{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:10787","slug":"opencode-10787","gitlabProjectId":10787,"name":"LLM Questionnaire Benchmarking Framework","pathWithNamespace":"uba-ki-lab/llm-questionnaire-benchmarking-framework","description":"Reproducible benchmarking framework for evaluating LLMs using structured multiple-choice and numeric questionnaires","webUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-questionnaire-benchmarking-framework","commitSha":"4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd","commitUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-questionnaire-benchmarking-framework/-/commit/4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd","lastActivityAt":"2026-07-13T00:00:12.759Z","headCommittedAt":"2026-06-28T20:48:20.000Z","tree":{"complete":true,"entryCount":120,"truncated":false},"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"1b55661fee93d4733461df8e9c2b491b9205aac2","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-questionnaire-benchmarking-framework/-/blob/4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd/uv.lock","commitSha":"4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd","contentSha256":"e0cfb7dbb1f83b9adb3c422816068eefba3a17e5146d084022722da579e14760","byteCount":734464,"state":"parsed","componentCount":241}],"resolvedComponentCount":241,"artifactResolvedComponentCount":241,"exactManifestPinCount":0,"packageCount":241,"ecosystems":["pypi"],"aiPackageCount":7,"licenseExpressionCount":26,"unknownLicensePackageCount":3,"advisoryIds":["GHSA-248v-346w-9cwc","GHSA-27jp-wm6q-gp25","GHSA-29pf-2h5f-8g72","GHSA-29vq-49wr-vm6x","GHSA-2c2j-9gv5-cj73","GHSA-2fqr-mr3j-6wp8","GHSA-2g68-c3qc-8985","GHSA-2h4p-vjrc-8xpq","GHSA-2pc9-4j83-qjmr","GHSA-2vrm-gr82-f7m5","GHSA-2xpw-w6gg-jr37","GHSA-3749-ghw9-m3mg","GHSA-37mw-44qp-f5jm","GHSA-38jv-5279-wg99","GHSA-38vq-g6vr-w8wf","GHSA-3c37-wwvx-h642","GHSA-3f6c-7fw2-ppm4","GHSA-3mwp-wvh9-7528","GHSA-3wq7-rqq7-wx6j","GHSA-3ww4-5jv9-j5gm","GHSA-42h5-h8qh-vv9v","GHSA-46r5-x6jq-v8g6","GHSA-48p4-8xcf-vxj5","GHSA-4fvr-rgm6-gqmc","GHSA-4m7w-qmgq-4wj5","GHSA-4qjh-9fv9-r85r","GHSA-4r2x-xpjr-7cvv","GHSA-4w7r-h757-3r74","GHSA-4x5p-f36r-mxxr","GHSA-4xgf-cpjx-pc3j","GHSA-5239-wwwm-4pmq","GHSA-537c-gmf6-5ccf","GHSA-53q9-r3pm-6pq6","GHSA-54jq-c3m8-4m76","GHSA-597g-3phw-6986","GHSA-59g5-xgcq-4qw3","GHSA-59p9-h35m-wg4g","GHSA-5cmr-4px5-23pc","GHSA-5h2m-4q8j-pqpj","GHSA-5jv2-g5wq-cmr4","GHSA-5qmp-p3c4-72qj","GHSA-5rjg-fvgr-3xxf","GHSA-5rvq-cxj2-64vf","GHSA-5xmw-vc9v-4wf2","GHSA-63hf-3vf5-4wqf","GHSA-63hw-fmq6-xxg2","GHSA-63vm-454h-vhhq","GHSA-65h7-c7c4-mghx","GHSA-65pc-fj4g-8rjx","GHSA-68rp-wp8r-4726","GHSA-69f9-5gxw-wvc2","GHSA-69j4-grxj-j64p","GHSA-69w3-r845-3855","GHSA-6c4r-fmh3-7rh8","GHSA-6fvq-23cw-5628","GHSA-6jhg-hg63-jvvf","GHSA-6jv3-5f52-599m","GHSA-6mq8-rvhq-8wgg","GHSA-6pr9-rp53-2pmc","GHSA-6qc9-v4r8-22xg","GHSA-6rvg-6v2m-4j46","GHSA-6v7p-g79w-8964","GHSA-6wgj-66m2-xxp2","GHSA-7432-952r-cw78","GHSA-7545-fcxq-7j24","GHSA-75cm-x2w3-8mgf","GHSA-768j-98cg-p3fv","GHSA-7972-pg2x-xr59","GHSA-79v4-65xg-pq4g","GHSA-7f5h-v6xp-fcq8","GHSA-7gcm-g887-7qv7","GHSA-7h4p-rffg-7823","GHSA-7qhf-v65m-g5f3","GHSA-7rgv-gqhr-fxg3","GHSA-82w8-qh3p-5jfq","GHSA-86qp-5c8j-p5mr","GHSA-87hc-h4r5-73f7","GHSA-887c-mr87-cxwp","GHSA-8c7q-86fq-vvmh","GHSA-8fr4-5q9j-m8gm","GHSA-8jr5-v98p-w75m","GHSA-8qvm-5x2c-j2w7","GHSA-9356-575x-2w9m","GHSA-94f4-hr76-p5j6","GHSA-9548-qrrj-x5pj","GHSA-966j-vmvw-g2g9","GHSA-98f3-hwg4-4rf7","GHSA-9h52-p55h-vw2f","GHSA-9hcf-v7m4-6m2j","GHSA-9hjg-9r4m-mvj7","GHSA-9pcc-gvx5-r5wm","GHSA-9wx4-h78v-vm56","GHSA-9x8q-7h8h-wcw9","GHSA-c2jp-c369-7pvx","GHSA-c427-h43c-vf67","GHSA-c65p-x677-fgj6","GHSA-c678-jfcj-6jmf","GHSA-cfh3-3jmp-rvhc","GHSA-cpwx-vrp4-4pq7","GHSA-cx63-2mw6-8hw5","GHSA-f2m9-wcf4-cwwx","GHSA-f4hp-rmr7-r7v8","GHSA-f96h-pmfr-66vw","GHSA-f9vj-2wh5-fj8j","GHSA-fg6f-75jq-6523","GHSA-fgcw-684q-jj6r","GHSA-fh55-r93g-j68g","GHSA-fh64-r2vc-xvhr","GHSA-fhff-qmm8-h2fp","GHSA-fpwr-67px-3qhx","GHSA-g35p-px32-whv6","GHSA-g3cq-j2xw-wf74","GHSA-g6pg-52vf-843h","GHSA-g7f3-828f-7h7m","GHSA-g7vv-2v7x-gj9p","GHSA-g84x-mcqj-x9qq","GHSA-gc5v-m9x4-r6x2","GHSA-gm62-xv2j-4w53","GHSA-gmj6-6f8f-6699","GHSA-gq3w-7jj3-x7gr","GHSA-grg2-63fw-f2qr","GHSA-gx77-xgc2-4888","GHSA-h4gh-qq45-vh27","GHSA-h75v-3vvj-5mfj","GHSA-hcc4-c3v8-rx92","GHSA-hg6j-4rv6-33pg","GHSA-hgf8-39gv-g3f2","GHSA-hgg8-fqqc-vfmw","GHSA-hpj7-wq8m-9hgp","GHSA-hpv8-x276-m59f","GHSA-hxxf-235m-72v3","GHSA-j828-28rj-hfhp","GHSA-j842-xgm4-wf88","GHSA-jg22-mg44-37j8","GHSA-jj3x-wxrx-4x23","GHSA-jj8c-mmj3-mmgv","GHSA-jjph-296x-mrcr","GHSA-jp82-jpqv-5vv3","GHSA-jpw9-pfvf-9f58","GHSA-jr27-m4p2-rc6r","GHSA-m344-f55w-2m6j","GHSA-m5qp-6w8w-w647","GHSA-m6qw-4cw2-hm4m","GHSA-m8x7-r2rg-vh5g","GHSA-m959-cc7f-wv43","GHSA-mcmc-2m55-j8jj","GHSA-mf9v-mfxr-j63j","GHSA-mf9w-mj56-hr94","GHSA-mj87-hwqh-73pj","GHSA-mqqc-3gqh-h2x8","GHSA-mrw7-hf4f-83pf","GHSA-mv93-w799-cj2w","GHSA-mw35-8rx3-xf9r","GHSA-mwh4-6h8g-pg8w","GHSA-mxxr-jv3v-6pgc","GHSA-p423-j2cm-9vmq","GHSA-p998-jp59-783m","GHSA-pgqp-8h46-6x4j","GHSA-phhr-52qp-3mj4","GHSA-pmqf-x6x8-p7qw","GHSA-pp6c-gr5w-3c5g","GHSA-pq5c-rjhq-qp7p","GHSA-pq5p-34cr-23v9","GHSA-pq67-6m6q-mj2v","GHSA-pwv6-vv43-88gr","GHSA-q279-jhrf-cc6v","GHSA-q2r8-vmq7-fpx2","GHSA-q2wp-rjmx-x6x9","GHSA-q2x7-8rv6-6q7h","GHSA-q34m-jh98-gwm2","GHSA-q5fh-2hc8-f6rq","GHSA-q8gq-377p-jq3r","GHSA-qccp-gfcp-xxvc","GHSA-qfhq-4f3w-5fph","GHSA-qh4c-xf7m-gxfc","GHSA-qmgc-5h2g-mvrw","GHSA-qq3j-4f4f-9583","GHSA-qxrp-vhvm-j765","GHSA-r23q-823p-vmf7","GHSA-r5m9-wm49-959f","GHSA-r6ph-v2qm-q3c2","GHSA-r73j-pqj5-w3x7","GHSA-r95x-qfjj-fjj2","GHSA-rcfx-77hg-w2wv","GHSA-rcv9-qm8p-9p6j","GHSA-rgxp-2hwp-jwgg","GHSA-rj5c-58rq-j5g5","GHSA-rpm5-65cw-6hj4","GHSA-rrmf-rvhw-rf47","GHSA-rvhj-8chj-8v3c","GHSA-rww4-4w9c-7733","GHSA-rwxx-mrjm-wc2m","GHSA-rxc4-3w6r-4v47","GHSA-v87r-6q3f-2j67","GHSA-v92g-xgxw-vvmm","GHSA-v9pg-7xvm-68hf","GHSA-vffw-93wf-4j4q","GHSA-vgrw-7cvw-pwgx","GHSA-vhcx-3pq2-4fvc","GHSA-vj7q-gjh5-988w","GHSA-vqfr-h8mv-ghfj","GHSA-vrq3-r879-7m65","GHSA-vv7q-7jx5-f767","GHSA-w2fm-2cpv-w7v5","GHSA-w5xq-c4pf-ghq7","GHSA-w6q7-j642-7c25","GHSA-w6vg-jg77-2qg6","GHSA-w853-jp5j-5j7f","GHSA-w8p2-r796-3vmq","GHSA-w8v5-vhqr-4h9v","GHSA-wcj4-jw5j-44wh","GHSA-wf7f-8fxf-xfxc","GHSA-whj4-6x5x-4v2j","GHSA-wjx4-4jcj-g98j","GHSA-wp53-j4wj-2cfg","GHSA-wqp7-x3pw-xc5r","GHSA-wr9h-g72x-mwhm","GHSA-wrfc-pvp9-mr9g","GHSA-wvwj-cvrp-7pv5","GHSA-x2qx-6953-8485","GHSA-x368-4g9h-fvv4","GHSA-x3gm-94wq-g975","GHSA-x746-7m8f-x49c","GHSA-xcgm-r5h9-7989","GHSA-xch3-2f9x-wh9f","GHSA-xg8h-j46f-w952","PYSEC-2025-198","PYSEC-2025-199","PYSEC-2025-200","PYSEC-2025-201","PYSEC-2025-202","PYSEC-2025-203","PYSEC-2025-204","PYSEC-2025-205","PYSEC-2025-206","PYSEC-2025-207","PYSEC-2025-208","PYSEC-2025-209","PYSEC-2025-211","PYSEC-2025-212","PYSEC-2025-213","PYSEC-2025-214","PYSEC-2025-215","PYSEC-2025-216","PYSEC-2025-217","PYSEC-2025-218","PYSEC-2025-238","PYSEC-2026-139","PYSEC-2026-2132","PYSEC-2026-2253","PYSEC-2026-2254","PYSEC-2026-2255","PYSEC-2026-2256","PYSEC-2026-2257","PYSEC-2026-227","PYSEC-2026-2273","PYSEC-2026-2286","PYSEC-2026-2302","PYSEC-2026-3447","PYSEC-2026-3451","PYSEC-2026-3452","PYSEC-2026-3453"],"advisoryCount":262,"providers":[]},"evidence":{"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"1b55661fee93d4733461df8e9c2b491b9205aac2","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-questionnaire-benchmarking-framework/-/blob/4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd/uv.lock","commitSha":"4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd","contentSha256":"e0cfb7dbb1f83b9adb3c422816068eefba3a17e5146d084022722da579e14760","byteCount":734464,"state":"parsed","componentCount":241}],"occurrenceCount":241},"related":{"packages":[{"id":"package:pypi:vllm","slug":"vllm-571f04fc","identity":"pypi:vllm","label":"vLLM","aiRelevant":true,"provider":null,"advisoryCount":39,"licenseExpressions":["Apache-2.0"],"versions":["0.10.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:transformers","slug":"transformers-65289303","identity":"pypi:transformers","label":"Transformers","aiRelevant":true,"provider":{"id":"hugging-face","label":"Hugging Face"},"advisoryCount":25,"licenseExpressions":["Apache-2.0"],"versions":["4.57.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:torch","slug":"torch-47a5352a","identity":"pypi:torch","label":"PyTorch","aiRelevant":true,"provider":null,"advisoryCount":23,"licenseExpressions":["BSD-3-Clause"],"versions":["2.7.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.104.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tokenizers","slug":"tokenizers-7ba00902","identity":"pypi:tokenizers","label":"Hugging Face Tokenizers","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.22.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:scikit-learn","slug":"scikit-learn-ab0941d9","identity":"pypi:scikit-learn","label":"scikit-learn","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["1.7.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tiktoken","slug":"tiktoken-06b251a3","identity":"pypi:tiktoken","label":"tiktoken","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.11.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohttp","slug":"aiohttp-5a806a63","identity":"pypi:aiohttp","label":"aiohttp","aiRelevant":false,"provider":null,"advisoryCount":30,"licenseExpressions":["Apache-2.0","Apache-2.0 AND MIT"],"versions":["3.12.15"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mlflow","slug":"mlflow-43f98b3c","identity":"pypi:mlflow","label":"mlflow","aiRelevant":false,"provider":null,"advisoryCount":23,"licenseExpressions":["non-standard"],"versions":["3.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pillow","slug":"pillow-834347dd","identity":"pypi:pillow","label":"pillow","aiRelevant":false,"provider":null,"advisoryCount":15,"licenseExpressions":["HPND","MIT-CMU"],"versions":["11.3.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:authlib","slug":"authlib-c1d999b9","identity":"pypi:authlib","label":"authlib","aiRelevant":false,"provider":null,"advisoryCount":9,"licenseExpressions":["BSD-3-Clause"],"versions":["1.6.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastmcp","slug":"fastmcp-62abcf82","identity":"pypi:fastmcp","label":"fastmcp","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["Apache-2.0"],"versions":["2.12.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-multipart","slug":"python-multipart-7d2a810e","identity":"pypi:python-multipart","label":"python-multipart","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["Apache-2.0"],"versions":["0.0.20"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:starlette","slug":"starlette-beb9e527","identity":"pypi:starlette","label":"starlette","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["BSD-3-Clause"],"versions":["0.47.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urllib3","slug":"urllib3-fa68f32c","identity":"pypi:urllib3","label":"urllib3","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["2.5.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cryptography","slug":"cryptography-de36c9c8","identity":"pypi:cryptography","label":"cryptography","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["Apache-2.0 OR BSD-3-Clause"],"versions":["45.0.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ray","slug":"ray-f8b4a0d3","identity":"pypi:ray","label":"ray","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["Apache-2.0"],"versions":["2.49.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:werkzeug","slug":"werkzeug-b18d5b02","identity":"pypi:werkzeug","label":"werkzeug","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:gitpython","slug":"gitpython-dcd13009","identity":"pypi:gitpython","label":"gitpython","aiRelevant":false,"provider":null,"advisoryCount":5,"licenseExpressions":["BSD-3-Clause"],"versions":["3.1.45"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jinja2","slug":"jinja2-f7d34747","identity":"pypi:jinja2","label":"jinja2","aiRelevant":false,"provider":null,"advisoryCount":4,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cbor2","slug":"cbor2-9a57866f","identity":"pypi:cbor2","label":"cbor2","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["5.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mcp","slug":"mcp-ef053766","identity":"pypi:mcp","label":"mcp","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["1.14.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests","slug":"requests-53653f76","identity":"pypi:requests","label":"requests","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["Apache-2.0"],"versions":["2.32.5"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:setuptools","slug":"setuptools-fe37c31a","identity":"pypi:setuptools","label":"setuptools","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["79.0.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:filelock","slug":"filelock-b1c63968","identity":"pypi:filelock","label":"filelock","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT","Unlicense"],"versions":["3.19.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mako","slug":"mako-ed406373","identity":"pypi:mako","label":"mako","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["1.3.10"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mlx","slug":"mlx-6c82b549","identity":"pypi:mlx","label":"mlx","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["0.29.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:protobuf","slug":"protobuf-6e30009a","identity":"pypi:protobuf","label":"protobuf","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["BSD-3-Clause"],"versions":["6.32.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyasn1","slug":"pyasn1-348780fa","identity":"pypi:pyasn1","label":"pyasn1","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["BSD-2-Clause"],"versions":["0.6.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:xgrammar","slug":"xgrammar-5ebaef86","identity":"pypi:xgrammar","label":"xgrammar","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["Apache-2.0"],"versions":["0.1.21"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:certifi","slug":"certifi-d4f0c37e","identity":"pypi:certifi","label":"certifi","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MPL-2.0"],"versions":["2025.8.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click","slug":"click-ef97f731","identity":"pypi:click","label":"click","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["8.2.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:diskcache","slug":"diskcache-a019f193","identity":"pypi:diskcache","label":"diskcache","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0"],"versions":["5.6.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:flask","slug":"flask-734a8b3c","identity":"pypi:flask","label":"flask","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fonttools","slug":"fonttools-d2488ea8","identity":"pypi:fonttools","label":"fonttools","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["4.59.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:h11","slug":"h11-48165ab1","identity":"pypi:h11","label":"h11","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.10"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:msgpack","slug":"msgpack-007a8d3b","identity":"pypi:msgpack","label":"msgpack","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyarrow","slug":"pyarrow-facb8516","identity":"pypi:pyarrow","label":"pyarrow","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["21.0.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-settings","slug":"pydantic-settings-d677745f","identity":"pypi:pydantic-settings","label":"pydantic-settings","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["2.10.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pygments","slug":"pygments-ad71bc11","identity":"pypi:pygments","label":"pygments","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-2-Clause"],"versions":["2.19.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dotenv","slug":"python-dotenv-27b12285","identity":"pypi:python-dotenv","label":"python-dotenv","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["1.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sentencepiece","slug":"sentencepiece-dda4c7df","identity":"pypi:sentencepiece","label":"sentencepiece","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["non-standard"],"versions":["0.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sqlparse","slug":"sqlparse-96380dda","identity":"pypi:sqlparse","label":"sqlparse","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["non-standard"],"versions":["0.5.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tqdm","slug":"tqdm-04b01f90","identity":"pypi:tqdm","label":"tqdm","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT AND MPL-2.0"],"versions":["4.67.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:virtualenv","slug":"virtualenv-aeb2a546","identity":"pypi:virtualenv","label":"virtualenv","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["20.34.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohappyeyeballs","slug":"aiohappyeyeballs-ea4657b8","identity":"pypi:aiohappyeyeballs","label":"aiohappyeyeballs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["2.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohttp-cors","slug":"aiohttp-cors-2026df90","identity":"pypi:aiohttp-cors","label":"aiohttp-cors","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.8.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiosignal","slug":"aiosignal-b6794e75","identity":"pypi:aiosignal","label":"aiosignal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:alembic","slug":"alembic-662caf9d","identity":"pypi:alembic","label":"alembic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.16.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-types","slug":"annotated-types-2304c38b","identity":"pypi:annotated-types","label":"annotated-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:antlr4-python3-runtime","slug":"antlr4-python3-runtime-52028339","identity":"pypi:antlr4-python3-runtime","label":"antlr4-python3-runtime","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.9.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:anyio","slug":"anyio-399e5280","identity":"pypi:anyio","label":"anyio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:astor","slug":"astor-5ea47d9f","identity":"pypi:astor","label":"astor","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.8.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:attrs","slug":"attrs-2e7954ac","identity":"pypi:attrs","label":"attrs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:blake3","slug":"blake3-71cab3aa","identity":"pypi:blake3","label":"blake3","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR CC0-1.0"],"versions":["1.0.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:blinker","slug":"blinker-409e1445","identity":"pypi:blinker","label":"blinker","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cachetools","slug":"cachetools-84fe6563","identity":"pypi:cachetools","label":"cachetools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["5.5.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cffi","slug":"cffi-38e65d3e","identity":"pypi:cffi","label":"cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:charset-normalizer","slug":"charset-normalizer-74ccb20a","identity":"pypi:charset-normalizer","label":"charset-normalizer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cloudpickle","slug":"cloudpickle-12e9c0d7","identity":"pypi:cloudpickle","label":"cloudpickle","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorful","slug":"colorful-3d452f6a","identity":"pypi:colorful","label":"colorful","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.5.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:compressed-tensors","slug":"compressed-tensors-e8905144","identity":"pypi:compressed-tensors","label":"compressed-tensors","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.10.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:contourpy","slug":"contourpy-f86f9e10","identity":"pypi:contourpy","label":"contourpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.3.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cupy-cuda12x","slug":"cupy-cuda12x-8ab55f02","identity":"pypi:cupy-cuda12x","label":"cupy-cuda12x","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["13.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cycler","slug":"cycler-3e14883d","identity":"pypi:cycler","label":"cycler","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.12.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cyclopts","slug":"cyclopts-479397c2","identity":"pypi:cyclopts","label":"cyclopts","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["3.24.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:databricks-sdk","slug":"databricks-sdk-26867d3a","identity":"pypi:databricks-sdk","label":"databricks-sdk","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.65.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:depyf","slug":"depyf-44ccc3bb","identity":"pypi:depyf","label":"depyf","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.19.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:dill","slug":"dill-e2d26698","identity":"pypi:dill","label":"dill","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distlib","slug":"distlib-d66be865","identity":"pypi:distlib","label":"distlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["0.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distro","slug":"distro-36b318e9","identity":"pypi:distro","label":"distro","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:dnspython","slug":"dnspython-33533784","identity":"pypi:dnspython","label":"dnspython","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["2.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:docker","slug":"docker-fa61cb72","identity":"pypi:docker","label":"docker","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["7.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:docstring-parser","slug":"docstring-parser-9edeecc2","identity":"pypi:docstring-parser","label":"docstring-parser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:docutils","slug":"docutils-cc2f8622","identity":"pypi:docutils","label":"docutils","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.22.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:einops","slug":"einops-248eadc2","identity":"pypi:einops","label":"einops","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:email-validator","slug":"email-validator-b33c8543","identity":"pypi:email-validator","label":"email-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Unlicense"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:et-xmlfile","slug":"et-xmlfile-634469c0","identity":"pypi:et-xmlfile","label":"et-xmlfile","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:exceptiongroup","slug":"exceptiongroup-316db5d9","identity":"pypi:exceptiongroup","label":"exceptiongroup","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi","slug":"fastapi-e52fd482","identity":"pypi:fastapi","label":"fastapi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.116.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi-cli","slug":"fastapi-cli-8229ae3c","identity":"pypi:fastapi-cli","label":"fastapi-cli","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.10"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi-cloud-cli","slug":"fastapi-cloud-cli-9011df6b","identity":"pypi:fastapi-cloud-cli","label":"fastapi-cloud-cli","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastrlock","slug":"fastrlock-0757e61e","identity":"pypi:fastrlock","label":"fastrlock","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.8.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:frozenlist","slug":"frozenlist-110237da","identity":"pypi:frozenlist","label":"frozenlist","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fsspec","slug":"fsspec-b1a7c311","identity":"pypi:fsspec","label":"fsspec","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2025.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:gguf","slug":"gguf-828fa24b","identity":"pypi:gguf","label":"gguf","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.17.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:gitdb","slug":"gitdb-dac4580b","identity":"pypi:gitdb","label":"gitdb","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.0.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-api-core","slug":"google-api-core-1f2bc06d","identity":"pypi:google-api-core","label":"google-api-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.25.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-auth","slug":"google-auth-42cfc01f","identity":"pypi:google-auth","label":"google-auth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.40.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:googleapis-common-protos","slug":"googleapis-common-protos-d5ca3481","identity":"pypi:googleapis-common-protos","label":"googleapis-common-protos","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.70.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:graphene","slug":"graphene-e89251f5","identity":"pypi:graphene","label":"graphene","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:graphql-core","slug":"graphql-core-6d217145","identity":"pypi:graphql-core","label":"graphql-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.2.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:graphql-relay","slug":"graphql-relay-f4584f38","identity":"pypi:graphql-relay","label":"graphql-relay","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:greenlet","slug":"greenlet-cd6f7934","identity":"pypi:greenlet","label":"greenlet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","MIT AND PSF-2.0","MIT AND Python-2.0"],"versions":["3.2.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:grpcio","slug":"grpcio-40fa763c","identity":"pypi:grpcio","label":"grpcio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.74.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:gunicorn","slug":"gunicorn-a765d3c5","identity":"pypi:gunicorn","label":"gunicorn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["23.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:hf-xet","slug":"hf-xet-732ec6c8","identity":"pypi:hf-xet","label":"hf-xet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.1.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpcore","slug":"httpcore-ba6ae671","identity":"pypi:httpcore","label":"httpcore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.0.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httptools","slug":"httptools-b6cca685","identity":"pypi:httptools","label":"httptools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx","slug":"httpx-a512a166","identity":"pypi:httpx","label":"httpx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx-sse","slug":"httpx-sse-0029fe64","identity":"pypi:httpx-sse","label":"httpx-sse","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:huggingface-hub","slug":"huggingface-hub-443ec6ef","identity":"pypi:huggingface-hub","label":"huggingface-hub","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["0.34.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:hydra-core","slug":"hydra-core-88ed8b5b","identity":"pypi:hydra-core","label":"hydra-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:importlib-metadata","slug":"importlib-metadata-a3dfda3c","identity":"pypi:importlib-metadata","label":"importlib-metadata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["8.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:inquirerpy","slug":"inquirerpy-7155acae","identity":"pypi:inquirerpy","label":"inquirerpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:interegular","slug":"interegular-393a5327","identity":"pypi:interegular","label":"interegular","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:isodate","slug":"isodate-fdef8b9b","identity":"pypi:isodate","label":"isodate","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.7.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:itsdangerous","slug":"itsdangerous-4af70837","identity":"pypi:itsdangerous","label":"itsdangerous","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jiter","slug":"jiter-d62b34e9","identity":"pypi:jiter","label":"jiter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:joblib","slug":"joblib-8cbb7872","identity":"pypi:joblib","label":"joblib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.5.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema","slug":"jsonschema-df23f5cd","identity":"pypi:jsonschema","label":"jsonschema","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.25.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema-path","slug":"jsonschema-path-7b9c625e","identity":"pypi:jsonschema-path","label":"jsonschema-path","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.3.