body is just `pass`/`return`) \u2014 src/outlines/processors/tensor_adapters/mlx.py:45"}, "properties": {"repobilityId": "4617f76ec812cfa2", "scanner": "scanner-primary", "fingerprint": "182c43abfa3ff74b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "ff741624ed5aa0cb", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "6156630f7dc9fdd6", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-380b7cb95b387b9c", "level": "note", "message": {"text": "Near-duplicate function bodies in 11 places"}, "properties": {"repobilityId": "f24d05776ea28608", "scanner": "scanner-primary", "fingerprint": "380b7cb95b387b9c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-454bb594c55998a9", "level": "warning", "message": {"text": "Vulnerable dependency diskcache 5.6.3: GHSA-w8v5-vhqr-4h9v"}, "properties": {"repobilityId": "f272ec4bafdd1a67", "scanner": "scanner-primary", "fingerprint": "454bb594c55998a9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w8v5-vhqr-4h9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-62c4287e167b0d2d", "level": "warning", "message": {"text": "Vulnerable dependency diskcache 5.6.3: PYSEC-2026-2447"}, "properties": {"repobilityId": "dda0140916acf781", "scanner": "scanner-primary", "fingerprint": "62c4287e167b0d2d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2447"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b2234d8706200df0", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-45hq-cxwh-f6vc"}, "properties": {"repobilityId": "6d3837cd04124a88", "scanner": "scanner-primary", "fingerprint": "b2234d8706200df0", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-45hq-cxwh-f6vc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb77fb9871b23298", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-4x4j-2g7c-83w6"}, "properties": {"repobilityId": "fa30361ecb15a0d7", "scanner": "scanner-primary", "fingerprint": "eb77fb9871b23298", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4x4j-2g7c-83w6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-879f300e6812613f", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-5x94-69rx-g8h2"}, "properties": {"repobilityId": "47d85bb511032ef6", "scanner": "scanner-primary", "fingerprint": "879f300e6812613f", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5x94-69rx-g8h2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c2bee2f22beac5e", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-5xmw-vc9v-4wf2"}, "properties": {"repobilityId": "080870793e6d6964", "scanner": "scanner-primary", "fingerprint": "3c2bee2f22beac5e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5xmw-vc9v-4wf2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0435fea082da18b9", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-62p4-gmf7-7g93"}, "properties": {"repobilityId": "15c2cd48d32f9a51", "scanner": "scanner-primary", "fingerprint": "0435fea082da18b9", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-62p4-gmf7-7g93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-724d6b29c2511ce7", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-6r8x-57c9-28j4"}, "properties": {"repobilityId": "e819a7822221f0fc", "scanner": "scanner-primary", "fingerprint": "724d6b29c2511ce7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6r8x-57c9-28j4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e1d9694a3f09bc34", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-8v84-f9pq-wr9x"}, "properties": {"repobilityId": "defbbb9f6ee36665", "scanner": "scanner-primary", "fingerprint": "e1d9694a3f09bc34", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8v84-f9pq-wr9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-660cd5fe4c56ed91", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-9hw9-ch79-4vh6"}, "properties": {"repobilityId": "74aab7eb26395b21", "scanner": "scanner-primary", "fingerprint": "660cd5fe4c56ed91", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9hw9-ch79-4vh6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ad047b7af1d9dc5", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-cfh3-3jmp-rvhc"}, "properties": {"repobilityId": "bde62b681ef93db7", "scanner": "scanner-primary", "fingerprint": "0ad047b7af1d9dc5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-cfh3-3jmp-rvhc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-18e69d1d468f1e8a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-fj7v-r99m-22gq"}, "properties": {"repobilityId": "47a5df834fff55ce", "scanner": "scanner-primary", "fingerprint": "18e69d1d468f1e8a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fj7v-r99m-22gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7e0823373d260e38", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-jjj6-mw9f-p565"}, "properties": {"repobilityId": "0793d94e90f7014b", "scanner": "scanner-primary", "fingerprint": "7e0823373d260e38", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jjj6-mw9f-p565"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-713beded503cb483", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-pg7v-jwj7-p798"}, "properties": {"repobilityId": "1e73e0a6857e1689", "scanner": "scanner-primary", "fingerprint": "713beded503cb483", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pg7v-jwj7-p798"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ecc356499f7b4d49", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-phj9-mv4w-65pm"}, "properties": {"repobilityId": "94e5be1dbb599ec3", "scanner": "scanner-primary", "fingerprint": "ecc356499f7b4d49", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-phj9-mv4w-65pm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9bb9b826e9656bb5", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-pwv6-vv43-88gr"}, "properties": {"repobilityId": "6104dfb6af3023a8", "scanner": "scanner-primary", "fingerprint": "9bb9b826e9656bb5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pwv6-vv43-88gr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30f99617ddce4271", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-r73j-pqj5-w3x7"}, "properties": {"repobilityId": "07134491bfd3ee65", "scanner": "scanner-primary", "fingerprint": "30f99617ddce4271", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r73j-pqj5-w3x7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58d89c4cb8b58e24", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-vjc4-5qp5-m44j"}, "properties": {"repobilityId": "f3a5ebac0a927c77", "scanner": "scanner-primary", "fingerprint": "58d89c4cb8b58e24", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vjc4-5qp5-m44j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-449b54de0838e577", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-whj4-6x5x-4v2j"}, "properties": {"repobilityId": "ad5da25ae8e561d3", "scanner": "scanner-primary", "fingerprint": "449b54de0838e577", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-whj4-6x5x-4v2j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f6668a6db53da45", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-wjx4-4jcj-g98j"}, "properties": {"repobilityId": "0787cbfa03dbb14f", "scanner": "scanner-primary", "fingerprint": "1f6668a6db53da45", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wjx4-4jcj-g98j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-681c056e31cdd578", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: GHSA-xj96-63gp-2gmr"}, "properties": {"repobilityId": "bbc5ab7d10945d63", "scanner": "scanner-primary", "fingerprint": "681c056e31cdd578", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xj96-63gp-2gmr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-caabfcd306e461cc", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-165"}, "properties": {"repobilityId": "86a1f43ca9bf1458", "scanner": "scanner-primary", "fingerprint": "caabfcd306e461cc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-165"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b47d979db8a7de5", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2249"}, "properties": {"repobilityId": "56317010d3f0a920", "scanner": "scanner-primary", "fingerprint": "6b47d979db8a7de5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2249"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e1d439870761e64", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2250"}, "properties": {"repobilityId": "b6dc65834de27347", "scanner": "scanner-primary", "fingerprint": "2e1d439870761e64", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2250"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2bb25340b5bafbe0", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2252"}, "properties": {"repobilityId": "ee8339d866f54f1d", "scanner": "scanner-primary", "fingerprint": "2bb25340b5bafbe0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2252"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-220ff3525bb6e774", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2253"}, "properties": {"repobilityId": "33bf364d76f06ca6", "scanner": "scanner-primary", "fingerprint": "220ff3525bb6e774", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2253"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76997a6562028410", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2256"}, "properties": {"repobilityId": "aeceaa16d23083a1", "scanner": "scanner-primary", "fingerprint": "76997a6562028410", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2256"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cc0edbaf1effcfc3", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-2874"}, "properties": {"repobilityId": "b88373f490ab7664", "scanner": "scanner-primary", "fingerprint": "cc0edbaf1effcfc3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2874"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-724cb91666a357a2", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3451"}, "properties": {"repobilityId": "2f46077676a99ce6", "scanner": "scanner-primary", "fingerprint": "724cb91666a357a2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3451"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b7413a251bee65b6", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3452"}, "properties": {"repobilityId": "f196f9cf5757c773", "scanner": "scanner-primary", "fingerprint": "b7413a251bee65b6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3452"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-08a775c3c1cb84c8", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3453"}, "properties": {"repobilityId": "68ca7752b2087bde", "scanner": "scanner-primary", "fingerprint": "08a775c3c1cb84c8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3453"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0f9858210bf81be", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.0.0: PYSEC-2026-3454"}, "properties": {"repobilityId": "a3c4acd80a01d9e9", "scanner": "scanner-primary", "fingerprint": "a0f9858210bf81be", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3454"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86e90a44c46470c6", "level": "warning", "message": {"text": "Vulnerable dependency pytest 9.0.1: GHSA-6w46-j5rx-g56g"}, "properties": {"repobilityId": "ac3d94e203e8dc28", "scanner": "scanner-primary", "fingerprint": "86e90a44c46470c6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6w46-j5rx-g56g", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-66b76c887f6fe91f", "level": "warning", "message": {"text": "Vulnerable dependency pytest 9.0.1: PYSEC-2026-1845"}, "properties": {"repobilityId": "a56d59bf9d000a7c", "scanner": "scanner-primary", "fingerprint": "66b76c887f6fe91f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1845", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8957f21465289c5d", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": "5a83342b2ace364f", "scanner": "scanner-primary", "fingerprint": "8957f21465289c5d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gc5v-m9x4-r6x2", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be4852e49573b162", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275"}, "properties": {"repobilityId": "9ca627556ae0371e", "scanner": "scanner-primary", "fingerprint": "be4852e49573b162", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2275", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4fbe3d554af2f9fd", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 80.9.0: GHSA-h35f-9h28-mq5c"}, "properties": {"repobilityId": "14f64c68863e4b70", "scanner": "scanner-primary", "fingerprint": "4fbe3d554af2f9fd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h35f-9h28-mq5c", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a00f58b07f3bd972", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 80.9.0: PYSEC-2026-3447"}, "properties": {"repobilityId": "71c9d8c0d47dedd0", "scanner": "scanner-primary", "fingerprint": "a00f58b07f3bd972", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3447", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e29b64e3a3e2d57", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.0: GHSA-qfhq-4f3w-5fph"}, "properties": {"repobilityId": "c3586de824b887da", "scanner": "scanner-primary", "fingerprint": "6e29b64e3a3e2d57", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qfhq-4f3w-5fph", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-955ab8685f1453bc", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.0: GHSA-rrmf-rvhw-rf47"}, "properties": {"repobilityId": "d606b05030c920fe", "scanner": "scanner-primary", "fingerprint": "955ab8685f1453bc", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rrmf-rvhw-rf47", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-39e93bc03b60b645", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.0: GHSA-vgrw-7cvw-pwgx"}, "properties": {"repobilityId": "a1b7ebb8f166ac8a", "scanner": "scanner-primary", "fingerprint": "39e93bc03b60b645", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vgrw-7cvw-pwgx", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-33df912565fbd4d3", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.0: PYSEC-2026-139"}, "properties": {"repobilityId": "237cd01d16a35589", "scanner": "scanner-primary", "fingerprint": "33df912565fbd4d3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-139", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65095b6697e0e22f", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.0: PYSEC-2026-2286"}, "properties": {"repobilityId": "bc6bfa59312cb851", "scanner": "scanner-primary", "fingerprint": "65095b6697e0e22f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2286", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f87a9cfc89873592", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.57.1: GHSA-29pf-2h5f-8g72"}, "properties": {"repobilityId": "592ce5843da47b29", "scanner": "scanner-primary", "fingerprint": "f87a9cfc89873592", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-29pf-2h5f-8g72"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6dc3733717193612", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.57.1: GHSA-69w3-r845-3855"}, "properties": {"repobilityId": "732a7be69aba7e9e", "scanner": "scanner-primary", "fingerprint": "6dc3733717193612", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69w3-r845-3855"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c63e23ee4c3ea4f", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.57.1: GHSA-fgcw-684q-jj6r"}, "properties": {"repobilityId": "afb0254103329d00", "scanner": "scanner-primary", "fingerprint": "9c63e23ee4c3ea4f", "layer": "dependencies", "severity": "critical", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fgcw-684q-jj6r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5028ff324e4ef715", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.57.1: PYSEC-2025-217"}, "properties": {"repobilityId": "5b721d30c59b5d44", "scanner": "scanner-primary", "fingerprint": "5028ff324e4ef715", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-217"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0b2e23509d770c38", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.57.1: PYSEC-2025-218"}, "properties": {"repobilityId": "cee6a2a49d350fb7", "scanner": "scanner-primary", "fingerprint": "0b2e23509d770c38", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-218"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e5c35098055b5f3", "level": "warning", "message": {"text": "Vulnerable dependency xgrammar 0.1.27: GHSA-7rgv-gqhr-fxg3"}, "properties": {"repobilityId": "8ee6aa177b94d3bd", "scanner": "scanner-primary", "fingerprint": "6e5c35098055b5f3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7rgv-gqhr-fxg3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b7a93544dfebbb63", "level": "warning", "message": {"text": "Vulnerable dependency xgrammar 0.1.27: PYSEC-2026-2322"}, "properties": {"repobilityId": "7e2657e0756efc2b", "scanner": "scanner-primary", "fingerprint": "b7a93544dfebbb63", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2322", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-60b35af4940466df", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-29pf-2h5f-8g72"}, "properties": {"repobilityId": "db63e4d3f9d74a9e", "scanner": "scanner-primary", "fingerprint": "60b35af4940466df", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-29pf-2h5f-8g72"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81f6537a3a07e248", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-37mw-44qp-f5jm"}, "properties": {"repobilityId": "ac31c7954ea61bc2", "scanner": "scanner-primary", "fingerprint": "81f6537a3a07e248", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-37mw-44qp-f5jm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f981f98c612e913", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-4w7r-h757-3r74"}, "properties": {"repobilityId": "051028b95b9d07c5", "scanner": "scanner-primary", "fingerprint": "5f981f98c612e913", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4w7r-h757-3r74"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-64219c906f4fa365", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-59p9-h35m-wg4g"}, "properties": {"repobilityId": "2309f40c5797caf0", "scanner": "scanner-primary", "fingerprint": "64219c906f4fa365", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-59p9-h35m-wg4g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3fc49f27141b3a8b", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-69w3-r845-3855"}, "properties": {"repobilityId": "27c31cb3866d94a8", "scanner": "scanner-primary", "fingerprint": "3fc49f27141b3a8b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-69w3-r845-3855"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f97c5a1f0c1f174", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-6rvg-6v2m-4j46"}, "properties": {"repobilityId": "7f854ff2b0766114", "scanner": "scanner-primary", "fingerprint": "0f97c5a1f0c1f174", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6rvg-6v2m-4j46"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9814c09e7771b0f", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-9356-575x-2w9m"}, "properties": {"repobilityId": "e4b26a44988a8a4d", "scanner": "scanner-primary", "fingerprint": "b9814c09e7771b0f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9356-575x-2w9m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e547164f571bf87", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-fgcw-684q-jj6r"}, "properties": {"repobilityId": "48d655e301bda500", "scanner": "scanner-primary", "fingerprint": "8e547164f571bf87", "layer": "dependencies", "severity": "critical", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fgcw-684q-jj6r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86d5a4f2c9fa7920", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-fpwr-67px-3qhx"}, "properties": {"repobilityId": "a9330b785ce33d8d", "scanner": "scanner-primary", "fingerprint": "86d5a4f2c9fa7920", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fpwr-67px-3qhx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dd3c12685c306887", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-hxxf-235m-72v3"}, "properties": {"repobilityId": "d9546cde0f1193a0", "scanner": "scanner-primary", "fingerprint": "dd3c12685c306887", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hxxf-235m-72v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-768cb22612581c8b", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-jjph-296x-mrcr"}, "properties": {"repobilityId": "c0f2c1acf287e366", "scanner": "scanner-primary", "fingerprint": "768cb22612581c8b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jjph-296x-mrcr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4e411af040f6e2cc", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-phhr-52qp-3mj4"}, "properties": {"repobilityId": "e5be128dc2fcad6d", "scanner": "scanner-primary", "fingerprint": "4e411af040f6e2cc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-phhr-52qp-3mj4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8fb5d62388a73db1", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-q2wp-rjmx-x6x9"}, "properties": {"repobilityId": "24ff73910a4832ef", "scanner": "scanner-primary", "fingerprint": "8fb5d62388a73db1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q2wp-rjmx-x6x9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f600ab3bd32b812", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-qq3j-4f4f-9583"}, "properties": {"repobilityId": "333c657c8eff98a1", "scanner": "scanner-primary", "fingerprint": "2f600ab3bd32b812", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qq3j-4f4f-9583"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3a0c0ecd8e8912c", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-qxrp-vhvm-j765"}, "properties": {"repobilityId": "670bff5870e823eb", "scanner": "scanner-primary", "fingerprint": "c3a0c0ecd8e8912c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qxrp-vhvm-j765"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-33e017ee26ecf658", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-rcv9-qm8p-9p6j"}, "properties": {"repobilityId": "b4db81588a6cced3", "scanner": "scanner-primary", "fingerprint": "33e017ee26ecf658", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rcv9-qm8p-9p6j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ade649933827b025", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: GHSA-wrfc-pvp9-mr9g"}, "properties": {"repobilityId": "e6b7cf1206f1baf7", "scanner": "scanner-primary", "fingerprint": "ade649933827b025", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wrfc-pvp9-mr9g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b85ccead2217f05", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-227"}, "properties": {"repobilityId": "0fc81183136f2853", "scanner": "scanner-primary", "fingerprint": "3b85ccead2217f05", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2024-227"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5492f8157b75fe15", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-228"}, "properties": {"repobilityId": "0d663ef46bb5b4fa", "scanner": "scanner-primary", "fingerprint": "5492f8157b75fe15", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2024-228"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d6878964d21d9b1f", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2024-229"}, "properties": {"repobilityId": "454c44148b0e318f", "scanner": "scanner-primary", "fingerprint": "d6878964d21d9b1f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2024-229"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2fccdfec4c2388fc", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-211"}, "properties": {"repobilityId": "1f1fcd46d640f749", "scanner": "scanner-primary", "fingerprint": "2fccdfec4c2388fc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-211"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e9e3c624b1710e25", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-212"}, "properties": {"repobilityId": "13cbd14fa172d912", "scanner": "scanner-primary", "fingerprint": "e9e3c624b1710e25", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-212"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc05e0dc730420f7", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-213"}, "properties": {"repobilityId": "e62ec895d0ebdb16", "scanner": "scanner-primary", "fingerprint": "bc05e0dc730420f7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-213"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b758aa54532710a", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-214"}, "properties": {"repobilityId": "6d04a11a2124e51a", "scanner": "scanner-primary", "fingerprint": "4b758aa54532710a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-214"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a591030e3f8aae87", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-215"}, "properties": {"repobilityId": "202fb1fca122facf", "scanner": "scanner-primary", "fingerprint": "a591030e3f8aae87", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-215"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-37ca66577652059b", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-216"}, "properties": {"repobilityId": "23af7ed100d0d6db", "scanner": "scanner-primary", "fingerprint": "37ca66577652059b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-216"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d43fced2347ecceb", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-217"}, "properties": {"repobilityId": "8ee3671253afc984", "scanner": "scanner-primary", "fingerprint": "d43fced2347ecceb", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-217"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-69afdeb128ddfd8c", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-218"}, "properties": {"repobilityId": "1cdce1790abfd94a", "scanner": "scanner-primary", "fingerprint": "69afdeb128ddfd8c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-218"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8182189c19ffd18b", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2025-40"}, "properties": {"repobilityId": "a021cbe9d87c41a6", "scanner": "scanner-primary", "fingerprint": "8182189c19ffd18b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2025-40"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8cc9f8098b139427", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1981"}, "properties": {"repobilityId": "2732f195f4ffd3f5", "scanner": "scanner-primary", "fingerprint": "8cc9f8098b139427", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1981"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d709da3b1ba0f00a", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1982"}, "properties": {"repobilityId": "a237f15497dae0c6", "scanner": "scanner-primary", "fingerprint": "d709da3b1ba0f00a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1982"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1eef0df1ce296277", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1983"}, "properties": {"repobilityId": "0b196af5dd580e20", "scanner": "scanner-primary", "fingerprint": "1eef0df1ce296277", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1983"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e45d98dea3a0ced", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1984"}, "properties": {"repobilityId": "f20f7e048de23bd2", "scanner": "scanner-primary", "fingerprint": "9e45d98dea3a0ced", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1984"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-67774b4495581432", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1985"}, "properties": {"repobilityId": "4fb3fb1d286826e3", "scanner": "scanner-primary", "fingerprint": "67774b4495581432", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1985"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-719d44a820de1d0a", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1986"}, "properties": {"repobilityId": "9a4f699369af4596", "scanner": "scanner-primary", "fingerprint": "719d44a820de1d0a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1986"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c84a4a1a5590ca0", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1987"}, "properties": {"repobilityId": "cb748ee7250c2bb9", "scanner": "scanner-primary", "fingerprint": "2c84a4a1a5590ca0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1987"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-815768951bedaaf6", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.38.2: PYSEC-2026-1988"}, "properties": {"repobilityId": "d4919fb780f17efa", "scanner": "scanner-primary", "fingerprint": "815768951bedaaf6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1988"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eae7ada9cac371f6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-2fqr-mr3j-6wp8"}, "properties": {"repobilityId": "ebe0b0662ab40cf6", "scanner": "scanner-primary", "fingerprint": "eae7ada9cac371f6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2fqr-mr3j-6wp8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffdebb971b87150e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-2vrm-gr82-f7m5"}, "properties": {"repobilityId": "5ad0351ff4a35151", "scanner": "scanner-primary", "fingerprint": "ffdebb971b87150e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2vrm-gr82-f7m5", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-091453a6655803e6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-3wq7-rqq7-wx6j"}, "properties": {"repobilityId": "8ac7cffb6a98edd3", "scanner": "scanner-primary", "fingerprint": "091453a6655803e6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3wq7-rqq7-wx6j", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e3bbeec4e01e6757", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-4fvr-rgm6-gqmc"}, "properties": {"repobilityId": "2f5b8482d4f9b29d", "scanner": "scanner-primary", "fingerprint": "e3bbeec4e01e6757", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4fvr-rgm6-gqmc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f21ebac622135391", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-4m7w-qmgq-4wj5"}, "properties": {"repobilityId": "80c019f6970da2ae", "scanner": "scanner-primary", "fingerprint": "f21ebac622135391", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4m7