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema-specifications","slug":"jsonschema-specifications-5d87863a","identity":"pypi:jsonschema-specifications","label":"jsonschema-specifications","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:kiwisolver","slug":"kiwisolver-41b47c33","identity":"pypi:kiwisolver","label":"kiwisolver","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.4.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lark","slug":"lark-56b23f4f","identity":"pypi:lark","label":"lark","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lazy-object-proxy","slug":"lazy-object-proxy-a9867681","identity":"pypi:lazy-object-proxy","label":"lazy-object-proxy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["1.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:llguidance","slug":"llguidance-a18efde0","identity":"pypi:llguidance","label":"llguidance","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.30"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:llvmlite","slug":"llvmlite-7b5a17d5","identity":"pypi:llvmlite","label":"llvmlite","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.44.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lm-format-enforcer","slug":"lm-format-enforcer-9e319c1b","identity":"pypi:lm-format-enforcer","label":"lm-format-enforcer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.10.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markdown-it-py","slug":"markdown-it-py-27073f5e","identity":"pypi:markdown-it-py","label":"markdown-it-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markupsafe","slug":"markupsafe-1bdd4c7f","identity":"pypi:markupsafe","label":"markupsafe","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:matplotlib","slug":"matplotlib-9dc72309","identity":"pypi:matplotlib","label":"matplotlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.10.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mdurl","slug":"mdurl-e6f5f075","identity":"pypi:mdurl","label":"mdurl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mistral-common","slug":"mistral-common-038e1158","identity":"pypi:mistral-common","label":"mistral-common","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.8.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mlflow-skinny","slug":"mlflow-skinny-05e8b169","identity":"pypi:mlflow-skinny","label":"mlflow-skinny","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mlflow-tracing","slug":"mlflow-tracing-6ac72d11","identity":"pypi:mlflow-tracing","label":"mlflow-tracing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mlx-lm","slug":"mlx-lm-c2e88814","identity":"pypi:mlx-lm","label":"mlx-lm","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.27.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mlx-metal","slug":"mlx-metal-fdc0094a","identity":"pypi:mlx-metal","label":"mlx-metal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["0.29.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:more-itertools","slug":"more-itertools-fa46f32b","identity":"pypi:more-itertools","label":"more-itertools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["10.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mpmath","slug":"mpmath-4ccb7a41","identity":"pypi:mpmath","label":"mpmath","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:msgspec","slug":"msgspec-abd3da4e","identity":"pypi:msgspec","label":"msgspec","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["0.19.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:multidict","slug":"multidict-b407a4ac","identity":"pypi:multidict","label":"multidict","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.6.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:networkx","slug":"networkx-c2336a8d","identity":"pypi:networkx","label":"networkx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ninja","slug":"ninja-d45560ae","identity":"pypi:ninja","label":"ninja","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.13.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:numba","slug":"numba-4cc2d278","identity":"pypi:numba","label":"numba","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.61.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:numpy","slug":"numpy-ba79b98d","identity":"pypi:numpy","label":"numpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib","non-standard"],"versions":["2.2.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cublas-cu12","slug":"nvidia-cublas-cu12-1d052261","identity":"pypi:nvidia-cublas-cu12","label":"nvidia-cublas-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.6.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cuda-cupti-cu12","slug":"nvidia-cuda-cupti-cu12-973480f1","identity":"pypi:nvidia-cuda-cupti-cu12","label":"nvidia-cuda-cupti-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.6.80"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cuda-nvrtc-cu12","slug":"nvidia-cuda-nvrtc-cu12-e32b7f38","identity":"pypi:nvidia-cuda-nvrtc-cu12","label":"nvidia-cuda-nvrtc-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.6.77"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cuda-runtime-cu12","slug":"nvidia-cuda-runtime-cu12-2b875d2a","identity":"pypi:nvidia-cuda-runtime-cu12","label":"nvidia-cuda-runtime-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.6.77"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cudnn-cu12","slug":"nvidia-cudnn-cu12-a21dce6d","identity":"pypi:nvidia-cudnn-cu12","label":"nvidia-cudnn-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["9.5.1.17"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cufft-cu12","slug":"nvidia-cufft-cu12-21ff54dd","identity":"pypi:nvidia-cufft-cu12","label":"nvidia-cufft-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["11.3.0.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cufile-cu12","slug":"nvidia-cufile-cu12-14048140","identity":"pypi:nvidia-cufile-cu12","label":"nvidia-cufile-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.11.1.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-curand-cu12","slug":"nvidia-curand-cu12-2fed778b","identity":"pypi:nvidia-curand-cu12","label":"nvidia-curand-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["10.3.7.77"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cusolver-cu12","slug":"nvidia-cusolver-cu12-7db0a33a","identity":"pypi:nvidia-cusolver-cu12","label":"nvidia-cusolver-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["11.7.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cusparse-cu12","slug":"nvidia-cusparse-cu12-d7e6a309","identity":"pypi:nvidia-cusparse-cu12","label":"nvidia-cusparse-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.5.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cusparselt-cu12","slug":"nvidia-cusparselt-cu12-97587f50","identity":"pypi:nvidia-cusparselt-cu12","label":"nvidia-cusparselt-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-ml-py","slug":"nvidia-ml-py-c07b1551","identity":"pypi:nvidia-ml-py","label":"nvidia-ml-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.575.51"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nccl-cu12","slug":"nvidia-nccl-cu12-90361558","identity":"pypi:nvidia-nccl-cu12","label":"nvidia-nccl-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2.26.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nvjitlink-cu12","slug":"nvidia-nvjitlink-cu12-6d08af75","identity":"pypi:nvidia-nvjitlink-cu12","label":"nvidia-nvjitlink-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.6.85"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nvtx-cu12","slug":"nvidia-nvtx-cu12-9a2d0378","identity":"pypi:nvidia-nvtx-cu12","label":"nvidia-nvtx-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["12.6.77"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:omegaconf","slug":"omegaconf-7670402e","identity":"pypi:omegaconf","label":"omegaconf","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openai-harmony","slug":"openai-harmony-030f1d71","identity":"pypi:openai-harmony","label":"openai-harmony","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["0.0.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openapi-core","slug":"openapi-core-24597bf8","identity":"pypi:openapi-core","label":"openapi-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.19.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openapi-pydantic","slug":"openapi-pydantic-b637b931","identity":"pypi:openapi-pydantic","label":"openapi-pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openapi-schema-validator","slug":"openapi-schema-validator-fe7e601b","identity":"pypi:openapi-schema-validator","label":"openapi-schema-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openapi-spec-validator","slug":"openapi-spec-validator-77311710","identity":"pypi:openapi-spec-validator","label":"openapi-spec-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.7.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opencensus","slug":"opencensus-a78c415d","identity":"pypi:opencensus","label":"opencensus","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.11.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opencensus-context","slug":"opencensus-context-22acaa15","identity":"pypi:opencensus-context","label":"opencensus-context","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.1.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opencv-python-headless","slug":"opencv-python-headless-4c615221","identity":"pypi:opencv-python-headless","label":"opencv-python-headless","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["4.12.0.88"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openpyxl","slug":"openpyxl-2c369bc4","identity":"pypi:openpyxl","label":"openpyxl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.1.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-api","slug":"opentelemetry-api-341bc8f7","identity":"pypi:opentelemetry-api","label":"opentelemetry-api","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.36.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-exporter-prometheus","slug":"opentelemetry-exporter-prometheus-512d2564","identity":"pypi:opentelemetry-exporter-prometheus","label":"opentelemetry-exporter-prometheus","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.57b0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-proto","slug":"opentelemetry-proto-f15a3372","identity":"pypi:opentelemetry-proto","label":"opentelemetry-proto","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.36.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-sdk","slug":"opentelemetry-sdk-38b86085","identity":"pypi:opentelemetry-sdk","label":"opentelemetry-sdk","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.36.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-semantic-conventions","slug":"opentelemetry-semantic-conventions-15f3be17","identity":"pypi:opentelemetry-semantic-conventions","label":"opentelemetry-semantic-conventions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.57b0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:outlines-core","slug":"outlines-core-16063b2f","identity":"pypi:outlines-core","label":"outlines-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.2.10"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pandas","slug":"pandas-e8d52445","identity":"pypi:pandas","label":"pandas","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.3.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:parse","slug":"parse-31eb237c","identity":"pypi:parse","label":"parse","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.20.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:partial-json-parser","slug":"partial-json-parser-185436fc","identity":"pypi:partial-json-parser","label":"partial-json-parser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.1.1.post6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pathable","slug":"pathable-3c4e83c8","identity":"pypi:pathable","label":"pathable","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pfzy","slug":"pfzy-9297092e","identity":"pypi:pfzy","label":"pfzy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:platformdirs","slug":"platformdirs-e64002f0","identity":"pypi:platformdirs","label":"platformdirs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prometheus-client","slug":"prometheus-client-7bd206b5","identity":"pypi:prometheus-client","label":"prometheus-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","Apache-2.0 AND BSD-2-Clause"],"versions":["0.22.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prometheus-fastapi-instrumentator","slug":"prometheus-fastapi-instrumentator-6b62ecc9","identity":"pypi:prometheus-fastapi-instrumentator","label":"prometheus-fastapi-instrumentator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["7.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prompt-toolkit","slug":"prompt-toolkit-e6f4118a","identity":"pypi:prompt-toolkit","label":"prompt-toolkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.52"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:propcache","slug":"propcache-1fcd6be4","identity":"pypi:propcache","label":"propcache","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.3.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:proto-plus","slug":"proto-plus-41237fa1","identity":"pypi:proto-plus","label":"proto-plus","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.26.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:psutil","slug":"psutil-840b9a74","identity":"pypi:psutil","label":"psutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["7.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:py-cpuinfo","slug":"py-cpuinfo-5ef63954","identity":"pypi:py-cpuinfo","label":"py-cpuinfo","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["9.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:py-spy","slug":"py-spy-5be0886a","identity":"pypi:py-spy","label":"py-spy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyasn1-modules","slug":"pyasn1-modules-6a7471e8","identity":"pypi:pyasn1-modules","label":"pyasn1-modules","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pybase64","slug":"pybase64-d848d924","identity":"pypi:pybase64","label":"pybase64","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["1.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pycountry","slug":"pycountry-938c3061","identity":"pypi:pycountry","label":"pycountry","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["LGPL-2.1-only"],"versions":["24.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pycparser","slug":"pycparser-102d9d3e","identity":"pypi:pycparser","label":"pycparser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.22"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic","slug":"pydantic-4ac148ca","identity":"pypi:pydantic","label":"pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.11.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-core","slug":"pydantic-core-f9814ebc","identity":"pypi:pydantic-core","label":"pydantic-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.33.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-extra-types","slug":"pydantic-extra-types-dddc16ef","identity":"pypi:pydantic-extra-types","label":"pydantic-extra-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.10.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pynvml","slug":"pynvml-46c48fc0","identity":"pypi:pynvml","label":"pynvml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["12.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyparsing","slug":"pyparsing-a28b9b62","identity":"pypi:pyparsing","label":"pyparsing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.2.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyperclip","slug":"pyperclip-4b45e1af","identity":"pypi:pyperclip","label":"pyperclip","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dateutil","slug":"python-dateutil-8eac96b7","identity":"pypi:python-dateutil","label":"python-dateutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.9.0.post0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-json-logger","slug":"python-json-logger-f4803e0b","identity":"pypi:python-json-logger","label":"python-json-logger","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytz","slug":"pytz-cbf1d95c","identity":"pypi:pytz","label":"pytz","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pywin32","slug":"pywin32-9a7c83ae","identity":"pypi:pywin32","label":"pywin32","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["311"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyyaml","slug":"pyyaml-16000901","identity":"pypi:pyyaml","label":"pyyaml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyzmq","slug":"pyzmq-30b92392","identity":"pypi:pyzmq","label":"pyzmq","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["27.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:referencing","slug":"referencing-b8d98ce1","identity":"pypi:referencing","label":"referencing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.36.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:regex","slug":"regex-5e8be65e","identity":"pypi:regex","label":"regex","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 AND CNRI-Python","non-standard"],"versions":["2025.9.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rfc3339-validator","slug":"rfc3339-validator-433f6951","identity":"pypi:rfc3339-validator","label":"rfc3339-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rich","slug":"rich-23b343f7","identity":"pypi:rich","label":"rich","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["14.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rich-rst","slug":"rich-rst-fda043f5","identity":"pypi:rich-rst","label":"rich-rst","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rich-toolkit","slug":"rich-toolkit-96f538ec","identity":"pypi:rich-toolkit","label":"rich-toolkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rignore","slug":"rignore-bc5396c6","identity":"pypi:rignore","label":"rignore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rpds-py","slug":"rpds-py-67c64be8","identity":"pypi:rpds-py","label":"rpds-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.27.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rsa","slug":"rsa-1037e3e0","identity":"pypi:rsa","label":"rsa","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["4.9.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:safetensors","slug":"safetensors-2a32c77a","identity":"pypi:safetensors","label":"safetensors","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.6.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:scipy","slug":"scipy-215f884d","identity":"pypi:scipy","label":"scipy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.16.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sentry-sdk","slug":"sentry-sdk-2727cc69","identity":"pypi:sentry-sdk","label":"sentry-sdk","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.35.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:setproctitle","slug":"setproctitle-5acfd9d9","identity":"pypi:setproctitle","label":"setproctitle","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.3.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:shellingham","slug":"shellingham-fceabe5b","identity":"pypi:shellingham","label":"shellingham","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:six","slug":"six-3c3888bd","identity":"pypi:six","label":"six","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:smart-open","slug":"smart-open-6f8d7c36","identity":"pypi:smart-open","label":"smart-open","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["7.3.0.post1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:smmap","slug":"smmap-943fc5aa","identity":"pypi:smmap","label":"smmap","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["5.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sniffio","slug":"sniffio-83f32c9d","identity":"pypi:sniffio","label":"sniffio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:soundfile","slug":"soundfile-10750d91","identity":"pypi:soundfile","label":"soundfile","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.13.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:soxr","slug":"soxr-a0701a3a","identity":"pypi:soxr","label":"soxr","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["LGPL-2.0-or-later","LGPL-2.1-or-later"],"versions":["0.5.0.post1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sqlalchemy","slug":"sqlalchemy-5de7c53b","identity":"pypi:sqlalchemy","label":"sqlalchemy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.43"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sse-starlette","slug":"sse-starlette-94ef666b","identity":"pypi:sse-starlette","label":"sse-starlette","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sympy","slug":"sympy-b30cb89e","identity":"pypi:sympy","label":"sympy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.14.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:threadpoolctl","slug":"threadpoolctl-e94f6300","identity":"pypi:threadpoolctl","label":"threadpoolctl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:torchaudio","slug":"torchaudio-fdd76263","identity":"pypi:torchaudio","label":"torchaudio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["2.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:torchvision","slug":"torchvision-7f85cafa","identity":"pypi:torchvision","label":"torchvision","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.22.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:triton","slug":"triton-601ea838","identity":"pypi:triton","label":"triton","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typer","slug":"typer-b291ff1c","identity":"pypi:typer","label":"typer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.17.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspection","slug":"typing-inspection-0abeb500","identity":"pypi:typing-inspection","label":"typing-inspection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tzdata","slug":"tzdata-f80b3bb7","identity":"pypi:tzdata","label":"tzdata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2025.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uvicorn","slug":"uvicorn-07c7a595","identity":"pypi:uvicorn","label":"uvicorn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.35.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uvloop","slug":"uvloop-7921eb0f","identity":"pypi:uvloop","label":"uvloop","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.21.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:waitress","slug":"waitress-e47950e2","identity":"pypi:waitress","label":"waitress","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ZPL-2.1"],"versions":["3.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:watchfiles","slug":"watchfiles-d200b8ce","identity":"pypi:watchfiles","label":"watchfiles","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wcwidth","slug":"wcwidth-038a8957","identity":"pypi:wcwidth","label":"wcwidth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.13"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:websockets","slug":"websockets-047236a0","identity":"pypi:websockets","label":"websockets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["15.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wrapt","slug":"wrapt-505c01f2","identity":"pypi:wrapt","label":"wrapt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.17.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:xformers","slug":"xformers-0f6528e3","identity":"pypi:xformers","label":"xformers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.0.31"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:yarl","slug":"yarl-05cd1b35","identity":"pypi:yarl","label":"yarl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.20.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:zipp","slug":"zipp-75ac1ddb","identity":"pypi:zipp","label":"zipp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.23.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]}],"vulnerabilities":[{"id":"GHSA-248v-346w-9cwc","slug":"ghsa-248v-346w-9cwc-8a7dbdf1","dossier":false,"summary":"Certifi removes GLOBALTRUST root certificate","aliases":["CVE-2024-39689","PYSEC-2024-230"],"sourceIds":["GHSA-248v-346w-9cwc","PYSEC-2024-230"],"published":"2024-07-05T19:15:10Z","modified":"2026-06-10T17:14:18.786020835Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39689"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463"},{"type":"PACKAGE","url":"https://github.com/certifi/python-certifi"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2024-230.yaml"},{"type":"ARTICLE","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241206-0001"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241206-0001/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248v-346w-9cwc"}],"versionKeys":["pypi:certifi@2024.6.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-27jp-wm6q-gp25","slug":"ghsa-27jp-wm6q-gp25-5ce03f88","dossier":false,"summary":"sqlparse: formatting list of tuples leads to denial of service","aliases":[],"sourceIds":["GHSA-27jp-wm6q-gp25"],"published":"2026-02-13T16:16:11Z","modified":"2026-02-19T02:59:07.083683Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-27jp-wm6q-gp25"},{"type":"WEB","url":"https://github.com/andialbrecht/sqlparse/commit/40ed3aa958657fa4a82055927fa9de70ab903360"},{"type":"PACKAGE","url":"https://github.com/andialbrecht/sqlparse"},{"type":"WEB","url":"https://github.com/andialbrecht/sqlparse/releases/tag/0.5.4"}],"versionKeys":["pypi:sqlparse@0.5.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-29pf-2h5f-8g72","slug":"ghsa-29pf-2h5f-8g72-1d83ebb4","dossier":false,"summary":"HuggingFace transformers vulnerable to remote code execution","aliases":["CVE-2026-4372","PYSEC-2026-2289"],"sourceIds":["GHSA-29pf-2h5f-8g72","PYSEC-2026-2289"],"published":"2026-05-24T14:16:16.917Z","modified":"2026-07-13T16:45:06.535860363Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4372"},{"type":"FIX","url":"https://github.com/huggingface/transformers/commit/a7f8e7ff37d87d1a1a0c8cf607971c607741452f"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/1f693a6e-6836-4b8b-a0bd-ca036fba8884"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-29pf-2h5f-8g72"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1","pypi:transformers@4.57.1","pypi:transformers@4.57.3","pypi:transformers@4.57.4","pypi:transformers@4.57.6"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-29vq-49wr-vm6x","slug":"ghsa-29vq-49wr-vm6x-7d88633b","dossier":false,"summary":"Werkzeug safe_join() allows Windows special device names","aliases":["CVE-2026-27199","PYSEC-2026-2320"],"sourceIds":["GHSA-29vq-49wr-vm6x","PYSEC-2026-2320"],"published":"2026-02-19T20:32:45Z","modified":"2026-07-13T07:26:55.904978535Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-29vq-49wr-vm6x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27199"},{"type":"FIX","url":"https://github.com/pallets/werkzeug/commit/f407712fdc60a09c2b3f4fe7db557703e5d9338d"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"ADVISORY","url":"https://github.com/pallets/werkzeug/releases/tag/3.1.6"}],"versionKeys":["pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3","pypi:werkzeug@3.1.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-2c2j-9gv5-cj73","slug":"ghsa-2c2j-9gv5-cj73-60bc1f35","dossier":false,"summary":"Starlette has possible denial-of-service vector when parsing large files in multipart forms","aliases":["CVE-2025-54121","PYSEC-2026-1941"],"sourceIds":["GHSA-2c2j-9gv5-cj73","PYSEC-2026-1941"],"published":"2025-07-21T19:34:23Z","modified":"2026-07-07T17:57:05.760766451Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54121"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"WEB","url":"https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14"},{"type":"WEB","url":"https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2c2j-9gv5-cj73"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-2fqr-mr3j-6wp8","slug":"ghsa-2fqr-mr3j-6wp8-5ee7c60f","dossier":false,"summary":"aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence","aliases":["CVE-2026-54279","PYSEC-2026-2112"],"sourceIds":["GHSA-2fqr-mr3j-6wp8","PYSEC-2026-2112"],"published":"2026-06-15T20:08:51Z","modified":"2026-07-13T07:26:35.059071977Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2g68-c3qc-8985","slug":"ghsa-2g68-c3qc-8985-d6075eca","dossier":false,"summary":"Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain","aliases":["CVE-2024-34069","PYSEC-2026-2043"],"sourceIds":["GHSA-2g68-c3qc-8985","PYSEC-2026-2043"],"published":"2024-05-06T14:21:27Z","modified":"2026-07-07T17:56:15.006571356Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-2g68-c3qc-8985"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34069"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/3386395b24c7371db11a5b8eaac0c91da5362692"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/02/msg00026.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4SH32AM3CTPMAAEOIDAN7VU565LO4IR"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HFERFN7PINV4MOGMGA3DPIXJPDCYOEJZ"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240614-0004"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2g68-c3qc-8985"}],"versionKeys":["pypi:werkzeug@3.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2h4p-vjrc-8xpq","slug":"ghsa-2h4p-vjrc-8xpq-f59f8dec","dossier":false,"summary":"Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup","aliases":["CVE-2026-44307","PYSEC-2026-2617"],"sourceIds":["GHSA-2h4p-vjrc-8xpq","PYSEC-2026-2617"],"published":"2026-05-06T21:45:16Z","modified":"2026-07-13T16:42:39.139801717Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/sqlalchemy/mako/security/advisories/GHSA-2h4p-vjrc-8xpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44307"},{"type":"WEB","url":"https://github.com/sqlalchemy/mako/issues/435"},{"type":"WEB","url":"https://github.com/sqlalchemy/mako/commit/72e10c573ca0fbcbddd4455abca8ce92a61780d7"},{"type":"PACKAGE","url":"https://github.com/sqlalchemy/mako"},{"type":"WEB","url":"https://github.com/sqlalchemy/mako/releases/tag/rel_1_3_12"},{"type":"PACKAGE","url":"https://pypi.org/project/mako"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2h4p-vjrc-8xpq"}],"versionKeys":["pypi:mako@1.3.10","pypi:mako@1.3.8"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-2pc9-4j83-qjmr","slug":"ghsa-2pc9-4j83-qjmr-6e2eb21d","dossier":false,"summary":"vLLM affected by RCE via auto_map dynamic module loading during model initialization","aliases":["CVE-2026-22807","PYSEC-2026-2010"],"sourceIds":["GHSA-2pc9-4j83-qjmr","PYSEC-2026-2010"],"published":"2026-01-21T16:12:54Z","modified":"2026-07-17T16:30:29.025047931Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-2pc9-4j83-qjmr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22807"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/32194"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/78d13ea9de4b1ce5e4d8a5af9738fea71fb024e5"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22807.json"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.0"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2010.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2pc9-4j83-qjmr"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431865"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-22807"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:5119"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3462"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-2vrm-gr82-f7m5","slug":"ghsa-2vrm-gr82-f7m5-5092ea0c","dossier":false,"summary":"AIOHTTP has CRLF injection through multipart part content type header construction","aliases":["CVE-2026-34514","PYSEC-2026-2096"],"sourceIds":["GHSA-2vrm-gr82-f7m5","PYSEC-2026-2096"],"published":"2026-04-01T21:16:59.417Z","modified":"2026-07-13T07:26:28.471600737Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2vrm-gr82-f7m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34514"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2xpw-w6gg-jr37","slug":"ghsa-2xpw-w6gg-jr37-91cead57","dossier":true,"summary":"urllib3 streaming API improperly handles highly compressed data","aliases":["CVE-2025-66471","PYSEC-2026-1994"],"sourceIds":["GHSA-2xpw-w6gg-jr37","PYSEC-2026-1994"],"published":"2025-12-05T18:15:54Z","modified":"2026-07-07T17:56:33.872074196Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-3749-ghw9-m3mg","slug":"ghsa-3749-ghw9-m3mg-fadf4a32","dossier":false,"summary":"PyTorch susceptible to local Denial of Service","aliases":["BIT-pytorch-2025-2953","CVE-2025-2953","PYSEC-2025-191"],"sourceIds":["GHSA-3749-ghw9-m3mg","PYSEC-2025-191"],"published":"2025-03-30T16:15:14.380Z","modified":"2026-06-10T17:02:35.808223212Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2953"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/149274"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/149274#issue-2923122269"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-191.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.302006"},{"type":"ADVISORY","url":"https://vuldb.com/?id.302006"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.521279"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3749-ghw9-m3mg"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-37mw-44qp-f5jm","slug":"ghsa-37mw-44qp-f5jm-fb05555e","dossier":false,"summary":"Transformers is vulnerable to ReDoS attack through its DonutProcessor class","aliases":["CVE-2025-3933","PYSEC-2026-1977"],"sourceIds":["GHSA-37mw-44qp-f5jm","PYSEC-2026-1977"],"published":"2025-07-11T12:30:32Z","modified":"2026-07-07T17:57:16.879129924Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3933"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/37788"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/ebbe9b12dd75b69f92100d684c47f923ee262a93"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/25282953-5827-4384-bb6f-5790d275721b"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-37mw-44qp-f5jm"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-38jv-5279-wg99","slug":"ghsa-38jv-5279-wg99-c9df8f7b","dossier":true,"summary":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)","aliases":["CVE-2026-21441","PYSEC-2026-1996"],"sourceIds":["GHSA-38jv-5279-wg99","PYSEC-2026-1996"],"published":"2026-01-07T19:18:14Z","modified":"2026-07-07T17:56:31.346111893Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38jv-5279-wg99"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-38vq-g6vr-w8wf","slug":"ghsa-38vq-g6vr-w8wf-91b7e775","dossier":false,"summary":"Sentencepiece has a a heap overflow issue","aliases":["CVE-2026-1260","PYSEC-2026-1909"],"sourceIds":["GHSA-38vq-g6vr-w8wf","PYSEC-2026-1909"],"published":"2026-01-22T18:30:39Z","modified":"2026-07-07T17:56:14.124737800Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1260"},{"type":"WEB","url":"https://github.com/google/sentencepiece/commit/d856b67fdb3492e035489abf9b3aaf486144b2c0"},{"type":"PACKAGE","url":"https://github.com/google/sentencepiece"},{"type":"WEB","url":"https://github.com/google/sentencepiece/releases/tag/v0.2.1"},{"type":"PACKAGE","url":"https://pypi.org/project/sentencepiece"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38vq-g6vr-w8wf"}],"versionKeys":["pypi:sentencepiece@0.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-3c37-wwvx-h642","slug":"ghsa-3c37-wwvx-h642-8520854e","dossier":false,"summary":"cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads","aliases":["CVE-2026-26209","PYSEC-2026-2123"],"sourceIds":["GHSA-3c37-wwvx-h642","PYSEC-2026-2123"],"published":"2026-03-23T19:16:39.530Z","modified":"2026-07-13T07:26:16.551981788Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/agronholm/cbor2/security/advisories/GHSA-3c37-wwvx-h642"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26209"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/pull/275"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/commit/e61a5f365ba610d5907a0ae1bc72769bba34294b"},{"type":"PACKAGE","url":"https://github.com/agronholm/cbor2"},{"type":"ADVISORY","url":"https://github.com/agronholm/cbor2/releases/tag/5.9.0"}],"versionKeys":["pypi:cbor2@5.7.0","pypi:cbor2@5.7.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-3f6c-7fw2-ppm4","slug":"ghsa-3f6c-7fw2-ppm4-735443b9","dossier":false,"summary":"vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class","aliases":["CVE-2025-6242","PYSEC-2026-2011"],"sourceIds":["GHSA-3f6c-7fw2-ppm4","PYSEC-2026-2011"],"published":"2025-10-07T22:14:15Z","modified":"2026-07-07T17:57:19.957237175Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3f6c-7fw2-ppm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6242"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/9d9a2b77f19f68262d5e469c4e82c0f6365ad72d"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-6242"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2373716"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3f6c-7fw2-ppm4"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-3mwp-wvh9-7528","slug":"ghsa-3mwp-wvh9-7528-9c78ec85","dossier":false,"summary":"vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server","aliases":["CVE-2026-34756","PYSEC-2026-2298"],"sourceIds":["GHSA-3mwp-wvh9-7528","PYSEC-2026-2298"],"published":"2026-04-03T15:35:48Z","modified":"2026-07-17T16:30:29.032335074Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3mwp-wvh9-7528"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34756"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/37952"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/b111f8a61f100fdca08706f41f29ef3548de7380"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34756"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455425"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2298.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34756.json"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-3wq7-rqq7-wx6j","slug":"ghsa-3wq7-rqq7-wx6j-29b8d785","dossier":false,"summary":"AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS","aliases":["CVE-2026-34517","PYSEC-2026-2099"],"sourceIds":["GHSA-3wq7-rqq7-wx6j","PYSEC-2026-2099"],"published":"2026-04-01T21:16:59.870Z","modified":"2026-07-13T07:26:13.561233517Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-3wq7-rqq7-wx6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34517"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/cbb774f38330563422ca0c413a71021d7b944145"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-3ww4-5jv9-j5gm","slug":"ghsa-3ww4-5jv9-j5gm-a5372bc1","dossier":false,"summary":"vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors","aliases":["CVE-2026-47155","PYSEC-2026-2301"],"sourceIds":["GHSA-3ww4-5jv9-j5gm","PYSEC-2026-2301"],"published":"2026-06-10T17:11:38Z","modified":"2026-07-17T16:30:30.495129102Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47155"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/42616"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2301.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-42h5-h8qh-vv9v","slug":"ghsa-42h5-h8qh-vv9v-4d35a1ef","dossier":false,"summary":"MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem","aliases":["BIT-mlflow-2026-2614","CVE-2026-2614","PYSEC-2026-2654"],"sourceIds":["GHSA-42h5-h8qh-vv9v","PYSEC-2026-2654"],"published":"2026-05-11T21:31:35Z","modified":"2026-07-13T16:42:45.636199436Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2614"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/6e801f4259d96804c73107315b24cef0f6aa115a"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/19380271-3fbf-4beb-987e-6fd7069c55e6"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-42h5-h8qh-vv9v"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-46r5-x6jq-v8g6","slug":"ghsa-46r5-x6jq-v8g6-fda1ffbe","dossier":false,"summary":"MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint","aliases":["BIT-mlflow-2026-33866","CVE-2026-33866","PYSEC-2026-94"],"sourceIds":["GHSA-46r5-x6jq-v8g6","PYSEC-2026-94"],"published":"2026-04-07T13:16:47Z","modified":"2026-06-10T17:02:20.749690187Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33866"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/pull/21708"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/005b959cacda05d1423356cfcbd9ebeda8ff96a7"},{"type":"EVIDENCE","url":"https://afine.com/blogs/attacking-mlflow-how-ml-artifacts-become-attack-vectors"},{"type":"WEB","url":"https://cert.pl/en/posts/2026/04/CVE-2026-33865"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2026-94.yaml"},{"type":"ADVISORY","url":"https://cert.pl/en/posts/2026/04/CVE-2026-33865/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-46r5-x6jq-v8g6"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-48p4-8xcf-vxj5","slug":"ghsa-48p4-8xcf-vxj5-13f12656","dossier":false,"summary":"urllib3 does not control redirects in browsers and Node.js","aliases":["CVE-2025-50182","PYSEC-2026-1997"],"sourceIds":["GHSA-48p4-8xcf-vxj5","PYSEC-2026-1997"],"published":"2025-06-18T17:50:11Z","modified":"2026-07-07T17:57:08.881416805Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-4fvr-rgm6-gqmc","slug":"ghsa-4fvr-rgm6-gqmc-c8b35c87","dossier":false,"summary":"aiohttp: HTTP/1 Pipelined Requests Queue Without Limit","aliases":["CVE-2026-54273","PYSEC-2026-2107"],"sourceIds":["GHSA-4fvr-rgm6-gqmc","PYSEC-2026-2107"],"published":"2026-06-15T20:10:32Z","modified":"2026-07-13T07:26:17.316378610Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4m7w-qmgq-4wj5","slug":"ghsa-4m7w-qmgq-4wj5-f98433d3","dossier":false,"summary":"aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections","aliases":["CVE-2026-54275","PYSEC-2026-237"],"sourceIds":["GHSA-4m7w-qmgq-4wj5","PYSEC-2026-237"],"published":"2026-06-15T20:11:13Z","modified":"2026-06-27T11:26:29.646102490Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4m7w-qmgq-4wj5"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4qjh-9fv9-r85r","slug":"ghsa-4qjh-9fv9-r85r-e1501317","dossier":false,"summary":"Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching","aliases":["CVE-2025-46570","PYSEC-2025-53"],"sourceIds":["GHSA-4qjh-9fv9-r85r","PYSEC-2025-53"],"published":"2025-05-28T18:02:24Z","modified":"2026-02-04T03:48:23.274649Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-4qjh-9fv9-r85r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46570"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/17045"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/77073c77bc2006eb80ea6d5128f076f5e6c6f54f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-53.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4r2x-xpjr-7cvv","slug":"ghsa-4r2x-xpjr-7cvv-b37b8fa2","dossier":false,"summary":"vLLM has RCE In Video Processing","aliases":["CVE-2026-22778","PYSEC-2026-565"],"sourceIds":["GHSA-4r2x-xpjr-7cvv","PYSEC-2026-565"],"published":"2026-02-02T17:43:45Z","modified":"2026-07-17T16:30:29.022952299Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22778"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/32319"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/31987"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22778.json"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.1"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-565.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4r2x-xpjr-7cvv"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2436113"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-22778"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3461"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-4w7r-h757-3r74","slug":"ghsa-4w7r-h757-3r74-ca8973bc","dossier":false,"summary":"Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer","aliases":["CVE-2025-6921","PYSEC-2026-1980"],"sourceIds":["GHSA-4w7r-h757-3r74","PYSEC-2026-1980"],"published":"2025-09-23T15:31:09Z","modified":"2026-07-07T17:57:12.050585329Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6921"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/47c34fba5c303576560cb29767efb452ff12b8be"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/d37f7517972f67e3f2194c000ed0f87f064e5099"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/287d15a7-6e7c-45d2-8c05-11e305776f1f"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4w7r-h757-3r74"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-4x5p-f36r-mxxr","slug":"ghsa-4x5p-f36r-mxxr-f02b9eff","dossier":false,"summary":"mlflow Creates of Temporary File in Directory with Insecure Permissions","aliases":["BIT-mlflow-2025-10279","CVE-2025-10279","PYSEC-2026-1639"],"sourceIds":["GHSA-4x5p-f36r-mxxr","PYSEC-2026-1639"],"published":"2026-02-02T12:31:14Z","modified":"2026-07-07T17:56:10.135090160Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10279"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/1d7c8d4cf0a67d407499a8a4ffac387ea4f8194a"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/01d3b81e-13d1-43aa-b91a-443aec68bdc8"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4x5p-f36r-mxxr"}],"versionKeys":["pypi:mlflow@3.1.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4xgf-cpjx-pc3j","slug":"ghsa-4xgf-cpjx-pc3j-c1284f87","dossier":false,"summary":"pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size","aliases":["CVE-2026-58203"],"sourceIds":["GHSA-4xgf-cpjx-pc3j"],"published":"2026-06-19T22:10:42Z","modified":"2026-07-08T08:12:48.604645024Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j"},{"type":"PACKAGE","url":"https://github.com/pydantic/pydantic-settings"}],"versionKeys":["pypi:pydantic-settings@2.12.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5239-wwwm-4pmq","slug":"ghsa-5239-wwwm-4pmq-228840e4","dossier":true,"summary":"Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching","aliases":["CVE-2026-4539","PYSEC-2026-2987"],"sourceIds":["GHSA-5239-wwwm-4pmq","PYSEC-2026-2987"],"published":"2026-03-22T06:30:15Z","modified":"2026-07-13T16:42:36.989801915Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4539"},{"type":"WEB","url":"https://github.com/pygments/pygments/issues/3058"},{"type":"WEB","url":"https://github.com/pygments/pygments/pull/3064"},{"type":"WEB","url":"https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc"},{"type":"PACKAGE","url":"https://github.com/pygments/pygments"},{"type":"WEB","url":"https://github.com/pygments/pygments/releases/tag/2.20.0"},{"type":"WEB","url":"https://vuldb.com/?ctiid.352327"},{"type":"WEB","url":"https://vuldb.com/?id.352327"},{"type":"WEB","url":"https://vuldb.com/?submit.774685"},{"type":"PACKAGE","url":"https://pypi.org/project/pygments"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5239-wwwm-4pmq"}],"versionKeys":["pypi:pygments@2.19.1","pypi:pygments@2.19.2"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-537c-gmf6-5ccf","slug":"ghsa-537c-gmf6-5ccf-23a24e16","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-537c-gmf6-5ccf"],"published":"2026-06-15T20:12:27Z","modified":"2026-06-16T19:59:26.897634900Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260609.txt"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-53q9-r3pm-6pq6","slug":"ghsa-53q9-r3pm-6pq6-6fbb0149","dossier":false,"summary":"PyTorch: `torch.load` with `weights_only=True` leads to remote code execution","aliases":["BIT-pytorch-2025-32434","CVE-2025-32434","PYSEC-2025-41"],"sourceIds":["GHSA-53q9-r3pm-6pq6","PYSEC-2025-41"],"published":"2025-04-18T15:19:28Z","modified":"2026-02-04T02:38:45.601605Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32434"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/8d4b8a920a2172523deb95bf20e8e52d50649c04"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-41.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"}],"versionKeys":["pypi:torch@2.5.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-54jq-c3m8-4m76","slug":"ghsa-54jq-c3m8-4m76-bba4b2d3","dossier":false,"summary":"AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components","aliases":["CVE-2025-69226","PYSEC-2026-1097"],"sourceIds":["GHSA-54jq-c3m8-4m76","PYSEC-2026-1097"],"published":"2026-01-05T23:09:51Z","modified":"2026-07-07T17:57:12.462419549Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-54jq-c3m8-4m76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69226"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f2a86fd5ac0383000d1715afddfa704413f0711e"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-54jq-c3m8-4m76"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-597g-3phw-6986","slug":"ghsa-597g-3phw-6986-6d75801e","dossier":false,"summary":"virtualenv Has TOCTOU Vulnerabilities in Directory Creation","aliases":["BIT-virtualenv-2026-22702","CVE-2026-22702","PYSEC-2026-2009"],"sourceIds":["GHSA-597g-3phw-6986","PYSEC-2026-2009"],"published":"2026-01-13T18:45:57Z","modified":"2026-07-07T17:57:28.238961214Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-597g-3phw-6986"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22702"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3013"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/dec4cec5d16edaf83a00a658f32d1e032661cebc"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-597g-3phw-6986"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-59g5-xgcq-4qw3","slug":"ghsa-59g5-xgcq-4qw3-949fce0e","dossier":false,"summary":"Denial of service (DoS) via deformation `multipart/form-data` boundary","aliases":["CVE-2024-53981","PYSEC-2026-1851"],"sourceIds":["GHSA-59g5-xgcq-4qw3","PYSEC-2026-1851"],"published":"2024-12-02T21:37:04Z","modified":"2026-07-07T17:56:30.840745333Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-59g5-xgcq-4qw3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53981"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/commit/c4fe4d3cebc08c660e57dd709af1ffa7059b3177"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-59g5-xgcq-4qw3"}],"versionKeys":["pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-59p9-h35m-wg4g","slug":"ghsa-59p9-h35m-wg4g-68657c65","dossier":false,"summary":"Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer","aliases":["CVE-2025-6638","PYSEC-2026-1981"],"sourceIds":["GHSA-59p9-h35m-wg4g","PYSEC-2026-1981"],"published":"2025-09-12T12:30:23Z","modified":"2026-07-07T17:56:49.269701149Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6638"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/47c34fba5c303576560cb29767efb452ff12b8be"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/d37f7517972f67e3f2194c000ed0f87f064e5099"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/6a6c933f-9ce8-4ded-8b3b-2c1444c61f36"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-59p9-h35m-wg4g"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5cmr-4px5-23pc","slug":"ghsa-5cmr-4px5-23pc-6775b484","dossier":false,"summary":"XGrammar affected by Denial of Service by infinite recursion grammars","aliases":["CVE-2025-57809","PYSEC-2026-2054"],"sourceIds":["GHSA-5cmr-4px5-23pc","PYSEC-2026-2054"],"published":"2025-08-25T20:43:45Z","modified":"2026-07-07T17:56:43.683032784Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"WEB","url":"https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-5cmr-4px5-23pc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57809"},{"type":"WEB","url":"https://github.com/mlc-ai/xgrammar/issues/250"},{"type":"WEB","url":"https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5"},{"type":"PACKAGE","url":"https://github.com/mlc-ai/xgrammar"},{"type":"PACKAGE","url":"https://pypi.org/project/xgrammar"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5cmr-4px5-23pc"}],"versionKeys":["pypi:xgrammar@0.1.18"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5h2m-4q8j-pqpj","slug":"ghsa-5h2m-4q8j-pqpj-f167fb9b","dossier":false,"summary":"FastMCP OAuth Proxy token reuse across MCP servers","aliases":["CVE-2025-69196","PYSEC-2026-2474"],"sourceIds":["GHSA-5h2m-4q8j-pqpj","PYSEC-2026-2474"],"published":"2026-03-16T15:14:55Z","modified":"2026-07-13T16:43:46.045162193Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-5h2m-4q8j-pqpj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69196"},{"type":"PACKAGE","url":"https://github.com/PrefectHQ/fastmcp"},{"type":"PACKAGE","url":"https://pypi.org/project/fastmcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5h2m-4q8j-pqpj"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5jv2-g5wq-cmr4","slug":"ghsa-5jv2-g5wq-cmr4-b1c3983f","dossier":false,"summary":"vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving","aliases":["CVE-2026-53923","PYSEC-2026-3403"],"sourceIds":["GHSA-5jv2-g5wq-cmr4","PYSEC-2026-3403"],"published":"2026-06-17T14:03:11Z","modified":"2026-07-17T16:30:30.538194678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-5jv2-g5wq-cmr4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53923"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/44971"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/f219788f91952827132fa4fdf916427cd20d225e"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5jv2-g5wq-cmr4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3403.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-5qmp-p3c4-72qj","slug":"ghsa-5qmp-p3c4-72qj-0f202987","dossier":false,"summary":"MLflow: Deterministic sampling in dataset digest enables predictable collisions","aliases":["BIT-mlflow-2026-10803","CVE-2026-10803","PYSEC-2026-195"],"sourceIds":["GHSA-5qmp-p3c4-72qj","PYSEC-2026-195"],"published":"2026-06-04T12:16:24.440Z","modified":"2026-07-15T18:11:16.191752741Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10803"},{"type":"REPORT","url":"https://github.com/mlflow/mlflow/issues/22419"},{"type":"REPORT","url":"https://github.com/mlflow/mlflow/pull/22420"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2026-195.yaml"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-10803"},{"type":"ADVISORY","url":"https://vuldb.com/submit/831462"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/368252"},{"type":"REPORT","url":"https://vuldb.com/vuln/368252/cti"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-5rjg-fvgr-3xxf","slug":"ghsa-5rjg-fvgr-3xxf-79d39e6b","dossier":false,"summary":"setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write","aliases":["BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49"],"sourceIds":["GHSA-5rjg-fvgr-3xxf","PYSEC-2025-49"],"published":"2025-05-17T16:15:19Z","modified":"2026-05-11T00:26:34.671259971Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273"},{"type":"REPORT","url":"https://github.com/pypa/setuptools/issues/4946"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@75.8.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5rvq-cxj2-64vf","slug":"ghsa-5rvq-cxj2-64vf-5e3e7388","dossier":false,"summary":"python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service","aliases":["CVE-2026-53539","PYSEC-2026-3036"],"sourceIds":["GHSA-5rvq-cxj2-64vf","PYSEC-2026-3036"],"published":"2026-06-15T20:24:09Z","modified":"2026-07-13T16:42:40.830680801Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5rvq-cxj2-64vf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53539"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-5xmw-vc9v-4wf2","slug":"ghsa-5xmw-vc9v-4wf2-86a8861a","dossier":false,"summary":"Pillow has a heap buffer overflow with nested list coordinates","aliases":["BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251"],"sourceIds":["GHSA-5xmw-vc9v-4wf2","PYSEC-2026-2251"],"published":"2026-05-04T20:18:27Z","modified":"2026-07-13T07:26:28.768890335Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5xmw-vc9v-4wf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42309"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-63hf-3vf5-4wqf","slug":"ghsa-63hf-3vf5-4wqf-aadd9f0f","dossier":false,"summary":"AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass","aliases":["CVE-2026-34520","PYSEC-2026-2102"],"sourceIds":["GHSA-63hf-3vf5-4wqf","PYSEC-2026-2102"],"published":"2026-04-01T21:17:00.333Z","modified":"2026-07-15T22:00:51.319409225Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hf-3vf5-4wqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34520"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2026-2102.yaml"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-63hw-fmq6-xxg2","slug":"ghsa-63hw-fmq6-xxg2-00aac622","dossier":false,"summary":"aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines","aliases":["CVE-2026-54277","PYSEC-2026-2110"],"sourceIds":["GHSA-63hw-fmq6-xxg2","PYSEC-2026-2110"],"published":"2026-06-15T20:09:16Z","modified":"2026-07-13T07:26:29.010491244Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hw-fmq6-xxg2"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5ab61bb4cd88f19b712f12c7c9295fe262bf804d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-63vm-454h-vhhq","slug":"ghsa-63vm-454h-vhhq-296aa7fc","dossier":false,"summary":"pyasn1 has a DoS vulnerability in decoder","aliases":["CVE-2026-23490","PYSEC-2026-1810"],"sourceIds":["GHSA-63vm-454h-vhhq","PYSEC-2026-1810"],"published":"2026-01-16T19:19:25Z","modified":"2026-07-07T17:56:27.705413895Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23490"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/be353d755f42ea36539b4f5053c652ddf56979a6"},{"type":"PACKAGE","url":"https://github.com/pyasn1/pyasn1"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/blob/0f07d7242a78ab4d129b26256d7474f7168cf536/pyasn1/codec/ber/decoder.py#L496"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/02/msg00002.html"},{"type":"PACKAGE","url":"https://pypi.org/project/pyasn1"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-63vm-454h-vhhq"}],"versionKeys":["pypi:pyasn1@0.6.1"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-65h7-c7c4-mghx","slug":"ghsa-65h7-c7c4-mghx-fc09466d","dossier":false,"summary":"MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability","aliases":["BIT-mlflow-2026-2393","CVE-2026-2393","PYSEC-2026-2219"],"sourceIds":["GHSA-65h7-c7c4-mghx","PYSEC-2026-2219"],"published":"2026-05-11T18:16:31.500Z","modified":"2026-07-13T16:45:08.114491424Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2393"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/commit/64aa0ab7207f9c649b59ba1a5f40d82196817389"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/04ef100d-06b5-4a70-95b1-b7be23aa8150"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-65h7-c7c4-mghx"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-07-08T17:45:15.021597323Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7"],"packageCount":1,"repositoryCount":17},{"id":"GHSA-68rp-wp8r-4726","slug":"ghsa-68rp-wp8r-4726-c59718b4","dossier":false,"summary":"Flask session does not add `Vary: Cookie` header when accessed in some ways","aliases":["CVE-2026-27205","PYSEC-2026-2151"],"sourceIds":["GHSA-68rp-wp8r-4726","PYSEC-2026-2151"],"published":"2026-02-19T20:45:41Z","modified":"2026-07-13T07:26:21.445447696Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27205"},{"type":"FIX","url":"https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4"},{"type":"PACKAGE","url":"https://github.com/pallets/flask"},{"type":"ADVISORY","url":"https://github.com/pallets/flask/releases/tag/3.1.3"}],"versionKeys":["pypi:flask@3.0.2","pypi:flask@3.0.3","pypi:flask@3.1.1","pypi:flask@3.1.