w-qmgq-4wj5", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-077933dad46d3093", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-54jq-c3m8-4m76"}, "properties": {"repobilityId": "f5081acbca0470f2", "scanner": "scanner-primary", "fingerprint": "077933dad46d3093", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-54jq-c3m8-4m76", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e9a68d80b7355017", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-63hf-3vf5-4wqf"}, "properties": {"repobilityId": "89b1a0f76e58acca", "scanner": "scanner-primary", "fingerprint": "e9a68d80b7355017", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-63hf-3vf5-4wqf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72a89562bc148031", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-63hw-fmq6-xxg2"}, "properties": {"repobilityId": "dbd27242c79d0639", "scanner": "scanner-primary", "fingerprint": "72a89562bc148031", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-63hw-fmq6-xxg2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-27c26d6cc2433628", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-69f9-5gxw-wvc2"}, "properties": {"repobilityId": "6111b022d01be42b", "scanner": "scanner-primary", "fingerprint": "27c26d6cc2433628", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-69f9-5gxw-wvc2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f887eedc570d3b30", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-6jhg-hg63-jvvf"}, "properties": {"repobilityId": "7925b0b0e13c5bec", "scanner": "scanner-primary", "fingerprint": "f887eedc570d3b30", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6jhg-hg63-jvvf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9adcf7fb40e47a3f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-6mq8-rvhq-8wgg"}, "properties": {"repobilityId": "c20919bcd8331371", "scanner": "scanner-primary", "fingerprint": "9adcf7fb40e47a3f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6mq8-rvhq-8wgg", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-af1cc70cc991275e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-966j-vmvw-g2g9"}, "properties": {"repobilityId": "69b90942bd9a61ce", "scanner": "scanner-primary", "fingerprint": "af1cc70cc991275e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-966j-vmvw-g2g9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf7f2af425fe3a69", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-9x8q-7h8h-wcw9"}, "properties": {"repobilityId": "49746182d27b53ce", "scanner": "scanner-primary", "fingerprint": "bf7f2af425fe3a69", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-9x8q-7h8h-wcw9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7f5d7517036e31ce", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-c427-h43c-vf67"}, "properties": {"repobilityId": "05e1fa96a7665f4c", "scanner": "scanner-primary", "fingerprint": "7f5d7517036e31ce", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c427-h43c-vf67", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-028ea7374734d8f6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-fh55-r93g-j68g"}, "properties": {"repobilityId": "82447c4aba2379b2", "scanner": "scanner-primary", "fingerprint": "028ea7374734d8f6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fh55-r93g-j68g", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f520a0158b23449", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-g3cq-j2xw-wf74"}, "properties": {"repobilityId": "e1b6610401363aa0", "scanner": "scanner-primary", "fingerprint": "4f520a0158b23449", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-g3cq-j2xw-wf74", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-712de8187d5e3a88", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-g84x-mcqj-x9qq"}, "properties": {"repobilityId": "adbe27bafca09ebd", "scanner": "scanner-primary", "fingerprint": "712de8187d5e3a88", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-g84x-mcqj-x9qq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-79d01376606c73d0", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-hcc4-c3v8-rx92"}, "properties": {"repobilityId": "090e52ab24c19a19", "scanner": "scanner-primary", "fingerprint": "79d01376606c73d0", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hcc4-c3v8-rx92", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e28cc8de7cda91c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-hg6j-4rv6-33pg"}, "properties": {"repobilityId": "f8fc801a00e4af23", "scanner": "scanner-primary", "fingerprint": "2e28cc8de7cda91c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hg6j-4rv6-33pg", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-45338a95299b5df8", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-hpj7-wq8m-9hgp"}, "properties": {"repobilityId": "6975d4b7ee662e65", "scanner": "scanner-primary", "fingerprint": "45338a95299b5df8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hpj7-wq8m-9hgp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-37786c667930c3f6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-jg22-mg44-37j8"}, "properties": {"repobilityId": "7c2b9eea214be80c", "scanner": "scanner-primary", "fingerprint": "37786c667930c3f6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jg22-mg44-37j8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97b3e90e9f21932d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-jj3x-wxrx-4x23"}, "properties": {"repobilityId": "846e6d41bd4f879e", "scanner": "scanner-primary", "fingerprint": "97b3e90e9f21932d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jj3x-wxrx-4x23", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1624a8cd3ab59e8b", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-m5qp-6w8w-w647"}, "properties": {"repobilityId": "d89c1850eeab8368", "scanner": "scanner-primary", "fingerprint": "1624a8cd3ab59e8b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-m5qp-6w8w-w647", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-035f474fce230892", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-m6qw-4cw2-hm4m"}, "properties": {"repobilityId": "9dcfaf47a2b03d4f", "scanner": "scanner-primary", "fingerprint": "035f474fce230892", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-m6qw-4cw2-hm4m", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-345a4b4666389d0a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-mqqc-3gqh-h2x8"}, "properties": {"repobilityId": "497bad8c6fc8251f", "scanner": "scanner-primary", "fingerprint": "345a4b4666389d0a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mqqc-3gqh-h2x8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f2c4860a207cc18", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-mwh4-6h8g-pg8w"}, "properties": {"repobilityId": "1972d3ef3a794c53", "scanner": "scanner-primary", "fingerprint": "4f2c4860a207cc18", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mwh4-6h8g-pg8w", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0cec972590d02dd3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-p998-jp59-783m"}, "properties": {"repobilityId": "466f48d194d2208e", "scanner": "scanner-primary", "fingerprint": "0cec972590d02dd3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-p998-jp59-783m", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9fbe8fedce994400", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-w2fm-2cpv-w7v5"}, "properties": {"repobilityId": "32e19f6ae273c90e", "scanner": "scanner-primary", "fingerprint": "9fbe8fedce994400", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w2fm-2cpv-w7v5", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-baaf24460054879a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: GHSA-xcgm-r5h9-7989"}, "properties": {"repobilityId": "5afda133099265e4", "scanner": "scanner-primary", "fingerprint": "baaf24460054879a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xcgm-r5h9-7989", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c5cb834d4f6c6cd", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1099"}, "properties": {"repobilityId": "7e2fa288cb196697", "scanner": "scanner-primary", "fingerprint": "7c5cb834d4f6c6cd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1099", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2eb3862902c2d8a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1100"}, "properties": {"repobilityId": "5e1fceeeb576645e", "scanner": "scanner-primary", "fingerprint": "d2eb3862902c2d8a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1100", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e4498dc7a6c8ec1f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1101"}, "properties": {"repobilityId": "17fc5694c72ca7ec", "scanner": "scanner-primary", "fingerprint": "e4498dc7a6c8ec1f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1101", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9281f6d12abc6e31", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1105"}, "properties": {"repobilityId": "138afeac004cf27e", "scanner": "scanner-primary", "fingerprint": "9281f6d12abc6e31", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1105", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7197a0a1456b8578", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1106"}, "properties": {"repobilityId": "e805ee02fcbf549b", "scanner": "scanner-primary", "fingerprint": "7197a0a1456b8578", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1106", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87513ebf796fdbe7", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1107"}, "properties": {"repobilityId": "eb292cfd68535cb5", "scanner": "scanner-primary", "fingerprint": "87513ebf796fdbe7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1107", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e3a9b01c4b20d4a3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-1109"}, "properties": {"repobilityId": "3087a787123052a1", "scanner": "scanner-primary", "fingerprint": "e3a9b01c4b20d4a3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1109", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-754937e92f9208f9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2094"}, "properties": {"repobilityId": "298d26e4c7ed221a", "scanner": "scanner-primary", "fingerprint": "754937e92f9208f9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2094", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8799c88835f71b4e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2095"}, "properties": {"repobilityId": "6a5a11368b6b10f3", "scanner": "scanner-primary", "fingerprint": "8799c88835f71b4e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2095", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7ecc289f961b6262", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2097"}, "properties": {"repobilityId": "f1db72bad698e7f5", "scanner": "scanner-primary", "fingerprint": "7ecc289f961b6262", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2097", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-541eea135abcd2af", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2098"}, "properties": {"repobilityId": "26460a0830de6607", "scanner": "scanner-primary", "fingerprint": "541eea135abcd2af", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2098", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-547fb63d5ecde297", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2100"}, "properties": {"repobilityId": "bed9a99a4d9cc9e0", "scanner": "scanner-primary", "fingerprint": "547fb63d5ecde297", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2100", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-024dd211dcefc148", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2101"}, "properties": {"repobilityId": "e364f3c853d4e772", "scanner": "scanner-primary", "fingerprint": "024dd211dcefc148", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2101", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3e0ffaafbb1e9ec", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2102"}, "properties": {"repobilityId": "2fe8324e083b097d", "scanner": "scanner-primary", "fingerprint": "c3e0ffaafbb1e9ec", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2102", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58da7510b0829ca0", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2103"}, "properties": {"repobilityId": "0e691b8c1d839f08", "scanner": "scanner-primary", "fingerprint": "58da7510b0829ca0", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2103", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-639ec948ecb97e82", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2104"}, "properties": {"repobilityId": "f67c86f836866010", "scanner": "scanner-primary", "fingerprint": "639ec948ecb97e82", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2104", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d78811ab8ff655d6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2105"}, "properties": {"repobilityId": "ae447a46ed693af1", "scanner": "scanner-primary", "fingerprint": "d78811ab8ff655d6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2105", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92b860ec31ad82ae", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2106"}, "properties": {"repobilityId": "fb959b30b32d0b18", "scanner": "scanner-primary", "fingerprint": "92b860ec31ad82ae", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2106", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b653df191f378ad9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2108"}, "properties": {"repobilityId": "9b24c5f388f9e772", "scanner": "scanner-primary", "fingerprint": "b653df191f378ad9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2108", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47e29690d67c7abe", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2109"}, "properties": {"repobilityId": "ce301661e92b457f", "scanner": "scanner-primary", "fingerprint": "47e29690d67c7abe", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2109", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-14e88ba0f4f88fda", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2110"}, "properties": {"repobilityId": "b53074c4ed25d450", "scanner": "scanner-primary", "fingerprint": "14e88ba0f4f88fda", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2110", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-56d86ab728bdcc91", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2111"}, "properties": {"repobilityId": "3616968f0749e7cb", "scanner": "scanner-primary", "fingerprint": "56d86ab728bdcc91", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2111", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c6f8ea962bb5a94", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.2: PYSEC-2026-2113"}, "properties": {"repobilityId": "189961079baa1d36", "scanner": "scanner-primary", "fingerprint": "9c6f8ea962bb5a94", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2113", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e12ad07bf9e97352", "level": "warning", "message": {"text": "Vulnerable dependency click 8.2.1: PYSEC-2026-2132"}, "properties": {"repobilityId": "0c2a5874a5d89276", "scanner": "scanner-primary", "fingerprint": "e12ad07bf9e97352", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2132", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f8b65b1cea4f40f", "level": "warning", "message": {"text": "Vulnerable dependency filelock 3.20.0: GHSA-qmgc-5h2g-mvrw"}, "properties": {"repobilityId": "a9160ed753d54a9d", "scanner": "scanner-primary", "fingerprint": "0f8b65b1cea4f40f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qmgc-5h2g-mvrw", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a27f36b095d4ce2", "level": "warning", "message": {"text": "Vulnerable dependency filelock 3.20.0: GHSA-w853-jp5j-5j7f"}, "properties": {"repobilityId": "978e04b6ea768576", "scanner": "scanner-primary", "fingerprint": "5a27f36b095d4ce2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w853-jp5j-5j7f", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b07637bfa7516ab9", "level": "warning", "message": {"text": "Vulnerable dependency filelock 3.20.0: PYSEC-2026-1374"}, "properties": {"repobilityId": "71a2bfa30029d009", "scanner": "scanner-primary", "fingerprint": "b07637bfa7516ab9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1374", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dad01c1a900eae48", "level": "warning", "message": {"text": "Vulnerable dependency filelock 3.20.0: PYSEC-2026-1375"}, "properties": {"repobilityId": "1dbc323918e1dabd", "scanner": "scanner-primary", "fingerprint": "dad01c1a900eae48", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1375", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9eb78ac091ef83de", "level": "warning", "message": {"text": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx"}, "properties": {"repobilityId": "fb9a242b2a48123b", "scanner": "scanner-primary", "fingerprint": "9eb78ac091ef83de", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-65pc-fj4g-8rjx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-53908982d0b4fca2", "level": "error", "message": {"text": "Vulnerable dependency keras 3.12.0: GHSA-3m4q-jmj6-r34q"}, "properties": {"repobilityId": "d0107c80c440cbee", "scanner": "scanner-primary", "fingerprint": "53908982d0b4fca2", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3m4q-jmj6-r34q", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b4ab84f115c226d4", "level": "error", "message": {"text": "Vulnerable dependency keras 3.12.0: GHSA-4f3f-g24h-fr8m"}, "properties": {"repobilityId": "6728ec1849b0bf7a", "scanner": "scanner-primary", "fingerprint": "b4ab84f115c226d4", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4f3f-g24h-fr8m", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c5e466c7ddc74087", "level": "warning", "message": {"text": "Vulnerable dependency keras 3.12.0: GHSA-mgx6-5cf9-rr43"}, "properties": {"repobilityId": "880a7cc446b7952f", "scanner": "scanner-primary", "fingerprint": "c5e466c7ddc74087", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mgx6-5cf9-rr43", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c6cda58e2141e680", "level": "warning", "message": {"text": "Vulnerable dependency keras 3.12.0: PYSEC-2026-2324"}, "properties": {"repobilityId": "ea0f1f56295cb8e8", "scanner": "scanner-primary", "fingerprint": "c6cda58e2141e680", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2324", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cce7de344341cace", "level": "warning", "message": {"text": "Vulnerable dependency keras 3.12.0: PYSEC-2026-73"}, "properties": {"repobilityId": "e9c99aa4d36b1797", "scanner": "scanner-primary", "fingerprint": "cce7de344341cace", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-73", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c77c4d1b2675bd17", "level": "warning", "message": {"text": "Vulnerable dependency msgpack 1.1.2: GHSA-6v7p-g79w-8964"}, "properties": {"repobilityId": "4805c7caf4a4f90d", "scanner": "scanner-primary", "fingerprint": "c77c4d1b2675bd17", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6v7p-g79w-8964", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-720e9bb3ab4fbb20", "level": "warning", "message": {"text": "Vulnerable dependency protobuf 6.33.1: GHSA-7gcm-g887-7qv7"}, "properties": {"repobilityId": "bfb68604e81f67bf", "scanner": "scanner-primary", "fingerprint": "720e9bb3ab4fbb20", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7gcm-g887-7qv7", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb57110b590e3e07", "level": "warning", "message": {"text": "Vulnerable dependency protobuf 6.33.1: PYSEC-2026-1805"}, "properties": {"repobilityId": "3ec4cd9a01e90cd1", "scanner": "scanner-primary", "fingerprint": "fb57110b590e3e07", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1805", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bdaac34b4de2d066", "level": "warning", "message": {"text": "Vulnerable dependency pyarrow 22.0.0: GHSA-rgxp-2hwp-jwgg"}, "properties": {"repobilityId": "9f0bb0fea2f125fd", "scanner": "scanner-primary", "fingerprint": "bdaac34b4de2d066", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rgxp-2hwp-jwgg", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-169ad7e54fab5d25", "level": "warning", "message": {"text": "Vulnerable dependency pyarrow 22.0.0: PYSEC-2026-113"}, "properties": {"repobilityId": "4f9ce5d64fe60051", "scanner": "scanner-primary", "fingerprint": "169ad7e54fab5d25", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-113", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-364dc785056399f2", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-63vm-454h-vhhq"}, "properties": {"repobilityId": "9911703c1f6f9206", "scanner": "scanner-primary", "fingerprint": "364dc785056399f2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-63vm-454h-vhhq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f5e54aaea81621a", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-8ppf-4f7h-5ppj"}, "properties": {"repobilityId": "873a8ac7359bf771", "scanner": "scanner-primary", "fingerprint": "1f5e54aaea81621a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8ppf-4f7h-5ppj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ea10d916c48959f", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-hm4w-wwcw-mr6r"}, "properties": {"repobilityId": "6f8dc18ac8a6262e", "scanner": "scanner-primary", "fingerprint": "0ea10d916c48959f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hm4w-wwcw-mr6r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28d657c37832bf9f", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: GHSA-jr27-m4p2-rc6r"}, "properties": {"repobilityId": "0af88eff8d72ff3b", "scanner": "scanner-primary", "fingerprint": "28d657c37832bf9f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jr27-m4p2-rc6r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3bba52511a4f5462", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-1810"}, "properties": {"repobilityId": "a6f92f2047ca4b05", "scanner": "scanner-primary", "fingerprint": "3bba52511a4f5462", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1810", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6870757873e4f752", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-2263"}, "properties": {"repobilityId": "3e295e87c8f50918", "scanner": "scanner-primary", "fingerprint": "6870757873e4f752", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2263", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e134a151ed33c523", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3455"}, "properties": {"repobilityId": "9ae4837eca152517", "scanner": "scanner-primary", "fingerprint": "e134a151ed33c523", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3455", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ece961f56587673", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3456"}, "properties": {"repobilityId": "fc68b67ad6f707ca", "scanner": "scanner-primary", "fingerprint": "0ece961f56587673", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3456", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a7c9d28fb64f89d", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.1: PYSEC-2026-3457"}, "properties": {"repobilityId": "a7e24f54feb6f519", "scanner": "scanner-primary", "fingerprint": "0a7c9d28fb64f89d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3457", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f35e24090839556", "level": "warning", "message": {"text": "Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq"}, "properties": {"repobilityId": "b5634ffa34a95a85", "scanner": "scanner-primary", "fingerprint": "2f35e24090839556", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5239-wwwm-4pmq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff57d7ec3600d392", "level": "error", "message": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-2xpw-w6gg-jr37"}, "properties": {"repobilityId": "4703c730a75cddd8", "scanner": "scanner-primary", "fingerprint": "ff57d7ec3600d392", "layer": "dependencies", "severity": "critical", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2xpw-w6gg-jr37", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3b6909cf7cc1f1c", "level": "error", "message": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-38jv-5279-wg99"}, "properties": {"repobilityId": "463cc5bf725409f0", "scanner": "scanner-primary", "fingerprint": "c3b6909cf7cc1f1c", "layer": "dependencies", "severity": "critical", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-38jv-5279-wg99", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0a64e27a9c3ea75", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-gm62-xv2j-4w53"}, "properties": {"repobilityId": "c1e9e282ddb1162e", "scanner": "scanner-primary", "fingerprint": "b0a64e27a9c3ea75", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gm62-xv2j-4w53", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0b3395f8792655a7", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.5.0: GHSA-qccp-gfcp-xxvc"}, "properties": {"repobilityId": "a16c51b300f83587", "scanner": "scanner-primary", "fingerprint": "0b3395f8792655a7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qccp-gfcp-xxvc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf64d0c2fef2c33e", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.5.0: PYSEC-2026-141"}, "properties": {"repobilityId": "1235a9fbf3c429a2", "scanner": "scanner-primary", "fingerprint": "cf64d0c2fef2c33e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-141", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a17785bbee94419f", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.5.0: PYSEC-2026-1998"}, "properties": {"repobilityId": "67b54462d9b1a111", "scanner": "scanner-primary", "fingerprint": "a17785bbee94419f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1998", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c036f1c93ce7d800", "level": "warning", "message": {"text": "Vulnerable dependency virtualenv 20.35.4: GHSA-597g-3phw-6986"}, "properties": {"repobilityId": "59b2a8728ec2338d", "scanner": "scanner-primary", "fingerprint": "c036f1c93ce7d800", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-597g-3phw-6986", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-46f2064f27a58a3e", "level": "warning", "message": {"text": "Vulnerable dependency virtualenv 20.35.4: PYSEC-2026-2009"}, "properties": {"repobilityId": "23498d6d244e9da4", "scanner": "scanner-primary", "fingerprint": "46f2064f27a58a3e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2009", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-364553bfa1c3729d", "level": "warning", "message": {"text": "Vulnerable dependency werkzeug 3.1.3: GHSA-29vq-49wr-vm6x"}, "properties": {"repobilityId": "1abb7c671bf43a1b", "scanner": "scanner-primary", "fingerprint": "364553bfa1c3729d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-29vq-49wr-vm6x", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fd265773b23790de", "level": "warning", "message": {"text": "Vulnerable dependency werkzeug 3.1.3: GHSA-87hc-h4r5-73f7"}, "properties": {"repobilityId": "ed782309aa204587", "scanner": "scanner-primary", "fingerprint": "fd265773b23790de", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-87hc-h4r5-73f7", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a693300e4d3e2c0a", "level": "warning", "message": {"text": "Vulnerable dependency werkzeug 3.1.3: GHSA-hgf8-39gv-g3f2"}, "properties": {"repobilityId": "fecfce1556355d43", "scanner": "scanner-primary", "fingerprint": "a693300e4d3e2c0a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hgf8-39gv-g3f2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f697d954eabfc57", "level": "warning", "message": {"text": "Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2044"}, "properties": {"repobilityId": "83073f2b19492564", "scanner": "scanner-primary", "fingerprint": "5f697d954eabfc57", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2044", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a392e4fcc405ed0d", "level": "warning", "message": {"text": "Vulnerable dependency werkzeug 3.1.3: PYSEC-2026-2046"}, "properties": {"repobilityId": "dca457f42101bfb8", "scanner": "scanner-primary", "fingerprint": "a392e4fcc405ed0d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2046", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4851d74e368ed96e", "level": "warning", "message": {"text": "Vulnerable dependency wheel 0.45.1: GHSA-8rrh-rw8j-w5fx"}, "properties": {"repobilityId": "43c500545f23446e", "scanner": "scanner-primary", "fingerprint": "4851d74e368ed96e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8rrh-rw8j-w5fx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fdd5e04247a812d8", "level": "warning", "message": {"text": "Vulnerable dependency wheel 0.45.1: PYSEC-2026-2047"}, "properties": {"repobilityId": "4c0678d844db983a", "scanner": "scanner-primary", "fingerprint": "fdd5e04247a812d8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2047", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f0b665aa20127d3", "level": "note", "message": {"text": "Dependency accelerate is a major version behind"}, "properties": {"repobilityId": "221d11a81e8a6fe1", "scanner": "scanner-primary", "fingerprint": "8f0b665aa20127d3", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e06d72b13e6f2d4", "level": "warning", "message": {"text": "Dependency datasets is two or more major versions behind"}, "properties": {"repobilityId": "fcf4e8783f76848e", "scanner": "scanner-primary", "fingerprint": "2e06d72b13e6f2d4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b6e0f8a84512616", "level": "note", "message": {"text": "Dependency outlines is a major version behind"}, "properties": {"repobilityId": "94cdfd839adaa488", "scanner": "scanner-primary", "fingerprint": "4b6e0f8a84512616", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38a60fdad0eca540", "level": "note", "message": {"text": "Dependency transformers is a major version behind"}, "properties": {"repobilityId": "546903d535d6d778", "scanner": "scanner-primary", "fingerprint": "38a60fdad0eca540", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/bentoml/requirements.txt"}, "region": {"startLine": 1}}}]}]}]}