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-69f9-5gxw-wvc2","slug":"ghsa-69f9-5gxw-wvc2-eec14573","dossier":false,"summary":"AIOHTTP's unicode processing of header values could cause parsing discrepancies","aliases":["CVE-2025-69224","PYSEC-2026-1099"],"sourceIds":["GHSA-69f9-5gxw-wvc2","PYSEC-2026-1099"],"published":"2026-01-05T22:58:57Z","modified":"2026-07-07T17:56:40.774148412Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-69f9-5gxw-wvc2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69224"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/32677f2adfd907420c078dda6b79225c6f4ebce0"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69f9-5gxw-wvc2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-69j4-grxj-j64p","slug":"ghsa-69j4-grxj-j64p-ff78c10b","dossier":false,"summary":"vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`","aliases":["CVE-2025-62426","PYSEC-2026-2012"],"sourceIds":["GHSA-69j4-grxj-j64p","PYSEC-2026-2012"],"published":"2025-11-20T21:26:24Z","modified":"2026-07-17T16:30:30.603743359Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-69j4-grxj-j64p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62426"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/27205"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/3ada34f9cb4d1af763fdfa3b481862a93eb6bd2b"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69j4-grxj-j64p"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2012.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/chat_utils.py#L1602-L1610"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/openai/serving_engine.py#L809-L814"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-69w3-r845-3855","slug":"ghsa-69w3-r845-3855-1b4edc28","dossier":false,"summary":"HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class","aliases":["CVE-2026-1839","PYSEC-2026-2288"],"sourceIds":["GHSA-69w3-r845-3855","PYSEC-2026-2288"],"published":"2026-04-07T06:16:41.490Z","modified":"2026-07-13T16:45:06.516869221Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1839"},{"type":"FIX","url":"https://github.com/huggingface/transformers/commit/03c8082ba4594c9b8d6fe190ca9bed0e5f8ca396"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/huggingface/transformers/releases/tag/v5.0.0rc3"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/3c77bb97-e493-493d-9a88-c57f5c536485"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69w3-r845-3855"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1","pypi:transformers@4.57.1","pypi:transformers@4.57.3","pypi:transformers@4.57.4","pypi:transformers@4.57.6"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-6c4r-fmh3-7rh8","slug":"ghsa-6c4r-fmh3-7rh8-a82d795c","dossier":false,"summary":"vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models","aliases":["CVE-2026-34760","PYSEC-2026-2299"],"sourceIds":["GHSA-6c4r-fmh3-7rh8","PYSEC-2026-2299"],"published":"2026-04-02T20:16:25.437Z","modified":"2026-07-17T17:00:52.155049383Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6c4r-fmh3-7rh8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34760"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/37058"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/c7f98b4d0a63b32ed939e2b6dfaa8a626e9b46c4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2299.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.0"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6fvq-23cw-5628","slug":"ghsa-6fvq-23cw-5628-8eb01b7c","dossier":false,"summary":"vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server","aliases":["CVE-2025-61620","PYSEC-2026-2013"],"sourceIds":["GHSA-6fvq-23cw-5628","PYSEC-2026-2013"],"published":"2025-10-07T21:35:22Z","modified":"2026-07-07T17:56:38.020494737Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6fvq-23cw-5628"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/25794"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/7977e5027c2250a4abc1f474c5619c40b4e5682f"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6fvq-23cw-5628"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61620"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-6jhg-hg63-jvvf","slug":"ghsa-6jhg-hg63-jvvf-74cd77d8","dossier":false,"summary":"AIOHTTP vulnerable to  denial of service through large payloads","aliases":["CVE-2025-69228","PYSEC-2026-1100"],"sourceIds":["GHSA-6jhg-hg63-jvvf","PYSEC-2026-1100"],"published":"2026-01-05T23:13:14Z","modified":"2026-07-07T17:57:35.249454020Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69228"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jhg-hg63-jvvf"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6jv3-5f52-599m","slug":"ghsa-6jv3-5f52-599m-dd700d26","dossier":false,"summary":"python-multipart: Semicolon treated as querystring field separator enables parameter smuggling","aliases":["CVE-2026-53538","PYSEC-2026-3037"],"sourceIds":["GHSA-6jv3-5f52-599m","PYSEC-2026-3037"],"published":"2026-06-15T20:22:25Z","modified":"2026-07-13T16:43:47.733262470Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jv3-5f52-599m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53538"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-6mq8-rvhq-8wgg","slug":"ghsa-6mq8-rvhq-8wgg-d94d738f","dossier":false,"summary":"AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb","aliases":["CVE-2025-69223","PYSEC-2026-1101"],"sourceIds":["GHSA-6mq8-rvhq-8wgg","PYSEC-2026-1101"],"published":"2026-01-05T22:58:41Z","modified":"2026-07-07T17:56:11.402262091Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69223"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6mq8-rvhq-8wgg"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6pr9-rp53-2pmc","slug":"ghsa-6pr9-rp53-2pmc-1471f1e7","dossier":false,"summary":"vLLM: OOM Denial of Service via Audio Decompression Bomb","aliases":["CVE-2026-54233","PYSEC-2026-3404"],"sourceIds":["GHSA-6pr9-rp53-2pmc","PYSEC-2026-3404"],"published":"2026-06-17T14:06:22Z","modified":"2026-07-17T16:45:18.929893807Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6pr9-rp53-2pmc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54233"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/44970"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/1b1359c33269446f13c05da9a90c25174cbea590"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6pr9-rp53-2pmc"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3404.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.23.1rc0"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6qc9-v4r8-22xg","slug":"ghsa-6qc9-v4r8-22xg-0e64781f","dossier":false,"summary":"vLLM DOS: Remotely kill vllm over http with invalid JSON schema","aliases":["CVE-2025-48942","PYSEC-2025-54"],"sourceIds":["GHSA-6qc9-v4r8-22xg","PYSEC-2025-54"],"published":"2025-05-28T19:41:53Z","modified":"2026-02-04T02:16:15.150519Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6qc9-v4r8-22xg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48942"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/17248"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/17623"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/08bf7840780980c7568c573c70a6a8db94fd45ff"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-54.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-6rvg-6v2m-4j46","slug":"ghsa-6rvg-6v2m-4j46-e04ee614","dossier":false,"summary":"Transformers Regular Expression Denial of Service (ReDoS) vulnerability","aliases":["CVE-2024-12720","PYSEC-2026-1982"],"sourceIds":["GHSA-6rvg-6v2m-4j46","PYSEC-2026-1982"],"published":"2025-03-20T12:32:43Z","modified":"2026-07-07T17:56:13.229192922Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12720"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/deac971c469bcbb182c2e52da0b82fb3bf54cccf"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/4bed1214-7835-4252-a853-22bbad891f98"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6rvg-6v2m-4j46"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-6v7p-g79w-8964","slug":"ghsa-6v7p-g79w-8964-7ab8b488","dossier":false,"summary":"MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error","aliases":["CVE-2026-57585"],"sourceIds":["GHSA-6v7p-g79w-8964"],"published":"2026-06-19T21:42:55Z","modified":"2026-07-08T08:26:50.587609817Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"},{"type":"WEB","url":"https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d"},{"type":"PACKAGE","url":"https://github.com/msgpack/msgpack-python"},{"type":"WEB","url":"https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1"}],"versionKeys":["pypi:msgpack@1.1.0","pypi:msgpack@1.1.1","pypi:msgpack@1.1.2"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-6wgj-66m2-xxp2","slug":"ghsa-6wgj-66m2-xxp2-37eb592b","dossier":false,"summary":"Ray has arbitrary code execution via jobs submission API","aliases":["CVE-2023-48022","PYSEC-2026-517"],"sourceIds":["GHSA-6wgj-66m2-xxp2","PYSEC-2026-517"],"published":"2023-11-28T09:30:26Z","modified":"2026-07-01T20:23:03.600233Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-48022"},{"type":"WEB","url":"https://github.com/ray-project/ray/commit/978947083b1e192dba61ef653c863b11d56b0936"},{"type":"WEB","url":"https://atlas.mitre.org/studies/AML.CS0023"},{"type":"WEB","url":"https://bishopfox.com/blog/ray-versions-2-6-3-2-8-0"},{"type":"WEB","url":"https://console.vulncheck.com/cve/CVE-2023-48022"},{"type":"WEB","url":"https://docs.ray.io/en/latest/ray-security/index.html"},{"type":"WEB","url":"https://docs.ray.io/en/latest/ray-security/token-auth.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xg2h-7cxj-3gvh"},{"type":"WEB","url":"https://github.com/honysyang/Ray"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"},{"type":"WEB","url":"https://www.anyscale.com/blog/update-on-ray-cve-2023-48022-new-verification-tooling-available"},{"type":"WEB","url":"https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/shadowray-cve-2023-48022-exploit"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/the-story-of-shadowray-cve-2023-48022"},{"type":"WEB","url":"https://www.vulncheck.com/blog/initial-access-intelligence-august-2024"},{"type":"PACKAGE","url":"https://pypi.org/project/ray"}],"versionKeys":["pypi:ray@2.45.0","pypi:ray@2.49.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-7432-952r-cw78","slug":"ghsa-7432-952r-cw78-bf3fc71f","dossier":false,"summary":"Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle","aliases":["CVE-2026-28490","PYSEC-2026-2116"],"sourceIds":["GHSA-7432-952r-cw78","PYSEC-2026-2116"],"published":"2026-03-16T15:17:28Z","modified":"2026-07-13T07:26:14.887077371Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-7432-952r-cw78"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28490"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/48b345f29f6c459f11c6a40162b6c0b742ef2e22"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"ADVISORY","url":"https://github.com/authlib/authlib/releases/tag/v1.6.9"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-7545-fcxq-7j24","slug":"ghsa-7545-fcxq-7j24-84dd19fd","dossier":false,"summary":"GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository","aliases":["CVE-2026-44243","PYSEC-2026-2162"],"sourceIds":["GHSA-7545-fcxq-7j24","PYSEC-2026-2162"],"published":"2026-05-06T19:38:48Z","modified":"2026-07-13T07:26:30.186818349Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"EVIDENCE","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44243"},{"type":"PACKAGE","url":"https://github.com/gitpython-developers/GitPython"},{"type":"FIX","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48"}],"versionKeys":["pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-75cm-x2w3-8mgf","slug":"ghsa-75cm-x2w3-8mgf-213b4d71","dossier":false,"summary":"MLflow: unauthenticated access to certain FastAPI routes","aliases":["BIT-mlflow-2026-2652","CVE-2026-2652","PYSEC-2026-2221"],"sourceIds":["GHSA-75cm-x2w3-8mgf","PYSEC-2026-2221"],"published":"2026-05-15T03:16:23.127Z","modified":"2026-07-13T16:45:09.381556404Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2652"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/commit/bb62e773263c14e9ba4d1a82fe72d0de2442c6aa"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/5aeff5f0-49c7-4180-b5cb-c9a046f16756"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-75cm-x2w3-8mgf"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-768j-98cg-p3fv","slug":"ghsa-768j-98cg-p3fv-0815ff07","dossier":false,"summary":"fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib","aliases":["CVE-2025-66034","PYSEC-2026-1389"],"sourceIds":["GHSA-768j-98cg-p3fv","PYSEC-2026-1389"],"published":"2025-12-01T19:07:00Z","modified":"2026-07-07T17:57:24.966058048Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/fonttools/fonttools/security/advisories/GHSA-768j-98cg-p3fv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66034"},{"type":"WEB","url":"https://github.com/fonttools/fonttools/commit/a696d5ba93270d5954f98e7cab5ddca8a02c1e32"},{"type":"PACKAGE","url":"https://github.com/fonttools/fonttools"},{"type":"PACKAGE","url":"https://pypi.org/project/fonttools"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-768j-98cg-p3fv"}],"versionKeys":["pypi:fonttools@4.55.3","pypi:fonttools@4.57.0","pypi:fonttools@4.58.0","pypi:fonttools@4.58.5","pypi:fonttools@4.59.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-7972-pg2x-xr59","slug":"ghsa-7972-pg2x-xr59-8de5a611","dossier":false,"summary":"vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out","aliases":["CVE-2026-27893","PYSEC-2026-2297"],"sourceIds":["GHSA-7972-pg2x-xr59","PYSEC-2026-2297"],"published":"2026-03-27T00:16:22.333Z","modified":"2026-07-17T16:30:29.029310389Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27893"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/36192"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27893.json"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2297.yaml"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2452055"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-27893"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8748"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8747"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8746"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19725"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19724"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10140"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10141"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-79v4-65xg-pq4g","slug":"ghsa-79v4-65xg-pq4g-b911b371","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":["CVE-2024-12797","PYSEC-2026-1284"],"sourceIds":["GHSA-79v4-65xg-pq4g","PYSEC-2026-1284"],"published":"2025-02-11T18:06:42Z","modified":"2026-07-07T17:57:01.916729628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12797"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20250211.txt"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-79v4-65xg-pq4g"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7f5h-v6xp-fcq8","slug":"ghsa-7f5h-v6xp-fcq8-9393173e","dossier":false,"summary":"Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``","aliases":["CVE-2025-62727","PYSEC-2026-1942"],"sourceIds":["GHSA-7f5h-v6xp-fcq8","PYSEC-2026-1942"],"published":"2025-10-28T20:38:01Z","modified":"2026-07-07T17:56:07.620081354Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-7f5h-v6xp-fcq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62727"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/4ea6e22b489ec388d6004cfbca52dd5b147127c5"},{"type":"INTRODUCED","url":"https://github.com/Kludex/starlette/commit/69ed26a85956ef4bd0161807eb27abf49be7cd3c"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/Kludex/starlette/releases/tag/0.49.1"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7f5h-v6xp-fcq8"}],"versionKeys":["pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-7gcm-g887-7qv7","slug":"ghsa-7gcm-g887-7qv7-55bb9ff1","dossier":false,"summary":"protobuf affected by a JSON recursion depth bypass","aliases":["CVE-2026-0994","PYSEC-2026-1805"],"sourceIds":["GHSA-7gcm-g887-7qv7","PYSEC-2026-1805"],"published":"2026-01-23T15:31:35Z","modified":"2026-07-07T17:56:36.712428283Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0994"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/issues/25070"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/pull/25239"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/5ebddcb1bcbe51d1fe323baa145e85f4f23128cf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/d2b001626d137c62dfee6c88c87324102531868b"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7gcm-g887-7qv7"}],"versionKeys":["pypi:protobuf@4.25.7","pypi:protobuf@4.25.8","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4","pypi:protobuf@6.31.1","pypi:protobuf@6.32.0","pypi:protobuf@6.33.0","pypi:protobuf@6.33.1","pypi:protobuf@6.33.4"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-7h4p-rffg-7823","slug":"ghsa-7h4p-rffg-7823-c840dc90","dossier":false,"summary":"vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels","aliases":["CVE-2026-54235","PYSEC-2026-3405"],"sourceIds":["GHSA-7h4p-rffg-7823","PYSEC-2026-3405"],"published":"2026-06-17T14:02:22Z","modified":"2026-07-17T16:45:18.824754082Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-7h4p-rffg-7823"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54235"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/45116"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/d598d239737cfa37bcfcb98886ec3f3557fc7198"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7h4p-rffg-7823"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3405.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7qhf-v65m-g5f3","slug":"ghsa-7qhf-v65m-g5f3-235f2d72","dossier":false,"summary":"mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization","aliases":["CVE-2026-0545","PYSEC-2026-419"],"sourceIds":["GHSA-7qhf-v65m-g5f3","PYSEC-2026-419"],"published":"2026-04-03T18:31:23Z","modified":"2026-07-01T20:22:58.301401Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0545"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/b2e5b028-9541-4d29-8703-a76f1a3734d8"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7qhf-v65m-g5f3"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7rgv-gqhr-fxg3","slug":"ghsa-7rgv-gqhr-fxg3-3d33cce2","dossier":false,"summary":"xgrammar vulnerable to DoS via multi-layer nesting","aliases":["CVE-2026-25048","PYSEC-2026-2322"],"sourceIds":["GHSA-7rgv-gqhr-fxg3","PYSEC-2026-2322"],"published":"2026-03-05T16:16:15.853Z","modified":"2026-07-13T07:26:24.793294058Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-7rgv-gqhr-fxg3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25048"},{"type":"PACKAGE","url":"https://github.com/mlc-ai/xgrammar"},{"type":"ADVISORY","url":"https://github.com/mlc-ai/xgrammar/releases/tag/v0.1.32"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-25048"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25048.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5809"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2444840"}],"versionKeys":["pypi:xgrammar@0.1.18","pypi:xgrammar@0.1.21","pypi:xgrammar@0.1.25"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-82w8-qh3p-5jfq","slug":"ghsa-82w8-qh3p-5jfq-a05ef51e","dossier":false,"summary":"Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS","aliases":["CVE-2026-54283","PYSEC-2026-249"],"sourceIds":["GHSA-82w8-qh3p-5jfq","PYSEC-2026-249"],"published":"2026-06-15T20:39:53Z","modified":"2026-06-27T11:26:15.727496147Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-86qp-5c8j-p5mr","slug":"ghsa-86qp-5c8j-p5mr-13e563cb","dossier":false,"summary":"Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks","aliases":["CVE-2026-48710","PYSEC-2026-161","X41-2026-002"],"sourceIds":["GHSA-86qp-5c8j-p5mr","PYSEC-2026-161"],"published":"2026-05-22T13:10:03Z","modified":"2026-07-10T12:45:24.283227548Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48710"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6"},{"type":"WEB","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette"},{"type":"ARTICLE","url":"https://www.secwest.net/starlette"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-48710"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json"},{"type":"WEB","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481742"},{"type":"DETECTION","url":"https://badhost.org/"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48710"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34532"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34526"},{"type":"ARTICLE","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/"},{"type":"ADVISORY","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette/"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-87hc-h4r5-73f7","slug":"ghsa-87hc-h4r5-73f7-c5117ca2","dossier":false,"summary":"Werkzeug safe_join() allows Windows special device names with compound extensions","aliases":["CVE-2026-21860","PYSEC-2026-2044"],"sourceIds":["GHSA-87hc-h4r5-73f7","PYSEC-2026-2044"],"published":"2026-01-08T19:51:21Z","modified":"2026-07-07T17:56:19.044748151Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-87hc-h4r5-73f7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21860"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/7ae1d254e04a0c33e241ac1cca4783ce6c875ca3"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-87hc-h4r5-73f7"}],"versionKeys":["pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-887c-mr87-cxwp","slug":"ghsa-887c-mr87-cxwp-233a2961","dossier":false,"summary":"PyTorch Improper Resource Shutdown or Release vulnerability","aliases":["BIT-pytorch-2025-3730","CVE-2025-3730","PYSEC-2026-1970"],"sourceIds":["GHSA-887c-mr87-cxwp","PYSEC-2026-1970"],"published":"2025-04-16T21:30:59Z","modified":"2026-07-14T16:44:12.813190902Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3730"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/150835"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/pull/150981"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/01f226bfb8f2c343f5c614a6bbf685d91160f3af"},{"type":"WEB","url":"https://github.com/timocafe/tewart-pytorch/commit/46fc5d8e360127361211cb237d5f9eef0223e567"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.305076"},{"type":"WEB","url":"https://vuldb.com/?id.305076"},{"type":"WEB","url":"https://vuldb.com/?submit.553645"},{"type":"PACKAGE","url":"https://pypi.org/project/torch"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-887c-mr87-cxwp"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-8c7q-86fq-vvmh","slug":"ghsa-8c7q-86fq-vvmh-be4df9cc","dossier":false,"summary":"MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled","aliases":["BIT-mlflow-2026-2651","CVE-2026-2651","PYSEC-2026-2220"],"sourceIds":["GHSA-8c7q-86fq-vvmh","PYSEC-2026-2220"],"published":"2026-05-25T07:16:15.100Z","modified":"2026-07-14T05:30:20.380332392Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2651"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/commit/d7290811d8f3c95366d80109424edc1fb1ad966f"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-2651"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481117"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/65beb119-d3e0-4e03-af2f-fa98f78f83dc"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2651.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8c7q-86fq-vvmh"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-8fr4-5q9j-m8gm","slug":"ghsa-8fr4-5q9j-m8gm-9a59ba60","dossier":false,"summary":"vLLM vulnerable to remote code execution via transformers_utils/get_config","aliases":["CVE-2025-66448","PYSEC-2026-2015"],"sourceIds":["GHSA-8fr4-5q9j-m8gm","PYSEC-2026-2015"],"published":"2025-12-02T17:34:16Z","modified":"2026-07-17T16:30:30.600907369Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-8fr4-5q9j-m8gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66448"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/28126"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/ffb08379d8870a1a81ba82b72797f196838d0c86"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8fr4-5q9j-m8gm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2015.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-8jr5-v98p-w75m","slug":"ghsa-8jr5-v98p-w75m-be5fb565","dossier":false,"summary":"vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations","aliases":["CVE-2026-12491","PYSEC-2026-3406"],"sourceIds":["GHSA-8jr5-v98p-w75m","PYSEC-2026-3406"],"published":"2026-06-17T14:02:42Z","modified":"2026-07-17T16:45:18.723841391Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-8jr5-v98p-w75m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12491"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/44974"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/cf1c90672404548aa3bc51f92c4745576a65ee26"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-12491"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489786"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8jr5-v98p-w75m"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3406.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8qvm-5x2c-j2w7","slug":"ghsa-8qvm-5x2c-j2w7-8a075519","dossier":false,"summary":"protobuf-python has a potential Denial of Service issue","aliases":["CVE-2025-4565","PYSEC-2026-1806"],"sourceIds":["GHSA-8qvm-5x2c-j2w7","PYSEC-2026-1806"],"published":"2025-06-16T16:02:58Z","modified":"2026-07-07T17:57:09.877491994Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-735f-pc8j-v9w8"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8qvm-5x2c-j2w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4565"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/blob/main/python/google/protobuf/internal/decoder_test.py#L87-L98"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/blob/main/python/google/protobuf/internal/message_test.py#L1436-L1478"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/tree/main/python#implementation-backends"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8qvm-5x2c-j2w7"}],"versionKeys":["pypi:protobuf@4.25.7","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-9356-575x-2w9m","slug":"ghsa-9356-575x-2w9m-908a1f8c","dossier":false,"summary":"Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability","aliases":["CVE-2025-5197","PYSEC-2026-1983"],"sourceIds":["GHSA-9356-575x-2w9m","PYSEC-2026-1983"],"published":"2025-08-06T12:31:20Z","modified":"2026-07-07T17:57:12.881673492Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5197"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/701caef704e356dc2f9331cc3fd5df0eccb4720a"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/944b56000be5e9b61af8301aa340838770ad8a0b"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/3f8b3fd0-166b-46e7-b60f-60dd9d2678bf"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9356-575x-2w9m"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-94f4-hr76-p5j6","slug":"ghsa-94f4-hr76-p5j6-34e6691e","dossier":false,"summary":"vLLM: OpenAI auth bypass","aliases":["CVE-2026-48746","PYSEC-2026-226"],"sourceIds":["GHSA-94f4-hr76-p5j6","PYSEC-2026-226"],"published":"2026-06-16T17:36:41Z","modified":"2026-07-17T16:30:30.589294814Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48746"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/43426"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48746"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491581"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-226.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json"},{"type":"ADVISORY","url":"https://x41-dsec.de/lab/advisories/x41-2026-002-starlette"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-9548-qrrj-x5pj","slug":"ghsa-9548-qrrj-x5pj-6121f213","dossier":false,"summary":"AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections","aliases":["CVE-2025-53643","PYSEC-2026-1104"],"sourceIds":["GHSA-9548-qrrj-x5pj","PYSEC-2026-1104"],"published":"2025-07-14T19:33:31Z","modified":"2026-07-07T17:56:52.935544397Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9548-qrrj-x5pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53643"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9548-qrrj-x5pj"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-966j-vmvw-g2g9","slug":"ghsa-966j-vmvw-g2g9-dad9a989","dossier":false,"summary":"AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect","aliases":["CVE-2026-34518","PYSEC-2026-2100"],"sourceIds":["GHSA-966j-vmvw-g2g9","PYSEC-2026-2100"],"published":"2026-04-01T21:17:00.020Z","modified":"2026-07-13T07:26:39.502317923Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-966j-vmvw-g2g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34518"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-98f3-hwg4-4rf7","slug":"ghsa-98f3-hwg4-4rf7-af876537","dossier":false,"summary":"vllm has Improper Resource Shutdown or Release","aliases":["CVE-2026-9540","PYSEC-2026-3407"],"sourceIds":["GHSA-98f3-hwg4-4rf7","PYSEC-2026-3407"],"published":"2026-05-26T15:32:10Z","modified":"2026-07-13T16:43:04.792575152Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9540"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/issues/37343"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/37594"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://ingero.io/debugging-vllm-latency-minimax-ollama-mcp"},{"type":"WEB","url":"https://vuldb.com/submit/814645"},{"type":"WEB","url":"https://vuldb.com/vuln/365601"},{"type":"WEB","url":"https://vuldb.com/vuln/365601/cti"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-98f3-hwg4-4rf7"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-9h52-p55h-vw2f","slug":"ghsa-9h52-p55h-vw2f-fc4c91e7","dossier":false,"summary":"Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default","aliases":["CVE-2025-66416","PYSEC-2026-1617"],"sourceIds":["GHSA-9h52-p55h-vw2f","PYSEC-2026-1617"],"published":"2025-12-02T16:52:08Z","modified":"2026-07-16T18:45:48.199773308Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-9h52-p55h-vw2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66416"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/d3a184119e4479ea6a63590bc41f01dc06e3fa99"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9h52-p55h-vw2f"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mcp/PYSEC-2026-1617.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-9hcf-v7m4-6m2j","slug":"ghsa-9hcf-v7m4-6m2j-d85c17a2","dossier":false,"summary":"vLLM allows clients to crash the openai server with invalid regex","aliases":["CVE-2025-48943","PYSEC-2025-55"],"sourceIds":["GHSA-9hcf-v7m4-6m2j","PYSEC-2025-55"],"published":"2025-05-28T19:42:12Z","modified":"2026-02-04T02:59:05.360205Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-9hcf-v7m4-6m2j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48943"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/17313"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/17623"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/08bf7840780980c7568c573c70a6a8db94fd45ff"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-55.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9hjg-9r4m-mvj7","slug":"ghsa-9hjg-9r4m-mvj7-32d7b63e","dossier":false,"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"sourceIds":["GHSA-9hjg-9r4m-mvj7","PYSEC-2026-1872"],"published":"2025-06-09T19:06:08Z","modified":"2026-07-07T17:56:56.234172558Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6965"},{"type":"FIX","url":"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2025/Jun/2"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-9pcc-gvx5-r5wm","slug":"ghsa-9pcc-gvx5-r5wm-4c73fdb6","dossier":false,"summary":"Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration","aliases":["CVE-2025-30165","PYSEC-2026-2017"],"sourceIds":["GHSA-9pcc-gvx5-r5wm","PYSEC-2026-2017"],"published":"2025-05-06T16:38:35Z","modified":"2026-07-17T16:30:32.007556436Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-9pcc-gvx5-r5wm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30165"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9pcc-gvx5-r5wm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2017.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L295-L301"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L468-L470"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9wx4-h78v-vm56","slug":"ghsa-9wx4-h78v-vm56-6a334c57","dossier":false,"summary":"Requests `Session` object does not verify requests after making first request with verify=False","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"sourceIds":["GHSA-9wx4-h78v-vm56","PYSEC-2026-1873"],"published":"2024-05-20T20:15:00Z","modified":"2026-07-07T17:57:17.012984050Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6655"},{"type":"FIX","url":"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wx4-h78v-vm56"}],"versionKeys":["pypi:requests@2.31.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9x8q-7h8h-wcw9","slug":"ghsa-9x8q-7h8h-wcw9-af94166e","dossier":false,"summary":"aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect","aliases":["CVE-2026-54280","PYSEC-2026-2113"],"sourceIds":["GHSA-9x8q-7h8h-wcw9","PYSEC-2026-2113"],"published":"2026-06-15T20:10:44Z","modified":"2026-07-13T07:26:14.649569270Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9x8q-7h8h-wcw9"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c2jp-c369-7pvx","slug":"ghsa-c2jp-c369-7pvx-e9d6578c","dossier":false,"summary":"FastMCP Auth Integration Allows for Confused Deputy Account Takeover","aliases":[],"sourceIds":["GHSA-c2jp-c369-7pvx"],"published":"2025-10-29T15:38:07Z","modified":"2026-02-03T03:11:14.390341Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-c2jp-c369-7pvx"},{"type":"PACKAGE","url":"https://github.com/jlowin/fastmcp"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-c427-h43c-vf67","slug":"ghsa-c427-h43c-vf67-fa5b38aa","dossier":false,"summary":"AIOHTTP accepts duplicate Host headers","aliases":["CVE-2026-34525","PYSEC-2026-2103"],"sourceIds":["GHSA-c427-h43c-vf67","PYSEC-2026-2103"],"published":"2026-04-01T21:17:00.490Z","modified":"2026-07-13T07:26:42.158681139Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34525"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c65p-x677-fgj6","slug":"ghsa-c65p-x677-fgj6-db33633a","dossier":false,"summary":"vLLM has a Weakness in MultiModalHasher Image Hashing Implementation","aliases":["CVE-2025-46722","PYSEC-2025-43"],"sourceIds":["GHSA-c65p-x677-fgj6","PYSEC-2025-43"],"published":"2025-05-28T18:03:41Z","modified":"2026-02-04T03:00:21.842092Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-c65p-x677-fgj6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46722"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/17378"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/99404f53c72965b41558aceb1bc2380875f5d848"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-43.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-c678-jfcj-6jmf","slug":"ghsa-c678-jfcj-6jmf-cd9a8774","dossier":false,"summary":"PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument","aliases":["BIT-pytorch-2025-2148","CVE-2025-2148","PYSEC-2025-189"],"sourceIds":["GHSA-c678-jfcj-6jmf"],"published":"2025-03-10T12:30:55Z","modified":"2026-06-09T21:26:06.844649427Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2148"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/147722"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-189.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/blob/b0a67c7495bb11ecb23e556058db059ba48354af/torch/autograd/profiler.py#L990"},{"type":"WEB","url":"https://vuldb.com/?ctiid.299059"},{"type":"WEB","url":"https://vuldb.com/?id.299059"},{"type":"WEB","url":"https://vuldb.com/?submit.505959"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cfh3-3jmp-rvhc","slug":"ghsa-cfh3-3jmp-rvhc-4e95572c","dossier":false,"summary":"Pillow affected by out-of-bounds write when loading PSD images","aliases":["BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249"],"sourceIds":["GHSA-cfh3-3jmp-rvhc","PYSEC-2026-2249"],"published":"2026-02-11T14:22:50Z","modified":"2026-07-13T07:26:49.514806069Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25990"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9427"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-25990"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14873"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14874"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:28385"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4128"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4942"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-cpwx-vrp4-4pq7","slug":"ghsa-cpwx-vrp4-4pq7-799bdc98","dossier":false,"summary":"Jinja2 vulnerable to sandbox breakout through attr filter selecting format method","aliases":["CVE-2025-27516","PYSEC-2026-1471"],"sourceIds":["GHSA-cpwx-vrp4-4pq7","PYSEC-2026-1471"],"published":"2025-03-05T20:40:14Z","modified":"2026-07-07T17:56:16.836141266Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-cpwx-vrp4-4pq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27516"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/90457bbf33b8662926ae65cdde4c4c32e756e403"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00045.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cpwx-vrp4-4pq7"}],"versionKeys":["pypi:jinja2@3.1.3","pypi:jinja2@3.1.5"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cx63-2mw6-8hw5","slug":"ghsa-cx63-2mw6-8hw5-1754ad59","dossier":false,"summary":"setuptools vulnerable to Command Injection via package URL","aliases":["BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918"],"sourceIds":["GHSA-cx63-2mw6-8hw5","PYSEC-2026-1918"],"published":"2024-07-15T03:30:57Z","modified":"2026-07-07T17:57:13.326243614Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6345"},{"type":"WEB","url":"https://github.com/pypa/setuptools/pull/4332"},{"type":"WEB","url":"https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html"},{"type":"PACKAGE","url":"https://pypi.org/project/setuptools"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx63-2mw6-8hw5"}],"versionKeys":["pypi:setuptools@69.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f2m9-wcf4-cwwx","slug":"ghsa-f2m9-wcf4-cwwx-e7c3cfb2","dossier":false,"summary":"MLFlow Creates a Temporary File With Insecure Permissions","aliases":["BIT-mlflow-2026-4137","CVE-2026-4137","PYSEC-2026-2655"],"sourceIds":["GHSA-f2m9-wcf4-cwwx","PYSEC-2026-2655"],"published":"2026-05-18T21:31:53Z","modified":"2026-07-13T16:43:33.416174314Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4137"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/1dcbb0c2fbd1f446c328830e601ca13a28219b8a"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4x5p-f36r-mxxr"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/648dc30b-76c7-4433-86b8-f43d926fd8d6"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f2m9-wcf4-cwwx"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-f4hp-rmr7-r7v8","slug":"ghsa-f4hp-rmr7-r7v8-fe038cb7","dossier":false,"summary":"PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function","aliases":["BIT-pytorch-2025-2998","CVE-2025-2998","PYSEC-2025-192"],"sourceIds":["GHSA-f4hp-rmr7-r7v8"],"published":"2025-03-31T15:30:48Z","modified":"2026-06-09T22:11:09.050788278Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2998"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622#issue-2935495265"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-192.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302047"},{"type":"WEB","url":"https://vuldb.com/?id.302047"},{"type":"WEB","url":"https://vuldb.com/?submit.524151"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-f96h-pmfr-66vw","slug":"ghsa-f96h-pmfr-66vw-6763f20e","dossier":false,"summary":"Starlette Denial of service (DoS) via multipart/form-data","aliases":["CVE-2024-47874","PYSEC-2026-1943"],"sourceIds":["GHSA-f96h-pmfr-66vw","PYSEC-2026-1943"],"published":"2024-10-15T18:12:57Z","modified":"2026-07-07T17:57:05.823442628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47874"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/fd038f3070c302bff17ef7d173dbb0b007617733"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f96h-pmfr-66vw"}],"versionKeys":["pypi:starlette@0.37.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f9vj-2wh5-fj8j","slug":"ghsa-f9vj-2wh5-fj8j-f0f29e2a","dossier":false,"summary":"Werkzeug safe_join not safe on Windows","aliases":["CVE-2024-49766","PYSEC-2026-2045"],"sourceIds":["GHSA-f9vj-2wh5-fj8j","PYSEC-2026-2045"],"published":"2024-10-25T19:43:41Z","modified":"2026-07-07T17:56:25.762524663Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-f9vj-2wh5-fj8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49766"},{"type":"FIX","url":"https://github.com/pallets/werkzeug/commit/2767bcb10a7dd1c297d812cc5e6d11a474c1f092"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.0.6"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250131-0005"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f9vj-2wh5-fj8j"}],"versionKeys":["pypi:werkzeug@3.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fg6f-75jq-6523","slug":"ghsa-fg6f-75jq-6523-c927e5c8","dossier":false,"summary":"Authlib has 1-click Account Takeover vulnerability","aliases":["CVE-2025-68158","PYSEC-2026-1201"],"sourceIds":["GHSA-fg6f-75jq-6523","PYSEC-2026-1201"],"published":"2026-01-08T22:40:56Z","modified":"2026-07-07T17:56:30.898731290Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-fg6f-75jq-6523"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68158"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/2808378611dd6fb2532b189a9087877d8f0c0489"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/7974f45e4d7492ab5f527577677f2770ce423228"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fg6f-75jq-6523"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fgcw-684q-jj6r","slug":"ghsa-fgcw-684q-jj6r-9fe55ba1","dossier":false,"summary":"huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path","aliases":["CVE-2026-5241","PYSEC-2026-2290"],"sourceIds":["GHSA-fgcw-684q-jj6r","PYSEC-2026-2290"],"published":"2026-06-03T14:16:46.337Z","modified":"2026-07-16T23:59:26.091024755Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5241"},{"type":"FIX","url":"https://github.com/huggingface/transformers/commit/676559d5022b74aaa0cee1cee0842b7f27c5320e"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-5241"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484384"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2026-2290.yaml"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/ceb3ce1a-4c45-497a-b25e-cb9a7685e619"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5241.json"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1","pypi:transformers@4.57.1","pypi:transformers@4.57.3","pypi:transformers@4.57.4","pypi:transformers@4.57.6"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-fh55-r93g-j68g","slug":"ghsa-fh55-r93g-j68g-a231bc8e","dossier":false,"summary":"AIOHTTP Vulnerable to Cookie Parser Warning Storm","aliases":["CVE-2025-69230","PYSEC-2026-1105"],"sourceIds":["GHSA-fh55-r93g-j68g","PYSEC-2026-1105"],"published":"2026-01-05T23:13:46Z","modified":"2026-07-07T17:56:34.702331996Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-fh55-r93g-j68g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69230"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/64629a0834f94e46d9881f4e99c41a137e1f3326"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh55-r93g-j68g"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-fh64-r2vc-xvhr","slug":"ghsa-fh64-r2vc-xvhr-8b7ea4aa","dossier":false,"summary":"MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface","aliases":["BIT-mlflow-2026-33865","CVE-2026-33865","PYSEC-2026-93"],"sourceIds":["GHSA-fh64-r2vc-xvhr","PYSEC-2026-93"],"published":"2026-04-07T13:16:46.840Z","modified":"2026-06-10T17:02:20.155874108Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33865"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/pull/21435"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/aca4dd0ec88a12f7655155c224371280e9b45dda"},{"type":"EVIDENCE","url":"https://afine.com/blogs/attacking-mlflow-how-ml-artifacts-become-attack-vectors"},{"type":"WEB","url":"https://cert.pl/en/posts/2026/04/CVE-2026-33865"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2026-93.yaml"},{"type":"ADVISORY","url":"https://cert.pl/en/posts/2026/04/CVE-2026-33865/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh64-r2vc-xvhr"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-fhff-qmm8-h2fp","slug":"ghsa-fhff-qmm8-h2fp-244bab2b","dossier":false,"summary":"Arbitrary file write via tar traversal in mlflow","aliases":["BIT-mlflow-2025-15031","CVE-2025-15031","PYSEC-2026-2656"],"sourceIds":["GHSA-fhff-qmm8-h2fp","PYSEC-2026-2656"],"published":"2026-03-19T00:30:20Z","modified":"2026-07-13T16:43:21.433539748Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15031"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/3bf6d81ac4d38654c8ff012dbd0c3e9f17e7e346"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/blob/fe4d9be330426904283401f1d2ed914238b6fc37/mlflow/pyfunc/dbconnect_artifact_cache.py#L140"},{"type":"WEB","url":"https://huntr.com/bounties/09856f77-f968-446f-a930-657d126efe4e"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fhff-qmm8-h2fp"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-fpwr-67px-3qhx","slug":"ghsa-fpwr-67px-3qhx-94f30126","dossier":false,"summary":"Transformers Regular Expression Denial of Service (ReDoS) vulnerability","aliases":["CVE-2025-1194","PYSEC-2026-1984"],"sourceIds":["GHSA-fpwr-67px-3qhx","PYSEC-2026-1984"],"published":"2025-04-29T12:30:21Z","modified":"2026-07-07T17:57:12.290933710Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1194"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/92c5ca9dd70de3ade2af2eb835c96215cc50e815"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/86f58dcd-683f-4adc-a735-849f51e9abb2"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fpwr-67px-3qhx"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g35p-px32-whv6","slug":"ghsa-g35p-px32-whv6-8b66e41b","dossier":false,"summary":"MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration","aliases":["BIT-mlflow-2026-4035","CVE-2026-4035","PYSEC-2026-2222"],"sourceIds":["GHSA-g35p-px32-whv6","PYSEC-2026-2222"],"published":"2026-06-03T09:16:13.083Z","modified":"2026-07-13T16:45:04.877817766Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4035"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/commit/4a3f2f720cb4f058c9e0c5b883e0acc9ab64a7f3"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-4035"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484318"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/f8e591a0-0f19-4910-b82e-16c9956f2233"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4035.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g35p-px32-whv6"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-g3cq-j2xw-wf74","slug":"ghsa-g3cq-j2xw-wf74-4475e17b","dossier":false,"summary":"aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup","aliases":["CVE-2026-54278","PYSEC-2026-2111"],"sourceIds":["GHSA-g3cq-j2xw-wf74","PYSEC-2026-2111"],"published":"2026-06-15T20:09:51Z","modified":"2026-07-13T07:26:25.190325605Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g3cq-j2xw-wf74"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-g6pg-52vf-843h","slug":"ghsa-g6pg-52vf-843h-da352526","dossier":false,"summary":"MLFlow allows Tracing + Assessments Access","aliases":["CVE-2025-15381","PYSEC-2026-2657"],"sourceIds":["GHSA-g6pg-52vf-843h","PYSEC-2026-2657"],"published":"2026-03-27T18:31:27Z","modified":"2026-07-13T16:43:42.935139106Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15381"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/blob/b569ebc74c14af593c326143bee2df44a5d59edf/mlflow/server/auth/__init__.py#L752"},{"type":"WEB","url":"https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g6pg-52vf-843h"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-g7f3-828f-7h7m","slug":"ghsa-g7f3-828f-7h7m-12134915","dossier":false,"summary":"Authlib : JWE zip=DEF decompression bomb enables DoS","aliases":["CVE-2025-62706","PYSEC-2026-1202"],"sourceIds":["GHSA-g7f3-828f-7h7m","PYSEC-2026-1202"],"published":"2025-10-10T22:54:03Z","modified":"2026-07-07T17:57:19.270494442Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-g7f3-828f-7h7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62706"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/e0863d5129316b1790eee5f14cece32a03b8184d"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00032.html"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7f3-828f-7h7m"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g7vv-2v7x-gj9p","slug":"ghsa-g7vv-2v7x-gj9p-5ef970c3","dossier":false,"summary":"tqdm CLI arguments injection attack","aliases":["CVE-2024-34062","PYSEC-2026-1976"],"sourceIds":["GHSA-g7vv-2v7x-gj9p","PYSEC-2026-1976"],"published":"2024-05-03T19:33:28Z","modified":"2026-07-07T17:56:20.187915678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"},{"type":"WEB","url":"https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316"},{"type":"PACKAGE","url":"https://github.com/tqdm/tqdm"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC"},{"type":"PACKAGE","url":"https://pypi.org/project/tqdm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7vv-2v7x-gj9p"}],"versionKeys":["pypi:tqdm@4.66.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g84x-mcqj-x9qq","slug":"ghsa-g84x-mcqj-x9qq-fc677e5d","dossier":false,"summary":"AIOHTTP vulnerable to DoS through chunked messages","aliases":["CVE-2025-69229","PYSEC-2026-1106"],"sourceIds":["GHSA-g84x-mcqj-x9qq","PYSEC-2026-1106"],"published":"2026-01-05T23:13:29Z","modified":"2026-07-07T17:56:31.463290158Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g84x-mcqj-x9qq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g84x-mcqj-x9qq"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-gc5v-m9x4-r6x2","slug":"ghsa-gc5v-m9x4-r6x2-b9828ad8","dossier":true,"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"sourceIds":["GHSA-gc5v-m9x4-r6x2","PYSEC-2026-2275"],"published":"2026-03-25T16:56:28Z","modified":"2026-07-13T07:26:34.091663004Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645"},{"type":"FIX","url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"ADVISORY","url":"https://github.com/psf/requests/releases/tag/v2.33.0"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3","pypi:requests@2.32.4","pypi:requests@2.32.5"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-gm62-xv2j-4w53","slug":"ghsa-gm62-xv2j-4w53-5befa184","dossier":true,"summary":"urllib3 allows an unbounded number of links in the decompression chain","aliases":["CVE-2025-66418","PYSEC-2026-1998"],"sourceIds":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"published":"2025-12-05T18:15:19Z","modified":"2026-07-07T17:57:28.931610368Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm62-xv2j-4w53"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-gmj6-6f8f-6699","slug":"ghsa-gmj6-6f8f-6699-e3e02f35","dossier":false,"summary":"Jinja has a sandbox breakout through malicious filenames","aliases":["CVE-2024-56201","PYSEC-2026-1472"],"sourceIds":["GHSA-gmj6-6f8f-6699","PYSEC-2026-1472"],"published":"2024-12-23T17:54:12Z","modified":"2026-07-07T17:56:55.074166933Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-gmj6-6f8f-6699"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56201"},{"type":"WEB","url":"https://github.com/pallets/jinja/issues/1792"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/767b23617628419ae3709ccfb02f9602ae9fe51f"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gmj6-6f8f-6699"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gq3w-7jj3-x7gr","slug":"ghsa-gq3w-7jj3-x7gr-f80b7f86","dossier":false,"summary":"MLflow Use of Default Password Authentication Bypass Vulnerability","aliases":["CVE-2026-2635","PYSEC-2026-421"],"sourceIds":["GHSA-gq3w-7jj3-x7gr","PYSEC-2026-421"],"published":"2026-02-21T00:31:43Z","modified":"2026-07-01T20:22:58.325967Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2635"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/pull/19260"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/5bf2ec2bd4222a18d78631183ac7f6b752afe8a4"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/releases/tag/v3.8.0rc0"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-26-111"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gq3w-7jj3-x7gr"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-grg2-63fw-f2qr","slug":"ghsa-grg2-63fw-f2qr-b9670d50","dossier":false,"summary":"vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions","aliases":["CVE-2026-22773","PYSEC-2026-143"],"sourceIds":["GHSA-grg2-63fw-f2qr","PYSEC-2026-143"],"published":"2026-01-10T07:16:03.527Z","modified":"2026-06-08T20:00:15.842086505Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-grg2-63fw-f2qr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22773"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/29881"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/0ec84221718d920c3f46da879cc354f94b8fb59e"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-143.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-gx77-xgc2-4888","slug":"ghsa-gx77-xgc2-4888-18e94d17","dossier":false,"summary":"Ray's New Token Authentication is Disabled By Default","aliases":["CVE-2025-34351","PYSEC-2026-518"],"sourceIds":["GHSA-gx77-xgc2-4888","PYSEC-2026-518"],"published":"2025-11-27T03:30:26Z","modified":"2026-07-01T20:23:03.614509Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-w8vc-465m-jjw6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-34351"},{"type":"WEB","url":"https://docs.ray.io/en/latest/ray-security/token-auth.html"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"},{"type":"WEB","url":"https://github.com/ray-project/ray/releases/tag/ray-2.52.0"},{"type":"WEB","url":"https://www.cve.org/resourcessupport/allresources/cnarules#section_4-1_Vulnerability_Determination"},{"type":"WEB","url":"https://www.linkedin.com/posts/jonathan-leitschuh_the-latest-piece-of-mind-bending-research-activity-7396976425997606912-qizE"},{"type":"WEB","url":"https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet"},{"type":"WEB","url":"https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/anyscale-ray-token-authentication-disabled-by-default-insecure-configuration"},{"type":"PACKAGE","url":"https://pypi.org/project/ray"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gx77-xgc2-4888"}],"versionKeys":["pypi:ray@2.45.0","pypi:ray@2.49.1","pypi:ray@2.50.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-h4gh-qq45-vh27","slug":"ghsa-h4gh-qq45-vh27-43490265","dossier":false,"summary":"pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-h4gh-qq45-vh27"],"published":"2024-09-03T21:59:48Z","modified":"2026-02-04T03:06:49.280647Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20240903.txt"}],"versionKeys":["pypi:cryptography@42.0.8"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h75v-3vvj-5mfj","slug":"ghsa-h75v-3vvj-5mfj-d8fc6bb7","dossier":false,"summary":"Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter","aliases":["CVE-2024-34064","PYSEC-2026-1474"],"sourceIds":["GHSA-h75v-3vvj-5mfj","PYSEC-2026-1474"],"published":"2024-05-06T14:20:59Z","modified":"2026-07-07T17:57:30.872296178Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34064"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h75v-3vvj-5mfj"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-hcc4-c3v8-rx92","slug":"ghsa-hcc4-c3v8-rx92-ddf32b5c","dossier":false,"summary":"AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector","aliases":["CVE-2026-34513","PYSEC-2026-2095"],"sourceIds":["GHSA-hcc4-c3v8-rx92","PYSEC-2026-2095"],"published":"2026-04-01T21:16:59.267Z","modified":"2026-07-13T07:26:43.174352940Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hcc4-c3v8-rx92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34513"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hg6j-4rv6-33pg","slug":"ghsa-hg6j-4rv6-33pg-d0ac8db0","dossier":false,"summary":"AIOHTTP is vulnerable to cross-origin redirect with per-request cookies","aliases":["CVE-2026-47265","PYSEC-2026-2105"],"sourceIds":["GHSA-hg6j-4rv6-33pg","PYSEC-2026-2105"],"published":"2026-06-02T20:16:37.903Z","modified":"2026-07-13T07:26:51.969507320Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hg6j-4rv6-33pg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47265"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hgf8-39gv-g3f2","slug":"ghsa-hgf8-39gv-g3f2-0469b394","dossier":false,"summary":"Werkzeug safe_join() allows Windows special device names","aliases":["CVE-2025-66221","PYSEC-2026-2046"],"sourceIds":["GHSA-hgf8-39gv-g3f2","PYSEC-2026-2046"],"published":"2025-12-02T00:27:38Z","modified":"2026-07-07T17:57:36.044527736Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-hgf8-39gv-g3f2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66221"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/4b833376a45c323a189cd11d2362bcffdb1c0c13"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.1.4"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hgf8-39gv-g3f2"}],"versionKeys":["pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-hgg8-fqqc-vfmw","slug":"ghsa-hgg8-fqqc-vfmw-ba9b1162","dossier":false,"summary":"vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router","aliases":["CVE-2026-54236","PYSEC-2026-3408"],"sourceIds":["GHSA-hgg8-fqqc-vfmw","PYSEC-2026-3408"],"published":"2026-06-17T14:04:09Z","modified":"2026-07-20T13:45:32.249353382Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-hgg8-fqqc-vfmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54236"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/45119"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/94923629729381d7f7c9efde72071a2441f7fd82"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hgg8-fqqc-vfmw"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3408.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-hpj7-wq8m-9hgp","slug":"ghsa-hpj7-wq8m-9hgp-fac25647","dossier":false,"summary":"aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges","aliases":["CVE-2026-54276","PYSEC-2026-2109"],"sourceIds":["GHSA-hpj7-wq8m-9hgp","PYSEC-2026-2109"],"published":"2026-06-15T20:09:06Z","modified":"2026-07-13T07:26:28.701980401Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hpj7-wq8m-9hgp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/38d16060037e1bfcd6d677abababa3c2a4bb58fa"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hpv8-x276-m59f","slug":"ghsa-hpv8-x276-m59f-6a62e8b6","dossier":false,"summary":"vLLM Vulnerable to Remote DoS via Special-Token Placeholders","aliases":["CVE-2026-44222","PYSEC-2026-3409"],"sourceIds":["GHSA-hpv8-x276-m59f","PYSEC-2026-3409"],"published":"2026-05-05T22:21:41Z","modified":"2026-07-17T16:30:29.072224452Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-hpv8-x276-m59f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44222"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/issues/32656"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hpv8-x276-m59f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3409.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-hxxf-235m-72v3","slug":"ghsa-hxxf-235m-72v3-21da19b0","dossier":false,"summary":"Deserialization of Untrusted Data in Hugging Face Transformers","aliases":["CVE-2024-11394","PYSEC-2024-229"],"sourceIds":["GHSA-hxxf-235m-72v3","PYSEC-2024-229"],"published":"2024-11-22T22:15:07Z","modified":"2026-06-10T17:02:30.328718397Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11394"},{"type":"WEB","url":"https://github.com/huggingface/transformers/issues/34840"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/35296"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2024-229.yaml"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-24-1515"},{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-24-1515/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hxxf-235m-72v3"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-j828-28rj-hfhp","slug":"ghsa-j828-28rj-hfhp-e66dafb9","dossier":false,"summary":"vLLM vulnerable to Regular Expression Denial of Service","aliases":["CVE-2025-71379"],"sourceIds":["GHSA-j828-28rj-hfhp"],"published":"2025-05-28T17:50:06Z","modified":"2026-07-08T07:35:38.046987158Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-j828-28rj-hfhp"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/18454"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/4fc1bf813ad80172c1db31264beaef7d93fe0601"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-j842-xgm4-wf88","slug":"ghsa-j842-xgm4-wf88-5ee5f9f5","dossier":false,"summary":"MLX has Wild Pointer Dereference in load_gguf()","aliases":["CVE-2025-62609","PYSEC-2025-139"],"sourceIds":["GHSA-j842-xgm4-wf88","PYSEC-2025-139"],"published":"2025-11-21T18:03:20Z","modified":"2026-06-06T00:45:47.874274188Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/ml-explore/mlx/security/advisories/GHSA-j842-xgm4-wf88"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62609"},{"type":"PACKAGE","url":"https://github.com/ml-explore/mlx"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mlx/PYSEC-2025-139.yaml"}],"versionKeys":["pypi:mlx@0.29.0","pypi:mlx@0.29.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-jg22-mg44-37j8","slug":"ghsa-jg22-mg44-37j8-b8064c77","dossier":false,"summary":"AIOHTTP is Vulnerable to Deserialization of Untrusted Data","aliases":["CVE-2026-34993","PYSEC-2026-2104"],"sourceIds":["GHSA-jg22-mg44-37j8","PYSEC-2026-2104"],"published":"2026-06-02T20:16:34.857Z","modified":"2026-07-13T07:26:37.684367184Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-jj3x-wxrx-4x23","slug":"ghsa-jj3x-wxrx-4x23-407bafac","dossier":false,"summary":"AIOHTTP vulnerable to DoS when bypassing asserts","aliases":["CVE-2025-69227","PYSEC-2026-1107"],"sourceIds":["GHSA-jj3x-wxrx-4x23","PYSEC-2026-1107"],"published":"2026-01-05T23:10:15Z","modified":"2026-07-07T17:57:17.782415842Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jj3x-wxrx-4x23"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69227"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj3x-wxrx-4x23"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-jj8c-mmj3-mmgv","slug":"ghsa-jj8c-mmj3-mmgv-216e3367","dossier":false,"summary":"Authlib: Cross-site request forging when using cache","aliases":["CVE-2026-41425","PYSEC-2026-25"],"sourceIds":["GHSA-jj8c-mmj3-mmgv","PYSEC-2026-25"],"published":"2026-04-16T22:38:03Z","modified":"2026-06-05T14:45:30.092809707Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41425"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-25.yaml"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jjph-296x-mrcr","slug":"ghsa-jjph-296x-mrcr-0f661d67","dossier":false,"summary":"Transformers vulnerable to ReDoS attack through its get_imports() function","aliases":["CVE-2025-3264","PYSEC-2026-1985"],"sourceIds":["GHSA-jjph-296x-mrcr","PYSEC-2026-1985"],"published":"2025-07-07T12:30:22Z","modified":"2026-07-07T17:56:51.899728258Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3264"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/0720e206c6ba28887e4d60ef60a6a089f6c1cc76"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/126abe3461762e5fc180e7e614391d1b4ab051ca"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/3c6f7822-9992-476d-8cf0-b0b1623427df"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jjph-296x-mrcr"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jp82-jpqv-5vv3","slug":"ghsa-jp82-jpqv-5vv3-4d50530e","dossier":false,"summary":"Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname","aliases":["CVE-2026-54282","PYSEC-2026-248"],"sourceIds":["GHSA-jp82-jpqv-5vv3","PYSEC-2026-248"],"published":"2026-06-15T20:38:08Z","modified":"2026-07-15T22:30:44.498280076Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54282"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-248.yaml"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-jpw9-pfvf-9f58","slug":"ghsa-jpw9-pfvf-9f58-39682a8f","dossier":false,"summary":"MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal","aliases":["CVE-2026-52869"],"sourceIds":["GHSA-jpw9-pfvf-9f58"],"published":"2026-07-16T19:58:53Z","modified":"2026-07-16T20:15:16.135872152Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52869"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2690"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2719"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/1abcca2408a6b50e10ec601181f63f9978705c00"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/ce267b6fc515dc4efc1dc70b6975b16ff0feef0a"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-jr27-m4p2-rc6r","slug":"ghsa-jr27-m4p2-rc6r-4991bc00","dossier":false,"summary":"Denial of Service in pyasn1 via Unbounded Recursion","aliases":["CVE-2026-30922","PYSEC-2026-2263"],"sourceIds":["GHSA-jr27-m4p2-rc6r","PYSEC-2026-2263"],"published":"2026-03-17T16:17:33Z","modified":"2026-07-13T07:26:46.403932690Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30922"},{"type":"FIX","url":"https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/5a49bd1fe93b5b866a1210f6bf0a3924f21572c8"},{"type":"PACKAGE","url":"https://github.com/pyasn1/pyasn1"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/05/msg00001.html"}],"versionKeys":["pypi:pyasn1@0.6.1"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-m344-f55w-2m6j","slug":"ghsa-m344-f55w-2m6j-43fc4846","dossier":false,"summary":"Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding","aliases":["CVE-2026-28498","PYSEC-2026-2117"],"sourceIds":["GHSA-m344-f55w-2m6j","PYSEC-2026-2117"],"published":"2026-03-16T16:15:06Z","modified":"2026-07-13T07:26:18.508336668Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-m344-f55w-2m6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28498"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/b9bb2b25bf8b7e01512d847a95c1749646eaa72b"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"ADVISORY","url":"https://github.com/authlib/authlib/releases/tag/v1.6.9"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-28498"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28498.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6309"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6497"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6567"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6568"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6720"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6912"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2448182"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-m5qp-6w8w-w647","slug":"ghsa-m5qp-6w8w-w647-495897bd","dossier":false,"summary":"AIOHTTP has a Multipart Header Size Bypass","aliases":["CVE-2026-34516","PYSEC-2026-2098"],"sourceIds":["GHSA-m5qp-6w8w-w647","PYSEC-2026-2098"],"published":"2026-04-01T21:16:59.723Z","modified":"2026-07-13T07:26:19.821892403Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m5qp-6w8w-w647"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34516"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/8a74257b3804c9aac0bf644af93070f68f6c5a6f"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-m6qw-4cw2-hm4m","slug":"ghsa-m6qw-4cw2-hm4m-3f6d3ee7","dossier":false,"summary":"aiohttp: CRLF injection in multipart headers","aliases":["CVE-2026-50269","PYSEC-2026-2106"],"sourceIds":["GHSA-m6qw-4cw2-hm4m","PYSEC-2026-2106"],"published":"2026-06-15T20:07:26Z","modified":"2026-07-13T07:26:17.983947245Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-m8x7-r2rg-vh5g","slug":"ghsa-m8x7-r2rg-vh5g-d7eda4e5","dossier":false,"summary":"FastMCP has a Command Injection vulnerability - Gemini CLI","aliases":["CVE-2025-64340","PYSEC-2026-2475"],"sourceIds":["GHSA-m8x7-r2rg-vh5g","PYSEC-2026-2475"],"published":"2026-03-31T22:24:15Z","modified":"2026-07-18T14:44:31.250470362Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-m8x7-r2rg-vh5g"},{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-m8x7-r2rg-vh5g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64340"},{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/pull/3522"},{"type":"PACKAGE","url":"https://github.com/PrefectHQ/fastmcp"},{"type":"PACKAGE","url":"https://pypi.org/project/fastmcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m8x7-r2rg-vh5g"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-m959-cc7f-wv43","slug":"ghsa-m959-cc7f-wv43-3b497c67","dossier":false,"summary":"cryptography has incomplete DNS name constraint enforcement on peer names","aliases":["CVE-2026-34073","PYSEC-2026-35"],"sourceIds":["GHSA-m959-cc7f-wv43","PYSEC-2026-35"],"published":"2026-03-27T19:56:21Z","modified":"2026-06-05T18:00:13.915417385Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34073"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-35.yaml"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mcmc-2m55-j8jj","slug":"ghsa-mcmc-2m55-j8jj-ea2fc7d3","dossier":false,"summary":"vLLM introduced enhanced protection for CVE-2025-62164","aliases":["CVE-2026-56340","PYSEC-2026-250"],"sourceIds":["GHSA-mcmc-2m55-j8jj","PYSEC-2026-250"],"published":"2026-01-08T21:47:43Z","modified":"2026-06-27T11:26:32.894007747Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/30649"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings"}],"versionKeys":["pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-mf9v-mfxr-j63j","slug":"ghsa-mf9v-mfxr-j63j-1a7db6d4","dossier":false,"summary":"urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API","aliases":["CVE-2026-44432","PYSEC-2026-142"],"sourceIds":["GHSA-mf9v-mfxr-j63j","PYSEC-2026-142"],"published":"2026-05-11T14:51:45Z","modified":"2026-06-08T20:00:12.284378628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mf9w-mj56-hr94","slug":"ghsa-mf9w-mj56-hr94-a492e0f4","dossier":false,"summary":"python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback","aliases":["CVE-2026-28684","PYSEC-2026-2270"],"sourceIds":["GHSA-mf9w-mj56-hr94","PYSEC-2026-2270"],"published":"2026-04-20T17:16:33.087Z","modified":"2026-07-13T07:26:26.604845458Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/security/advisories/GHSA-mf9w-mj56-hr94"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28684"},{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311"},{"type":"WEB","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311.patch"},{"type":"PACKAGE","url":"https://github.com/theskumar/python-dotenv"},{"type":"ADVISORY","url":"https://github.com/theskumar/python-dotenv/releases/tag/v1.2.2"}],"versionKeys":["pypi:python-dotenv@1.0.1","pypi:python-dotenv@1.1.0","pypi:python-dotenv@1.1.1","pypi:python-dotenv@1.2.1"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-mj87-hwqh-73pj","slug":"ghsa-mj87-hwqh-73pj-92a4d569","dossier":false,"summary":"python-multipart affected by Denial of Service via large multipart preamble or epilogue data","aliases":["CVE-2026-40347","PYSEC-2026-3038"],"sourceIds":["GHSA-mj87-hwqh-73pj","PYSEC-2026-3038"],"published":"2026-04-15T19:45:44Z","modified":"2026-07-13T16:43:05.220439399Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-mj87-hwqh-73pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40347"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/releases/tag/0.0.26"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mj87-hwqh-73pj"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-mqqc-3gqh-h2x8","slug":"ghsa-mqqc-3gqh-h2x8-6d702daf","dossier":false,"summary":"AIOHTTP has unicode match groups in regexes for ASCII protocol elements","aliases":["CVE-2025-69225","PYSEC-2026-1109"],"sourceIds":["GHSA-mqqc-3gqh-h2x8","PYSEC-2026-1109"],"published":"2026-01-05T23:09:30Z","modified":"2026-07-07T17:56:18.569417663Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69225"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqqc-3gqh-h2x8"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mrw7-hf4f-83pf","slug":"ghsa-mrw7-hf4f-83pf-125f2ed3","dossier":false,"summary":"vLLM deserialization vulnerability leading to DoS and potential RCE","aliases":["CVE-2025-62164","PYSEC-2026-2018"],"sourceIds":["GHSA-mrw7-hf4f-83pf","PYSEC-2026-2018"],"published":"2025-11-20T20:59:34Z","modified":"2026-07-17T16:30:30.638326686Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-mrw7-hf4f-83pf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62164"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/27204"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mrw7-hf4f-83pf"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2018.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-mv93-w799-cj2w","slug":"ghsa-mv93-w799-cj2w-4413137a","dossier":false,"summary":"GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath","aliases":[],"sourceIds":["GHSA-mv93-w799-cj2w"],"published":"2026-05-08T23:19:02Z","modified":"2026-05-10T04:44:28.835923654Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rpm5-65cw-6hj4"},{"type":"PACKAGE","url":"https://github.com/gitpython-developers/GitPython"}],"versionKeys":["pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-mw35-8rx3-xf9r","slug":"ghsa-mw35-8rx3-xf9r-5497861f","dossier":false,"summary":"Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization","aliases":["CVE-2026-41486","PYSEC-2026-2272","PYSEC-2026-2296"],"sourceIds":["GHSA-mw35-8rx3-xf9r","PYSEC-2026-2272"],"published":"2026-04-24T16:15:00Z","modified":"2026-07-13T07:26:16.094513511Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/ray-project/ray/security/advisories/GHSA-mw35-8rx3-xf9r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41486"},{"type":"WEB","url":"https://github.com/ray-project/ray/pull/54831"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/62056"},{"type":"FIX","url":"https://github.com/ray-project/ray/commit/c02bd31ae31996805868baa446a131a8d304525f"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"},{"type":"ADVISORY","url":"https://github.com/ray-project/ray/releases/tag/ray-2.55.0"}],"versionKeys":["pypi:ray@2.45.0","pypi:ray@2.49.1","pypi:ray@2.50.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mwh4-6h8g-pg8w","slug":"ghsa-mwh4-6h8g-pg8w-881420d8","dossier":false,"summary":"AIOHTTP has HTTP response splitting via \\r in reason phrase","aliases":["CVE-2026-34519","PYSEC-2026-2101"],"sourceIds":["GHSA-mwh4-6h8g-pg8w","PYSEC-2026-2101"],"published":"2026-04-01T21:17:00.170Z","modified":"2026-07-13T07:26:39.246105773Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mwh4-6h8g-pg8w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34519"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53b35a2f8869c37a133e60bf1a82a1c01642ba2b"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-mxxr-jv3v-6pgc","slug":"ghsa-mxxr-jv3v-6pgc-cbbc697b","dossier":false,"summary":"FastMCP vulnerable to reflected XSS in client's callback page","aliases":["CVE-2025-62800","PYSEC-2026-1364"],"sourceIds":["GHSA-mxxr-jv3v-6pgc","PYSEC-2026-1364"],"published":"2025-10-29T15:38:29Z","modified":"2026-07-07T17:56:05.411756133Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-mxxr-jv3v-6pgc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62800"},{"type":"WEB","url":"https://github.com/jlowin/fastmcp/pull/2090"},{"type":"WEB","url":"https://github.com/jlowin/fastmcp/commit/2a20f54617a37213ed83894a8c2f0ac38a2e83a3"},{"type":"PACKAGE","url":"https://github.com/jlowin/fastmcp"},{"type":"PACKAGE","url":"https://pypi.org/project/fastmcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mxxr-jv3v-6pgc"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-p423-j2cm-9vmq","slug":"ghsa-p423-j2cm-9vmq-1455bc4c","dossier":false,"summary":"Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs","aliases":["CVE-2026-39892","PYSEC-2026-36"],"sourceIds":["GHSA-p423-j2cm-9vmq","PYSEC-2026-36"],"published":"2026-04-08T19:23:08Z","modified":"2026-06-05T18:00:15.295914184Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39892"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml"}],"versionKeys":["pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-p998-jp59-783m","slug":"ghsa-p998-jp59-783m-17c88f0d","dossier":false,"summary":"AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows","aliases":["CVE-2026-34515","PYSEC-2026-2097"],"sourceIds":["GHSA-p998-jp59-783m","PYSEC-2026-2097"],"published":"2026-04-01T21:16:59.570Z","modified":"2026-07-13T07:26:55.790859426Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34515"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-pgqp-8h46-6x4j","slug":"ghsa-pgqp-8h46-6x4j-303ca0ec","dossier":false,"summary":"MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation","aliases":["BIT-mlflow-2025-14279","CVE-2025-14279","PYSEC-2026-1656"],"sourceIds":["GHSA-pgqp-8h46-6x4j","PYSEC-2026-1656"],"published":"2026-01-12T09:30:31Z","modified":"2026-07-07T17:56:18.060826978Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14279"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/pull/17910"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/b0ffd289e9b0d0cc32c9e3a9b9f3843ae83dbec3"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/ef478f72-2e4f-44dc-8055-fc06bef03108"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pgqp-8h46-6x4j"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-phhr-52qp-3mj4","slug":"ghsa-phhr-52qp-3mj4-6f5d82e3","dossier":false,"summary":"Transformers's Improper Input Validation vulnerability can be exploited through username injection","aliases":["CVE-2025-3777","PYSEC-2026-1986"],"sourceIds":["GHSA-phhr-52qp-3mj4","PYSEC-2026-1986"],"published":"2025-07-07T12:30:22Z","modified":"2026-07-07T17:56:47.225461188Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3777"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/4dda5f71b35fb70cf602187eef84bb17a50b9082"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/huggingface/transformers/blame/a7d2bbaaa8aac64f7c1ee8c1421cfe84b38359a4/src/transformers/image_utils.py"},{"type":"WEB","url":"https://huntr.com/bounties/ccba0730-9248-4853-b7ff-5c20e6364f09"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-phhr-52qp-3mj4"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pmqf-x6x8-p7qw","slug":"ghsa-pmqf-x6x8-p7qw-b2778e4b","dossier":false,"summary":"vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs","aliases":["CVE-2025-62372","PYSEC-2026-2019"],"sourceIds":["GHSA-pmqf-x6x8-p7qw","PYSEC-2026-2019"],"published":"2025-11-20T21:23:29Z","modified":"2026-07-17T16:30:32.010515304Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62372"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/27204"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/6613"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pmqf-x6x8-p7qw"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-pp6c-gr5w-3c5g","slug":"ghsa-pp6c-gr5w-3c5g-de40aafe","dossier":false,"summary":"python-multipart has Denial of Service via unbounded multipart part headers","aliases":["CVE-2026-42561","PYSEC-2026-3039"],"sourceIds":["GHSA-pp6c-gr5w-3c5g","PYSEC-2026-3039"],"published":"2026-05-06T21:56:14Z","modified":"2026-07-13T16:42:24.725022295Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-pp6c-gr5w-3c5g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42561"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pp6c-gr5w-3c5g"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-pq5c-rjhq-qp7p","slug":"ghsa-pq5c-rjhq-qp7p-741b6a4f","dossier":false,"summary":"vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing","aliases":["CVE-2026-34755","PYSEC-2026-144"],"sourceIds":["GHSA-pq5c-rjhq-qp7p","PYSEC-2026-144"],"published":"2026-04-03T21:51:35Z","modified":"2026-07-17T16:30:29.016474105Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-pq5c-rjhq-qp7p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34755"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/38636"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/58ee61422169ce17e08248f8efa1e9df434fe395"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34755"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455403"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-144.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34755.json"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-pq5p-34cr-23v9","slug":"ghsa-pq5p-34cr-23v9-127ea2b8","dossier":false,"summary":"Authlib is vulnerable to Denial of Service via Oversized JOSE Segments","aliases":["CVE-2025-61920","PYSEC-2026-1203"],"sourceIds":["GHSA-pq5p-34cr-23v9","PYSEC-2026-1203"],"published":"2025-10-10T20:26:43Z","modified":"2026-07-07T17:56:17.886883361Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-pq5p-34cr-23v9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61920"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/867e3f87b072347a1ae9cf6983cc8bbf88447e5e"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00032.html"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq5p-34cr-23v9"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-pq67-6m6q-mj2v","slug":"ghsa-pq67-6m6q-mj2v-3522d1d4","dossier":false,"summary":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","aliases":["CVE-2025-50181","PYSEC-2026-1999"],"sourceIds":["GHSA-pq67-6m6q-mj2v","PYSEC-2026-1999"],"published":"2025-06-18T17:50:00Z","modified":"2026-07-07T17:56:41.872294653Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-pwv6-vv43-88gr","slug":"ghsa-pwv6-vv43-88gr-c5f811d0","dossier":true,"summary":"Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)","aliases":["BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252"],"sourceIds":["GHSA-pwv6-vv43-88gr","PYSEC-2026-2252"],"published":"2026-05-04T20:20:31Z","modified":"2026-07-13T07:26:52.198871129Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42311"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9520"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-q279-jhrf-cc6v","slug":"ghsa-q279-jhrf-cc6v-6a45143b","dossier":false,"summary":"Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack","aliases":["CVE-2025-62593","PYSEC-2026-520"],"sourceIds":["GHSA-q279-jhrf-cc6v","PYSEC-2026-520"],"published":"2025-11-26T19:35:23Z","modified":"2026-07-01T20:23:03.643178Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62593"},{"type":"WEB","url":"https://github.com/nccgroup/singularity/pull/68"},{"type":"WEB","url":"https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09"},{"type":"WEB","url":"https://docs.ray.io/en/releases-2.51.1/ray-security/index.html"},{"type":"WEB","url":"https://en.wikipedia.org/wiki/Malvertising"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"},{"type":"WEB","url":"https://github.com/ray-project/ray/blob/e7889ae542bf0188610bc8b06d274cbf53790cbd/python/ray/dashboard/http_server_head.py#L184-L196"},{"type":"WEB","url":"https://github.com/ray-project/ray/blob/f39a860436dca3ed5b9dfae84bd867ac10c84dc6/python/ray/dashboard/optional_utils.py#L129-L155"},{"type":"PACKAGE","url":"https://pypi.org/project/ray"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q279-jhrf-cc6v"}],"versionKeys":["pypi:ray@2.45.0","pypi:ray@2.49.1","pypi:ray@2.50.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-q2r8-vmq7-fpx2","slug":"ghsa-q2r8-vmq7-fpx2-63c75ef0","dossier":false,"summary":"MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability","aliases":["CVE-2026-2033","PYSEC-2026-2658"],"sourceIds":["GHSA-q2r8-vmq7-fpx2","PYSEC-2026-2658"],"published":"2026-02-21T00:31:43Z","modified":"2026-07-13T16:43:16.528255849Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2033"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/pull/19260"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/5bf2ec2bd4222a18d78631183ac7f6b752afe8a4"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/releases/tag/v3.8.0rc0"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-26-105"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2r8-vmq7-fpx2"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-q2wp-rjmx-x6x9","slug":"ghsa-q2wp-rjmx-x6x9-43135d3d","dossier":false,"summary":"Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking","aliases":["CVE-2025-3263","PYSEC-2026-1987"],"sourceIds":["GHSA-q2wp-rjmx-x6x9","PYSEC-2026-1987"],"published":"2025-07-07T12:30:22Z","modified":"2026-07-07T17:56:57.889099913Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3263"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/0720e206c6ba28887e4d60ef60a6a089f6c1cc76"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/126abe3461762e5fc180e7e614391d1b4ab051ca"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/c7a69150-54f8-4e81-8094-791e7a2a0f29"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2wp-rjmx-x6x9"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-q2x7-8rv6-6q7h","slug":"ghsa-q2x7-8rv6-6q7h-1113a288","dossier":false,"summary":"Jinja has a sandbox breakout through indirect reference to format method","aliases":["CVE-2024-56326","PYSEC-2026-1475"],"sourceIds":["GHSA-q2x7-8rv6-6q7h","PYSEC-2026-1475"],"published":"2024-12-23T17:56:08Z","modified":"2026-07-07T17:56:44.376174317Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56326"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2x7-8rv6-6q7h"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-q34m-jh98-gwm2","slug":"ghsa-q34m-jh98-gwm2-76f8ef0b","dossier":false,"summary":"Werkzeug possible resource exhaustion when parsing file data in forms","aliases":["CVE-2024-49767","PYSEC-2026-1860","PYSEC-2026-3417"],"sourceIds":["GHSA-q34m-jh98-gwm2","PYSEC-2026-3417"],"published":"2024-10-25T19:44:43Z","modified":"2026-07-13T16:43:34.482065524Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49767"},{"type":"WEB","url":"https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee"},{"type":"WEB","url":"https://github.com/pallets/quart/commit/abb04a512496206de279225340ed022852fbf51f"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/50cfeebcb0727e18cc52ffbeb125f4a66551179b"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/cbb446fdcada7685fce936ded01b76c08dbd6eb5"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.0.6"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250103-0007"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q34m-jh98-gwm2"}],"versionKeys":["pypi:werkzeug@3.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-q5fh-2hc8-f6rq","slug":"ghsa-q5fh-2hc8-f6rq-8b758e91","dossier":false,"summary":"Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)","aliases":["CVE-2026-27482","PYSEC-2026-2271"],"sourceIds":["GHSA-q5fh-2hc8-f6rq","PYSEC-2026-2271"],"published":"2026-02-20T21:15:25Z","modified":"2026-07-13T07:26:45.034743516Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/ray-project/ray/security/advisories/GHSA-q5fh-2hc8-f6rq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27482"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/60526"},{"type":"FIX","url":"https://github.com/ray-project/ray/commit/0fda8b824cdc9dc6edd763bb28dfd7d1cc9b02a4"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"},{"type":"ADVISORY","url":"https://github.com/ray-project/ray/releases/tag/ray-2.54.0"}],"versionKeys":["pypi:ray@2.45.0","pypi:ray@2.49.1","pypi:ray@2.50.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-q8gq-377p-jq3r","slug":"ghsa-q8gq-377p-jq3r-b6095d17","dossier":false,"summary":"vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution","aliases":["CVE-2026-41523","PYSEC-2026-2300"],"sourceIds":["GHSA-q8gq-377p-jq3r","PYSEC-2026-2300"],"published":"2026-06-16T17:34:49Z","modified":"2026-07-17T16:30:30.544440776Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-q8gq-377p-jq3r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41523"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-41523"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491582"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2300.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-qccp-gfcp-xxvc","slug":"ghsa-qccp-gfcp-xxvc-0d988969","dossier":true,"summary":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects","aliases":["CVE-2026-44431","PYSEC-2026-141"],"sourceIds":["GHSA-qccp-gfcp-xxvc","PYSEC-2026-141"],"published":"2026-05-11T14:51:20Z","modified":"2026-05-20T09:19:20.983812Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-qfhq-4f3w-5fph","slug":"ghsa-qfhq-4f3w-5fph-33bc3f14","dossier":false,"summary":"PyTorch is vulnerable to memory corruption through its torch.lstm_cell function","aliases":["BIT-pytorch-2025-3001","CVE-2025-3001","PYSEC-2025-195"],"sourceIds":["GHSA-qfhq-4f3w-5fph"],"published":"2025-03-31T18:31:08Z","modified":"2026-06-10T18:26:26.736808954Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3001"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149626"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149626#issue-2935860995"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/999d94b5ede5f4ec111ba7dd144129e2c2725b03"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-195.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302050"},{"type":"WEB","url":"https://vuldb.com/?id.302050"},{"type":"WEB","url":"https://vuldb.com/?submit.524212"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-qh4c-xf7m-gxfc","slug":"ghsa-qh4c-xf7m-gxfc-81424acf","dossier":false,"summary":"vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector","aliases":["CVE-2026-24779","PYSEC-2026-2020"],"sourceIds":["GHSA-qh4c-xf7m-gxfc","PYSEC-2026-2020"],"published":"2026-01-28T16:14:28Z","modified":"2026-07-17T16:30:32.009053490Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24779"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/32746"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/f46d576c54fb8aeec5fc70560e850bed38ef17d7"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24779.json"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2020.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qh4c-xf7m-gxfc"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433624"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-24779"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30088"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-qmgc-5h2g-mvrw","slug":"ghsa-qmgc-5h2g-mvrw-199eacc8","dossier":false,"summary":"filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock","aliases":["CVE-2026-22701","PYSEC-2026-1374"],"sourceIds":["GHSA-qmgc-5h2g-mvrw","PYSEC-2026-1374"],"published":"2026-01-13T18:44:55Z","modified":"2026-07-07T17:56:19.485233787Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22701"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qmgc-5h2g-mvrw"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-qq3j-4f4f-9583","slug":"ghsa-qq3j-4f4f-9583-cd76c72c","dossier":false,"summary":"Hugging Face Transformers Regular Expression Denial of Service","aliases":["CVE-2025-2099","PYSEC-2025-40"],"sourceIds":["GHSA-qq3j-4f4f-9583","PYSEC-2025-40"],"published":"2025-05-19T12:15:19Z","modified":"2026-06-10T17:02:48.111891265Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2099"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/36648"},{"type":"FIX","url":"https://github.com/huggingface/transformers/commit/8cb522b4190bd556ce51be04942720650b1a3e57"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2025-40.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/97b780f3-ffca-424f-ad5d-0e1c57a5bde4"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qq3j-4f4f-9583"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qxrp-vhvm-j765","slug":"ghsa-qxrp-vhvm-j765-63c6e9a2","dossier":false,"summary":"Deserialization of Untrusted Data in Hugging Face Transformers","aliases":["CVE-2024-11392","PYSEC-2024-227"],"sourceIds":["GHSA-qxrp-vhvm-j765","PYSEC-2024-227"],"published":"2024-11-22T22:15:06Z","modified":"2026-06-10T17:02:35.857656186Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11392"},{"type":"WEB","url":"https://github.com/huggingface/transformers/issues/34840"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/35296"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2024-227.yaml"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-24-1513"},{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-24-1513/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qxrp-vhvm-j765"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-r23q-823p-vmf7","slug":"ghsa-r23q-823p-vmf7-9a5ef709","dossier":false,"summary":"MLflow Command Injection vulnerability","aliases":["BIT-mlflow-2025-15379","CVE-2025-15379","PYSEC-2026-423"],"sourceIds":["GHSA-r23q-823p-vmf7","PYSEC-2026-423"],"published":"2026-03-30T09:31:28Z","modified":"2026-07-01T20:22:58.350388Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15379"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/361b6f620adf98385c6721e384fb5ef9a30bb05e"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/a22ce7157f646bdce4c95106fc38ccc9ca289205"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/dc9c1c20-7879-4050-87df-4d095fe5ca75"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r23q-823p-vmf7"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-r5m9-wm49-959f","slug":"ghsa-r5m9-wm49-959f-62964e46","dossier":false,"summary":"MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions","aliases":["BIT-mlflow-2026-3198","CVE-2026-3198","PYSEC-2026-2659"],"sourceIds":["GHSA-r5m9-wm49-959f","PYSEC-2026-2659"],"published":"2026-06-02T06:30:26Z","modified":"2026-07-13T16:42:37.733340178Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3198"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a1a67f8fc5ef12c9"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/e57db731-97d3-40c3-a429-831ee959807f"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r5m9-wm49-959f"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-r6ph-v2qm-q3c2","slug":"ghsa-r6ph-v2qm-q3c2-c75907df","dossier":false,"summary":"cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves","aliases":["CVE-2026-26007","PYSEC-2026-2141"],"sourceIds":["GHSA-r6ph-v2qm-q3c2","PYSEC-2026-2141"],"published":"2026-02-10T21:27:06Z","modified":"2026-07-13T07:26:47.289183808Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26007"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pyca/cryptography/releases/tag/46.0.5"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-26007"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:12176"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13553"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13672"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19355"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21517"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22330"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22993"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2694"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-r73j-pqj5-w3x7","slug":"ghsa-r73j-pqj5-w3x7-8d4d543f","dossier":true,"summary":"Pillow has a PDF Parsing Trailer Infinite Loop (DoS)","aliases":["BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874"],"sourceIds":["GHSA-r73j-pqj5-w3x7","PYSEC-2026-2874"],"published":"2026-05-04T20:19:30Z","modified":"2026-07-13T16:42:37.358429541Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-r73j-pqj5-w3x7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42310"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9519"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3bf614e4b8615d0ce1d5039efaf6db447fe7c468"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r73j-pqj5-w3x7"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-r95x-qfjj-fjj2","slug":"ghsa-r95x-qfjj-fjj2-df4fdb80","dossier":false,"summary":"Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect","aliases":["CVE-2026-44681","PYSEC-2026-188"],"sourceIds":["GHSA-r95x-qfjj-fjj2","PYSEC-2026-188"],"published":"2026-05-13T01:36:03Z","modified":"2026-06-09T00:00:25.468861825Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44681"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/authlib/authlib/releases/tag/v1.6.12"},{"type":"WEB","url":"https://github.com/authlib/authlib/releases/tag/v1.7.1"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-188.yaml"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-rcfx-77hg-w2wv","slug":"ghsa-rcfx-77hg-w2wv-60228d8d","dossier":false,"summary":"FastMCP updated to MCP 1.23+ due to CVE-2025-66416","aliases":[],"sourceIds":["GHSA-rcfx-77hg-w2wv"],"published":"2025-12-26T23:20:50Z","modified":"2025-12-26T23:27:27.257304Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-rcfx-77hg-w2wv"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-9h52-p55h-vw2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66416"},{"type":"PACKAGE","url":"https://github.com/jlowin/fastmcp"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-rcv9-qm8p-9p6j","slug":"ghsa-rcv9-qm8p-9p6j-edc1db04","dossier":false,"summary":"Hugging Face Transformers library has Regular Expression Denial of Service","aliases":["CVE-2025-6051","PYSEC-2026-1988"],"sourceIds":["GHSA-rcv9-qm8p-9p6j","PYSEC-2026-1988"],"published":"2025-09-14T18:30:26Z","modified":"2026-07-07T17:56:51.178415128Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6051"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/38844"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/54a02160eb030da9be18231c77791f2eb3a52216"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/ba8eaba9865618253f997784aa565b96206426f0"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/af929523-7b59-418a-bf55-301830b2ac9d"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rcv9-qm8p-9p6j"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-rgxp-2hwp-jwgg","slug":"ghsa-rgxp-2hwp-jwgg-76cdda06","dossier":false,"summary":"Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering","aliases":["CVE-2026-25087","PYSEC-2026-113"],"sourceIds":["GHSA-rgxp-2hwp-jwgg","PYSEC-2026-113"],"published":"2026-02-17T14:16:01.947Z","modified":"2026-06-12T10:29:15.451071539Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25087"},{"type":"FIX","url":"https://github.com/apache/arrow/pull/48925"},{"type":"PACKAGE","url":"https://github.com/apache/arrow"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyarrow/PYSEC-2026-113.yaml"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/mpm4ld1qony30tchfpjtk5b11tcyvmwh"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rgxp-2hwp-jwgg"}],"versionKeys":["pypi:pyarrow@18.1.0","pypi:pyarrow@20.0.0","pypi:pyarrow@21.0.0","pypi:pyarrow@22.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-rj5c-58rq-j5g5","slug":"ghsa-rj5c-58rq-j5g5-60d8d6a7","dossier":false,"summary":"FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name","aliases":["CVE-2025-62801","PYSEC-2026-1365"],"sourceIds":["GHSA-rj5c-58rq-j5g5","PYSEC-2026-1365"],"published":"2025-10-29T15:39:03Z","modified":"2026-07-07T17:56:56.677841650Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-rj5c-58rq-j5g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62801"},{"type":"PACKAGE","url":"https://github.com/jlowin/fastmcp"},{"type":"PACKAGE","url":"https://pypi.org/project/fastmcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rj5c-58rq-j5g5"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-rpm5-65cw-6hj4","slug":"ghsa-rpm5-65cw-6hj4-6c97dd77","dossier":false,"summary":"GitPython has Command Injection via Git options bypass","aliases":["CVE-2026-42215","PYSEC-2026-2160"],"sourceIds":["GHSA-rpm5-65cw-6hj4","PYSEC-2026-2160"],"published":"2026-04-25T23:42:16Z","modified":"2026-07-13T07:26:42.486885613Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42215"},{"type":"PACKAGE","url":"https://github.com/gitpython-developers/GitPython"},{"type":"FIX","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47"}],"versionKeys":["pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-rrmf-rvhw-rf47","slug":"ghsa-rrmf-rvhw-rf47-389d8330","dossier":false,"summary":"PyTorch is vulnerable to memory corruption through its torch.jit.script function","aliases":["BIT-pytorch-2025-3000","CVE-2025-3000","PYSEC-2025-194"],"sourceIds":["GHSA-rrmf-rvhw-rf47"],"published":"2025-03-31T15:30:48Z","modified":"2026-07-17T17:15:51.452848951Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3000"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149623"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149623#issue-2935703015"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/b90c94991cdf8b87c8f7439f79518e0ef2c4ca4f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-194.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302049"},{"type":"WEB","url":"https://vuldb.com/?id.302049"},{"type":"WEB","url":"https://vuldb.com/?submit.524197"}],"versionKeys":["pypi:torch@2.10.0","pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-rvhj-8chj-8v3c","slug":"ghsa-rvhj-8chj-8v3c-edfd1899","dossier":false,"summary":"Mlflow: Command Injection when serving models with enable_mlserver=True","aliases":["BIT-mlflow-2026-0596","CVE-2026-0596","PYSEC-2026-424"],"sourceIds":["GHSA-rvhj-8chj-8v3c","PYSEC-2026-424"],"published":"2026-03-31T15:31:56Z","modified":"2026-07-01T20:22:58.365246Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0596"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/pull/19738"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/202fac4c83ccc8544c087c142b80196d0e60695c"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/2e905add-f9f5-4309-a3db-b17de5981285"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rvhj-8chj-8v3c"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-rww4-4w9c-7733","slug":"ghsa-rww4-4w9c-7733-0e0ef0e5","dossier":false,"summary":"FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities","aliases":["CVE-2026-27124","PYSEC-2026-2476"],"sourceIds":["GHSA-rww4-4w9c-7733","PYSEC-2026-2476"],"published":"2026-03-31T22:32:28Z","modified":"2026-07-18T14:44:30.738106660Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733"},{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-rww4-4w9c-7733"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27124"},{"type":"PACKAGE","url":"https://github.com/PrefectHQ/fastmcp"},{"type":"PACKAGE","url":"https://pypi.org/project/fastmcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rww4-4w9c-7733"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-rwxx-mrjm-wc2m","slug":"ghsa-rwxx-mrjm-wc2m-e234c364","dossier":false,"summary":"vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends","aliases":["CVE-2026-55574","PYSEC-2026-2304"],"sourceIds":["GHSA-rwxx-mrjm-wc2m","PYSEC-2026-2304"],"published":"2026-07-06T21:16:57.347Z","modified":"2026-07-17T17:15:51.409816079Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55574"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/45118"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2304.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-rxc4-3w6r-4v47","slug":"ghsa-rxc4-3w6r-4v47-0c8c9269","dossier":false,"summary":"vllm API endpoints vulnerable to Denial of Service Attacks","aliases":["CVE-2025-48956","PYSEC-2026-2021"],"sourceIds":["GHSA-rxc4-3w6r-4v47","PYSEC-2026-2021"],"published":"2025-08-21T14:24:16Z","modified":"2026-07-17T16:30:30.538696375Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-rxc4-3w6r-4v47"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48956"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/23267"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/d8b736f913a59117803d6701521d2e4861701944"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rxc4-3w6r-4v47"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2021.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-v87r-6q3f-2j67","slug":"ghsa-v87r-6q3f-2j67-81913ca6","dossier":false,"summary":"GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath","aliases":["CVE-2026-44244","PYSEC-2026-2163"],"sourceIds":["GHSA-v87r-6q3f-2j67","PYSEC-2026-2163"],"published":"2026-05-06T21:58:00Z","modified":"2026-07-13T07:26:38.585123077Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44244"},{"type":"PACKAGE","url":"https://github.com/gitpython-developers/GitPython"},{"type":"FIX","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49"}],"versionKeys":["pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-v92g-xgxw-vvmm","slug":"ghsa-v92g-xgxw-vvmm-8ea08169","dossier":false,"summary":"Mako: Path traversal via double-slash URI prefix in TemplateLookup","aliases":["CVE-2026-41205","PYSEC-2026-88"],"sourceIds":["GHSA-v92g-xgxw-vvmm","PYSEC-2026-88"],"published":"2026-04-16T21:16:40Z","modified":"2026-06-05T14:16:15.268937299Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://github.com/sqlalchemy/mako/security/advisories/GHSA-v92g-xgxw-vvmm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41205"},{"type":"WEB","url":"https://github.com/sqlalchemy/mako/commit/e05ac61989a7fb9dd7dcde6cfd72dc48328719a3"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mako/PYSEC-2026-88.yaml"},{"type":"PACKAGE","url":"https://github.com/sqlalchemy/mako"},{"type":"WEB","url":"https://github.com/sqlalchemy/mako/releases/tag/rel_1_3_11"}],"versionKeys":["pypi:mako@1.3.10","pypi:mako@1.3.8"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-v9pg-7xvm-68hf","slug":"ghsa-v9pg-7xvm-68hf-bd9c7524","dossier":false,"summary":"python-multipart: Negative Content-Length in parse_form buffers the entire body in memory","aliases":["CVE-2026-53540","PYSEC-2026-3040"],"sourceIds":["GHSA-v9pg-7xvm-68hf","PYSEC-2026-3040"],"published":"2026-06-15T20:23:45Z","modified":"2026-07-13T16:43:20.711288699Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-v9pg-7xvm-68hf"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v9pg-7xvm-68hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53540"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-vffw-93wf-4j4q","slug":"ghsa-vffw-93wf-4j4q-3828c302","dossier":false,"summary":"python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters","aliases":["CVE-2026-53537","PYSEC-2026-3041"],"sourceIds":["GHSA-vffw-93wf-4j4q","PYSEC-2026-3041"],"published":"2026-06-15T20:20:51Z","modified":"2026-07-15T22:30:45.845963114Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-vffw-93wf-4j4q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53537"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vffw-93wf-4j4q"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/blob/main/vulns/python-multipart/PYSEC-2026-3041.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-vgrw-7cvw-pwgx","slug":"ghsa-vgrw-7cvw-pwgx-766c6098","dossier":false,"summary":"PyTorch is vulnerable to memory corruption through its unpack_sequence function","aliases":["BIT-pytorch-2025-2999","CVE-2025-2999","PYSEC-2025-193"],"sourceIds":["GHSA-vgrw-7cvw-pwgx"],"published":"2025-03-31T15:30:48Z","modified":"2026-06-10T17:41:15.774477397Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2999"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622#issue-2935495265"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-193.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302048"},{"type":"WEB","url":"https://vuldb.com/?id.302048"},{"type":"WEB","url":"https://vuldb.com/?submit.524198"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-vhcx-3pq2-4fvc","slug":"ghsa-vhcx-3pq2-4fvc-4147c43c","dossier":false,"summary":"MLFlow path traversal vulnerability","aliases":["BIT-mlflow-2025-15036","CVE-2025-15036","PYSEC-2026-425"],"sourceIds":["GHSA-vhcx-3pq2-4fvc","PYSEC-2026-425"],"published":"2026-03-30T03:30:19Z","modified":"2026-07-01T20:22:58.380148Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15036"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/3bf6d81ac4d38654c8ff012dbd0c3e9f17e7e346"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/36c314cf-fd6e-4fb0-b9b0-1b47bcdf0eb0"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vhcx-3pq2-4fvc"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-vj7q-gjh5-988w","slug":"ghsa-vj7q-gjh5-988w-54882ae8","dossier":false,"summary":"MCP Python SDK: WebSocket server transport does not support Host/Origin validation","aliases":["CVE-2026-59950"],"sourceIds":["GHSA-vj7q-gjh5-988w"],"published":"2026-07-16T20:14:34Z","modified":"2026-07-16T20:30:09.565200126Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-vj7q-gjh5-988w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59950"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2992"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.28.1"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-vqfr-h8mv-ghfj","slug":"ghsa-vqfr-h8mv-ghfj-49515033","dossier":false,"summary":"h11 accepts some malformed Chunked-Encoding bodies","aliases":["CVE-2025-43859","PYSEC-2026-348"],"sourceIds":["GHSA-vqfr-h8mv-ghfj","PYSEC-2026-348"],"published":"2025-04-24T16:07:56Z","modified":"2026-07-01T20:22:54.082067Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43859"},{"type":"WEB","url":"https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h11"},{"type":"PACKAGE","url":"https://pypi.org/project/h11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqfr-h8mv-ghfj"}],"versionKeys":["pypi:h11@0.14.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-vrq3-r879-7m65","slug":"ghsa-vrq3-r879-7m65-0fc59d0f","dossier":false,"summary":"vLLM Tool Schema allows DoS via Malformed pattern and type Fields","aliases":["CVE-2025-48944","PYSEC-2026-2023"],"sourceIds":["GHSA-vrq3-r879-7m65","PYSEC-2026-2023"],"published":"2025-05-28T19:42:32Z","modified":"2026-07-17T16:30:29.005158547Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-vrq3-r879-7m65"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48944"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/17623"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vrq3-r879-7m65"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2023.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vv7q-7jx5-f767","slug":"ghsa-vv7q-7jx5-f767-0be97d94","dossier":false,"summary":"FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability","aliases":["CVE-2026-32871","PYSEC-2026-338"],"sourceIds":["GHSA-vv7q-7jx5-f767","PYSEC-2026-338"],"published":"2026-03-31T22:53:21Z","modified":"2026-07-18T14:44:31.819120844Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-vv7q-7jx5-f767"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32871"},{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/pull/3507"},{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/commit/40bdfb6b1de0ce30609ee9ba5bb95ecd04a9fb71"},{"type":"PACKAGE","url":"https://github.com/PrefectHQ/fastmcp"},{"type":"WEB","url":"https://github.com/PrefectHQ/fastmcp/releases/tag/v3.2.0"},{"type":"PACKAGE","url":"https://pypi.org/project/fastmcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vv7q-7jx5-f767"}],"versionKeys":["pypi:fastmcp@2.12.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-w2fm-2cpv-w7v5","slug":"ghsa-w2fm-2cpv-w7v5-c2f7701a","dossier":false,"summary":"aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage","aliases":["CVE-2026-22815","PYSEC-2026-2094"],"sourceIds":["GHSA-w2fm-2cpv-w7v5","PYSEC-2026-2094"],"published":"2026-04-01T19:45:17Z","modified":"2026-07-13T07:26:28.950069528Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-w2fm-2cpv-w7v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22815"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-w5xq-c4pf-ghq7","slug":"ghsa-w5xq-c4pf-ghq7-a926672a","dossier":false,"summary":"MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks","aliases":["BIT-mlflow-2026-2734","CVE-2026-2734","PYSEC-2026-2660"],"sourceIds":["GHSA-w5xq-c4pf-ghq7","PYSEC-2026-2660"],"published":"2026-05-21T06:31:31Z","modified":"2026-07-13T16:43:34.965176091Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2734"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a1a67f8fc5ef12c9"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://huntr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w5xq-c4pf-ghq7"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-w6q7-j642-7c25","slug":"ghsa-w6q7-j642-7c25-391074f5","dossier":false,"summary":"vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`","aliases":["CVE-2025-48887","PYSEC-2025-50"],"sourceIds":["GHSA-w6q7-j642-7c25","PYSEC-2025-50"],"published":"2025-05-28T17:49:33Z","modified":"2026-06-10T17:14:19.371824623Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-w6q7-j642-7c25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48887"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/18454"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/4fc1bf813ad80172c1db31264beaef7d93fe0601"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-50.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w6q7-j642-7c25"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-w6vg-jg77-2qg6","slug":"ghsa-w6vg-jg77-2qg6-e819e20a","dossier":false,"summary":"MLX has heap-buffer-overflow in load()","aliases":["CVE-2025-62608","PYSEC-2025-138"],"sourceIds":["GHSA-w6vg-jg77-2qg6","PYSEC-2025-138"],"published":"2025-11-21T18:02:38Z","modified":"2026-06-06T00:45:48.146084644Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/ml-explore/mlx/security/advisories/GHSA-w6vg-jg77-2qg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62608"},{"type":"FIX","url":"https://github.com/ml-explore/mlx/pull/1"},{"type":"FIX","url":"https://github.com/ml-explore/mlx/pull/2"},{"type":"PACKAGE","url":"https://github.com/ml-explore/mlx"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mlx/PYSEC-2025-138.yaml"}],"versionKeys":["pypi:mlx@0.29.0","pypi:mlx@0.29.3"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-w853-jp5j-5j7f","slug":"ghsa-w853-jp5j-5j7f-2786386f","dossier":false,"summary":"filelock has a TOCTOU race condition which allows symlink attacks during lock file creation","aliases":["CVE-2025-68146","PYSEC-2026-1375"],"sourceIds":["GHSA-w853-jp5j-5j7f","PYSEC-2026-1375"],"published":"2025-12-16T20:52:55Z","modified":"2026-07-07T17:56:10.949145470Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/releases/tag/3.20.1"},{"type":"WEB","url":"https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants"},{"type":"WEB","url":"https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w853-jp5j-5j7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68146"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-w8p2-r796-3vmq","slug":"ghsa-w8p2-r796-3vmq-0e5f6b4f","dossier":false,"summary":"Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type","aliases":["CVE-2026-41479","PYSEC-2026-2119"],"sourceIds":["GHSA-w8p2-r796-3vmq","PYSEC-2026-2119"],"published":"2026-06-08T17:52:04Z","modified":"2026-07-18T17:30:29.215396840Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-w8p2-r796-3vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41479"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-2119.yaml"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-w8v5-vhqr-4h9v","slug":"ghsa-w8v5-vhqr-4h9v-05062d37","dossier":false,"summary":"DiskCache has unsafe pickle deserialization","aliases":["CVE-2025-69872","PYSEC-2026-2447"],"sourceIds":["GHSA-w8v5-vhqr-4h9v","PYSEC-2026-2447"],"published":"2026-02-11T21:30:39Z","modified":"2026-07-13T16:43:29.892158838Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69872"},{"type":"WEB","url":"https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69872-DiskCache-Pickle-Deserialization.md"},{"type":"PACKAGE","url":"https://github.com/grantjenks/python-diskcache"},{"type":"PACKAGE","url":"https://pypi.org/project/diskcache"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w8v5-vhqr-4h9v"}],"versionKeys":["pypi:diskcache@5.6.3"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-wcj4-jw5j-44wh","slug":"ghsa-wcj4-jw5j-44wh-9e6393c7","dossier":false,"summary":"CBORDecoder reuse can leak shareable values across decode calls","aliases":["CVE-2025-68131","PYSEC-2025-90"],"sourceIds":["GHSA-wcj4-jw5j-44wh","PYSEC-2025-90"],"published":"2025-12-31T02:15:42.527Z","modified":"2026-06-05T14:30:11.179250820Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/agronholm/cbor2/security/advisories/GHSA-wcj4-jw5j-44wh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68131"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/pull/268"},{"type":"WEB","url":"https://github.com/agronholm/cbor2/commit/f1d701cd2c411ee40bb1fe383afe7f365f35abf0"},{"type":"PACKAGE","url":"https://github.com/agronholm/cbor2"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cbor2/PYSEC-2025-90.yaml"}],"versionKeys":["pypi:cbor2@5.7.0","pypi:cbor2@5.7.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-wf7f-8fxf-xfxc","slug":"ghsa-wf7f-8fxf-xfxc-07509bf2","dossier":false,"summary":"MLFlow unsafe deserialization","aliases":["BIT-mlflow-2024-37059","CVE-2024-37059","PYSEC-2026-1660"],"sourceIds":["GHSA-wf7f-8fxf-xfxc","PYSEC-2026-1660"],"published":"2024-06-04T12:31:05Z","modified":"2026-07-07T17:56:49.672624556Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37059"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://hiddenlayer.com/sai-security-advisory/mlflow-june2024"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wf7f-8fxf-xfxc"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-whj4-6x5x-4v2j","slug":"ghsa-whj4-6x5x-4v2j-eb5fc6a1","dossier":true,"summary":"FITS GZIP decompression bomb in Pillow","aliases":["BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250"],"sourceIds":["GHSA-whj4-6x5x-4v2j","PYSEC-2026-2250"],"published":"2026-04-13T19:22:35Z","modified":"2026-07-13T07:26:24.246094941Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40192"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9521"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40192"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16008"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16009"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17609"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17611"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19375"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21017"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22465"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22629"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22840"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-wjx4-4jcj-g98j","slug":"ghsa-wjx4-4jcj-g98j-e937161b","dossier":true,"summary":"Pillow has an integer overflow when processing fonts","aliases":["BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165"],"sourceIds":["GHSA-wjx4-4jcj-g98j","PYSEC-2026-165"],"published":"2026-05-04T20:18:45Z","modified":"2026-06-08T23:45:16.414580348Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42308"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-wp53-j4wj-2cfg","slug":"ghsa-wp53-j4wj-2cfg-22cec3c5","dossier":false,"summary":"Python-Multipart has Arbitrary File Write via Non-Default Configuration","aliases":["CVE-2026-24486","PYSEC-2026-1852"],"sourceIds":["GHSA-wp53-j4wj-2cfg","PYSEC-2026-1852"],"published":"2026-01-26T23:28:05Z","modified":"2026-07-07T17:57:28.813401667Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-wp53-j4wj-2cfg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24486"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/commit/9433f4bbc9652bdde82bbe380984e32f8cfc89c4"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/releases/tag/0.0.22"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wp53-j4wj-2cfg"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-wqp7-x3pw-xc5r","slug":"ghsa-wqp7-x3pw-xc5r-4caabf81","dossier":false,"summary":"Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows","aliases":["CVE-2026-48818","PYSEC-2026-2281"],"sourceIds":["GHSA-wqp7-x3pw-xc5r","PYSEC-2026-2281"],"published":"2026-06-15T20:16:30Z","modified":"2026-07-13T07:26:44.976412482Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-wqp7-x3pw-xc5r"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48818"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48818.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30087"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490020"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/fd53168a7767b6b55ba5af787fd88f49e33cabc5"},{"type":"FIX","url":"https://github.com/Kludex/starlette/pull/3287"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-wr9h-g72x-mwhm","slug":"ghsa-wr9h-g72x-mwhm-9f241db1","dossier":false,"summary":"vLLM is vulnerable to timing attack at bearer auth","aliases":["CVE-2025-59425","PYSEC-2026-2026"],"sourceIds":["GHSA-wr9h-g72x-mwhm","PYSEC-2026-2026"],"published":"2025-10-07T17:24:47Z","modified":"2026-07-17T16:30:30.606191061Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-wr9h-g72x-mwhm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59425"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/ee10d7e6ff5875386c7f136ce8b5f525c8fcef48"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wr9h-g72x-mwhm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2026.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/4b946d693e0af15740e9ca9c0e059d5f333b1083/vllm/entrypoints/openai/api_server.py#L1270-L1274"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-wrfc-pvp9-mr9g","slug":"ghsa-wrfc-pvp9-mr9g-c6b03ddf","dossier":false,"summary":"Deserialization of Untrusted Data in Hugging Face Transformers","aliases":["CVE-2024-11393","PYSEC-2024-228"],"sourceIds":["GHSA-wrfc-pvp9-mr9g","PYSEC-2024-228"],"published":"2024-11-22T22:15:07Z","modified":"2026-06-10T17:00:13.252500033Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11393"},{"type":"WEB","url":"https://github.com/huggingface/transformers/issues/34840"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/35296"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2024-228.yaml"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-24-1514"},{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-24-1514/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wrfc-pvp9-mr9g"}],"versionKeys":["pypi:transformers@4.47.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-wvwj-cvrp-7pv5","slug":"ghsa-wvwj-cvrp-7pv5-e187e76a","dossier":false,"summary":"Authlib JWS JWK Header Injection: Signature Verification Bypass","aliases":["CVE-2026-27962","PYSEC-2026-287"],"sourceIds":["GHSA-wvwj-cvrp-7pv5","PYSEC-2026-287"],"published":"2026-03-16T15:17:15Z","modified":"2026-07-13T16:15:15.641042659Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-wvwj-cvrp-7pv5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27962"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/a5d4b2d4c9e46bfa11c82f85fdc2bcc0b50ae681"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/authlib/authlib/releases/tag/v1.6.9"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wvwj-cvrp-7pv5"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-x2qx-6953-8485","slug":"ghsa-x2qx-6953-8485-107f8fe2","dossier":false,"summary":"GitPython: Unsafe option check validates multi_options before shlex.split transformation","aliases":["CVE-2026-42284","PYSEC-2026-2161"],"sourceIds":["GHSA-x2qx-6953-8485","PYSEC-2026-2161"],"published":"2026-04-25T23:41:49Z","modified":"2026-07-13T07:26:44.494568822Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42284"},{"type":"PACKAGE","url":"https://github.com/gitpython-developers/GitPython"},{"type":"FIX","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47"},{"type":"WEB","url":"https://www.tenable.com/cve/CVE-2026-32686"}],"versionKeys":["pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-x368-4g9h-fvv4","slug":"ghsa-x368-4g9h-fvv4-37873c2f","dossier":false,"summary":"vLLM makes Use of Uninitialized Resource","aliases":["CVE-2026-7141","PYSEC-2026-2306"],"sourceIds":["GHSA-x368-4g9h-fvv4","PYSEC-2026-2306"],"published":"2026-04-27T17:16:45.637Z","modified":"2026-07-13T16:45:11.279169812Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7141"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/39146"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/39146#issue-4215090365"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/39283"},{"type":"FIX","url":"https://github.com/AjAnubolu/vllm/commit/1ad67864c0c20f167929e64c875f5c28e1aad9fd"},{"type":"ADVISORY","url":"https://vuldb.com/submit/801297"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/359740"},{"type":"REPORT","url":"https://vuldb.com/vuln/359740/cti"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x368-4g9h-fvv4"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-x3gm-94wq-g975","slug":"ghsa-x3gm-94wq-g975-a197ba31","dossier":false,"summary":"PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module","aliases":["BIT-pytorch-2025-2149","CVE-2025-2149","PYSEC-2025-190"],"sourceIds":["GHSA-x3gm-94wq-g975"],"published":"2025-03-10T15:30:47Z","modified":"2026-06-09T22:11:08.734544854Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2149"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/147818"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/147818#issue-2877301660"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-190.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.299060"},{"type":"WEB","url":"https://vuldb.com/?id.299060"},{"type":"WEB","url":"https://vuldb.com/?submit.506563"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-x746-7m8f-x49c","slug":"ghsa-x746-7m8f-x49c-c0349d3f","dossier":false,"summary":"Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`","aliases":["CVE-2026-48817","PYSEC-2026-2280"],"sourceIds":["GHSA-x746-7m8f-x49c","PYSEC-2026-2280"],"published":"2026-06-15T20:16:05Z","modified":"2026-07-13T07:26:54.069698774Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48817"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-xcgm-r5h9-7989","slug":"ghsa-xcgm-r5h9-7989-77bcbc26","dossier":false,"summary":"aiohttp: Incomplete websocket frame payloads bypass memory limits","aliases":["CVE-2026-54274","PYSEC-2026-2108"],"sourceIds":["GHSA-xcgm-r5h9-7989","PYSEC-2026-2108"],"published":"2026-06-15T20:11:22Z","modified":"2026-07-13T07:26:54.330692251Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-xch3-2f9x-wh9f","slug":"ghsa-xch3-2f9x-wh9f-70e88660","dossier":false,"summary":"MLflow has a command injection in mlflow/sagemaker/__init__.py","aliases":["BIT-mlflow-2025-14287","CVE-2025-14287","PYSEC-2026-2661"],"sourceIds":["GHSA-xch3-2f9x-wh9f","PYSEC-2026-2661"],"published":"2026-03-16T15:30:41Z","modified":"2026-07-13T16:42:49.591762139Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14287"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/pull/19277"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/8b8792a7034fb33a14b0b31cabcaa9b912d3485f"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/releases/tag/v3.8.0rc0"},{"type":"WEB","url":"https://huntr.com/bounties/229cd526-41aa-4819-b6f0-e2d0371c89e3"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xch3-2f9x-wh9f"}],"versionKeys":["pypi:mlflow@3.1.1","pypi:mlflow@3.4.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-xg8h-j46f-w952","slug":"ghsa-xg8h-j46f-w952-da36a616","dossier":false,"summary":"Pillow vulnerability can cause write buffer overflow on BCn encoding","aliases":["BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61"],"sourceIds":["GHSA-xg8h-j46f-w952","PYSEC-2025-61"],"published":"2025-07-01T17:29:37Z","modified":"2026-02-04T03:49:31.268130Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48379"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9041"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2025-61.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/11.3.0"}],"versionKeys":["pypi:pillow@11.2.1"],"packageCount":1,"repositoryCount":4},{"id":"PYSEC-2025-198","slug":"pysec-2025-198-62b25ed4","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46148","CVE-2025-46148"],"sourceIds":["PYSEC-2025-198"],"published":"2025-09-25T15:16:12.007Z","modified":"2026-05-20T09:19:19.437232Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/65a587a579dfdff887b9b35bb79b9093"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151198"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/152993"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"PYSEC-2025-199","slug":"pysec-2025-199-c528cb5a","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46149","CVE-2025-46149"],"sourceIds":["PYSEC-2025-199"],"published":"2025-09-25T15:16:12.153Z","modified":"2026-05-20T09:19:19.498677Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/147848"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/147961"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-200","slug":"pysec-2025-200-d11172cd","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46150","CVE-2025-46150"],"sourceIds":["PYSEC-2025-200"],"published":"2025-09-25T15:16:12.303Z","modified":"2026-05-20T09:19:19.559970Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/141538"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/141538#issuecomment-2537424658"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/144395"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-201","slug":"pysec-2025-201-c002b022","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46152","CVE-2025-46152"],"sourceIds":["PYSEC-2025-201"],"published":"2025-09-25T15:16:12.470Z","modified":"2026-05-20T09:19:19.618679Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/143555"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/143635"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-202","slug":"pysec-2025-202-f0ff1751","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46153","CVE-2025-46153"],"sourceIds":["PYSEC-2025-202"],"published":"2025-09-25T15:16:12.603Z","modified":"2026-05-20T09:19:19.678555Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pytorch/pytorch/compare/v2.6.0...v2.7.0"},{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/e636f2e7a306105b7e96809e2b85c28a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/142853"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/143460"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-203","slug":"pysec-2025-203-2febb201","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55551","CVE-2025-55551"],"sourceIds":["PYSEC-2025-203"],"published":"2025-09-25T15:16:12.887Z","modified":"2026-05-20T09:19:19.739357Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151401"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-204","slug":"pysec-2025-204-cdae47da","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55552","CVE-2025-55552"],"sourceIds":["PYSEC-2025-204"],"published":"2025-09-25T16:15:34.320Z","modified":"2026-05-20T09:19:19.802802Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/147847"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-205","slug":"pysec-2025-205-fd5e58fd","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55553","CVE-2025-55553"],"sourceIds":["PYSEC-2025-205"],"published":"2025-09-25T16:15:34.460Z","modified":"2026-05-20T09:19:19.866970Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151432"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/154645"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-206","slug":"pysec-2025-206-58322476","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55554","CVE-2025-55554"],"sourceIds":["PYSEC-2025-206"],"published":"2025-09-25T16:15:34.593Z","modified":"2026-05-20T09:19:19.928295Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151510"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-207","slug":"pysec-2025-207-2abef3fc","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55557","CVE-2025-55557"],"sourceIds":["PYSEC-2025-207"],"published":"2025-09-25T16:15:34.833Z","modified":"2026-05-20T09:19:19.989717Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151738"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/151931"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-208","slug":"pysec-2025-208-6e93fe9d","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55558","CVE-2025-55558"],"sourceIds":["PYSEC-2025-208"],"published":"2025-09-25T16:15:34.960Z","modified":"2026-05-20T09:19:20.054109Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151523"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/151887"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-209","slug":"pysec-2025-209-e6f352b0","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55560","CVE-2025-55560"],"sourceIds":["PYSEC-2025-209"],"published":"2025-09-25T16:15:35.197Z","modified":"2026-05-20T09:19:20.117285Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151522"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/151897"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-211","slug":"pysec-2025-211-d8bd15de","dossier":false,"summary":null,"aliases":["CVE-2025-14920"],"sourceIds":["PYSEC-2025-211"],"published":"2025-12-23T21:15:47.183Z","modified":"2026-05-21T15:00:32.080516132Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1150/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-212","slug":"pysec-2025-212-a011b97d","dossier":false,"summary":null,"aliases":["CVE-2025-14921"],"sourceIds":["PYSEC-2025-212"],"published":"2025-12-23T21:15:47.340Z","modified":"2026-05-21T15:00:32.052313357Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1149/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-213","slug":"pysec-2025-213-9043dc9b","dossier":false,"summary":null,"aliases":["CVE-2025-14924"],"sourceIds":["PYSEC-2025-213"],"published":"2025-12-23T21:15:47.600Z","modified":"2026-05-21T15:00:32.048516839Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1141/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-214","slug":"pysec-2025-214-eb241255","dossier":false,"summary":null,"aliases":["CVE-2025-14926"],"sourceIds":["PYSEC-2025-214"],"published":"2025-12-23T21:15:47.857Z","modified":"2026-05-21T15:00:32.929011749Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1147/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-215","slug":"pysec-2025-215-6064f491","dossier":false,"summary":null,"aliases":["CVE-2025-14927"],"sourceIds":["PYSEC-2025-215"],"published":"2025-12-23T21:15:47.987Z","modified":"2026-05-21T15:00:32.888290877Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1148/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-216","slug":"pysec-2025-216-5708ed01","dossier":false,"summary":null,"aliases":["CVE-2025-14928"],"sourceIds":["PYSEC-2025-216"],"published":"2025-12-23T21:15:48.110Z","modified":"2026-05-21T15:00:32.939311939Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1146/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-217","slug":"pysec-2025-217-2c1ad388","dossier":false,"summary":null,"aliases":["CVE-2025-14929"],"sourceIds":["PYSEC-2025-217"],"published":"2025-12-23T21:15:48.240Z","modified":"2026-05-21T15:00:24.271970226Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1144/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1","pypi:transformers@4.57.1","pypi:transformers@4.57.3","pypi:transformers@4.57.4","pypi:transformers@4.57.6"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-218","slug":"pysec-2025-218-39811fc3","dossier":false,"summary":null,"aliases":["CVE-2025-14930"],"sourceIds":["PYSEC-2025-218"],"published":"2025-12-23T21:15:48.367Z","modified":"2026-05-21T15:00:33.791364554Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-25-1145/"}],"versionKeys":["pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1","pypi:transformers@4.57.1"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2025-238","slug":"pysec-2025-238-fe0347f8","dossier":false,"summary":null,"aliases":["CVE-2025-64076"],"sourceIds":["PYSEC-2025-238"],"published":"2025-11-18T18:16:14.263Z","modified":"2026-07-13T07:15:16.765464311Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"REPORT","url":"https://github.com/agronholm/cbor2/issues/264"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/commit/851473490281f82d82560b2368284ef33cf6e8f9"},{"type":"FIX","url":"https://github.com/agronholm/cbor2/pull/265"}],"versionKeys":["pypi:cbor2@5.7.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-139","slug":"pysec-2026-139-96951ff6","dossier":false,"summary":null,"aliases":["BIT-pytorch-2026-4538","CVE-2026-4538"],"sourceIds":["PYSEC-2026-139"],"published":"2026-03-22T05:16:20.273Z","modified":"2026-05-21T15:00:31.962442644Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pytorch/pytorch/"},{"type":"ADVISORY","url":"https://vuldb.com/?id.352326"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.774681"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.352326"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/176791"}],"versionKeys":["pypi:torch@2.10.0","pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":10},{"id":"PYSEC-2026-2132","slug":"pysec-2026-2132-627bf7c7","dossier":true,"summary":null,"aliases":["CVE-2026-7246","GHSA-47fr-3ffg-hgmw"],"sourceIds":["PYSEC-2026-2132"],"published":"2026-04-30T14:16:36.433Z","modified":"2026-07-13T07:15:21.899333658Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-7246"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464121"},{"type":"FIX","url":"https://github.com/pallets/click/releases/tag/8.3.3"},{"type":"EVIDENCE","url":"https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw"}],"versionKeys":["pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1"],"packageCount":1,"repositoryCount":14},{"id":"PYSEC-2026-2253","slug":"pysec-2026-2253-e1ccf3df","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-54059","CVE-2026-54059","GHSA-8v84-f9pq-wr9x"],"sourceIds":["PYSEC-2026-2253"],"published":"2026-07-06T19:17:08.127Z","modified":"2026-07-13T07:26:49.281845979Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2254","slug":"pysec-2026-2254-a1ed1fd2","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-54060","CVE-2026-54060","GHSA-5x94-69rx-g8h2"],"sourceIds":["PYSEC-2026-2254"],"published":"2026-07-06T19:17:08.270Z","modified":"2026-07-13T07:26:56.196935469Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2255","slug":"pysec-2026-2255-d0951b98","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55379","CVE-2026-55379","GHSA-45hq-cxwh-f6vc"],"sourceIds":["PYSEC-2026-2255"],"published":"2026-07-06T19:17:08.577Z","modified":"2026-07-13T07:26:26.726353373Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2256","slug":"pysec-2026-2256-0f333f0b","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55380","CVE-2026-55380","GHSA-phj9-mv4w-65pm"],"sourceIds":["PYSEC-2026-2256"],"published":"2026-07-06T19:17:08.703Z","modified":"2026-07-13T07:26:17.085341343Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2257","slug":"pysec-2026-2257-bcbe5d79","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55798","CVE-2026-55798","GHSA-4x4j-2g7c-83w6"],"sourceIds":["PYSEC-2026-2257"],"published":"2026-07-06T19:17:08.830Z","modified":"2026-07-13T07:26:48.229039344Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8a"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/88194166691b7b603529b8b036ab3ab9cedd2de4"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/b0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-227","slug":"pysec-2026-227-5f5a1d28","dossier":false,"summary":null,"aliases":["CVE-2026-54232","GHSA-jrf6-vqxq-pjv2"],"sourceIds":["PYSEC-2026-227"],"published":"2026-06-22T23:16:30.873Z","modified":"2026-06-26T00:00:06.054142968Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-jrf6-vqxq-pjv2"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-2273","slug":"pysec-2026-2273-c0c1a62e","dossier":false,"summary":null,"aliases":["CVE-2026-57516","GHSA-hhrp-gw25-jr43"],"sourceIds":["PYSEC-2026-2273"],"published":"2026-07-01T17:16:37.390Z","modified":"2026-07-13T07:15:44.097966037Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"ADVISORY","url":"https://github.com/ray-project/ray/releases/tag/ray-2.56.0"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ray-unsafe-deserialization-rce-via-webdataset-reader"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/63469"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/63470"},{"type":"FIX","url":"https://github.com/ray-project/ray/security/advisories/GHSA-hhrp-gw25-jr43"}],"versionKeys":["pypi:ray@2.45.0","pypi:ray@2.49.1","pypi:ray@2.50.1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-2286","slug":"pysec-2026-2286-8795b007","dossier":false,"summary":null,"aliases":["BIT-pytorch-2026-24747","CVE-2026-24747","GHSA-63cw-57p8-fm3p","PYSEC-2026-1856"],"sourceIds":["PYSEC-2026-2286"],"published":"2026-01-27T22:15:56.470Z","modified":"2026-07-13T07:26:23.701611780Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-24747"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24747.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://github.com/pytorch/pytorch/releases/tag/v2.10.0"},{"type":"ADVISORY","url":"https://github.com/pytorch/pytorch/security/advisories/GHSA-63cw-57p8-fm3p"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433612"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/163105"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/163122/commit/954dc5183ee9205cbe79876ad05dd2d9ae752139"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":9},{"id":"PYSEC-2026-2302","slug":"pysec-2026-2302-60c0b148","dossier":false,"summary":null,"aliases":["CVE-2026-5497"],"sourceIds":["PYSEC-2026-2302"],"published":"2026-06-11T10:16:21.903Z","modified":"2026-07-13T07:15:46.584903724Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-5497"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5497.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487813"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/58ee61422169ce17e08248f8efa1e9df434fe395"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/7bd92629-b396-4449-8f88-6c0092530eb4"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-3447","slug":"pysec-2026-3447-df031425","dossier":true,"summary":null,"aliases":["BIT-setuptools-2026-59890","CVE-2026-59890","GHSA-h35f-9h28-mq5c"],"sourceIds":["PYSEC-2026-3447"],"published":"2026-07-08T17:17:27.020Z","modified":"2026-07-14T10:56:37.948360943Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/pypa/setuptools/releases/tag/v83.0.0"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f"},{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@75.8.0","pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@82.0.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3451","slug":"pysec-2026-3451-3e5eac34","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-59199","CVE-2026-59199","GHSA-6r8x-57c9-28j4"],"sourceIds":["PYSEC-2026-3451"],"published":"2026-07-14T16:17:01.937Z","modified":"2026-07-15T20:11:36.266805254Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9703"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3452","slug":"pysec-2026-3452-0999fd2a","dossier":false,"summary":null,"aliases":["BIT-pillow-2026-59203","CVE-2026-59203","GHSA-pg7v-jwj7-p798"],"sourceIds":["PYSEC-2026-3452"],"published":"2026-07-14T16:17:02.063Z","modified":"2026-07-15T20:11:27.953713427Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9708"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798"}],"versionKeys":["pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":4},{"id":"PYSEC-2026-3453","slug":"pysec-2026-3453-83974725","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-59205","CVE-2026-59205","GHSA-9hw9-ch79-4vh6"],"sourceIds":["PYSEC-2026-3453"],"published":"2026-07-14T16:17:02.370Z","modified":"2026-07-15T20:11:15.582336837Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9715"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13}]}}
