{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-31T19:03:09.699Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-31T19:01:26.023Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":31,"completeTreeCount":30,"incompleteTreeCount":1,"lockfileRepositoryCount":18,"sbomRepositoryCount":4,"artifactRepositoryCount":21,"resolvedRepositoryCount":30,"resolvedArtifactRepositoryCount":21,"dependencyFileCount":32,"parsedFileCount":31,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":3642,"metadataResolvedCount":3632,"metadataNotFoundCount":10,"osvEvaluatedVersionCount":3642,"codeRadarRepositoryCount":31},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":8000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":31,"packageCount":2274,"aiPackageCount":44,"resolvedComponentCount":5994,"resolvedVersionCount":3642,"providerExposureRepositoryCount":6,"licenseExpressionCount":53,"knownLicensePackageCount":2244,"unknownLicensePackageCount":30,"advisoryCount":596,"matchedAdvisoryRepositoryCount":26,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":19,"repositoryShare":0.6129032258064516}},"kind":"repository","entity":{"id":"opencode:12239","slug":"opencode-12239","gitlabProjectId":12239,"name":"LLM Service","pathWithNamespace":"sh/diwish/splitbot/kosmo/llm-service","description":null,"webUrl":"https://gitlab.opencode.de/sh/diwish/splitbot/kosmo/llm-service","commitSha":"318cda8c49da743f2c4a18a4f4d5c36fc22102fc","commitUrl":"https://gitlab.opencode.de/sh/diwish/splitbot/kosmo/llm-service/-/commit/318cda8c49da743f2c4a18a4f4d5c36fc22102fc","lastActivityAt":"2026-07-31T12:19:47.438Z","headCommittedAt":"2026-07-31T10:12:04.000Z","tree":{"complete":true,"entryCount":241,"truncated":false},"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"5c34ec93b8f084fb238b9dfb84642a3091538e9d","sourceUrl":"https://gitlab.opencode.de/sh/diwish/splitbot/kosmo/llm-service/-/blob/318cda8c49da743f2c4a18a4f4d5c36fc22102fc/uv.lock","commitSha":"318cda8c49da743f2c4a18a4f4d5c36fc22102fc","contentSha256":"72d385efaa1c9d7ef74ecd2177161e9b80f5ec89cc764f9cf3892c4a65408df2","byteCount":466608,"state":"parsed","componentCount":303}],"resolvedComponentCount":303,"artifactResolvedComponentCount":303,"exactManifestPinCount":0,"packageCount":303,"ecosystems":["pypi"],"aiPackageCount":17,"licenseExpressionCount":26,"unknownLicensePackageCount":3,"advisoryIds":["GHSA-248m-82v9-q6g6","GHSA-248v-346w-9cwc","GHSA-24qx-w28j-9m6p","GHSA-2c2j-9gv5-cj73","GHSA-2fqr-mr3j-6wp8","GHSA-2g6r-c272-w58r","GHSA-2hm2-hc3v-44h9","GHSA-2q4j-m29v-hq73","GHSA-2rw7-x74f-jg35","GHSA-2vrm-gr82-f7m5","GHSA-2wc2-fm75-p42x","GHSA-2xpw-w6gg-jr37","GHSA-33p9-3p43-82vq","GHSA-3644-q5cj-c5c7","GHSA-37w4-hwhx-4rc4","GHSA-38jv-5279-wg99","GHSA-3crg-w4f6-42mx","GHSA-3wq7-rqq7-wx6j","GHSA-3x9g-8vmp-wqvf","GHSA-428g-f7cq-pgp5","GHSA-45hq-cxwh-f6vc","GHSA-45pg-36p6-83v9","GHSA-469j-vmhf-r6v7","GHSA-48p4-8xcf-vxj5","GHSA-4c99-qj7h-p3vg","GHSA-4f6g-68pf-7vhv","GHSA-4fvr-rgm6-gqmc","GHSA-4j32-57v6-6g45","GHSA-4m7w-qmgq-4wj5","GHSA-4pxv-j86v-mhcw","GHSA-4x4j-2g7c-83w6","GHSA-4xc4-762w-m6cg","GHSA-4xgf-cpjx-pc3j","GHSA-5239-wwwm-4pmq","GHSA-52x6-gq3r-vpf4","GHSA-537c-gmf6-5ccf","GHSA-54jq-c3m8-4m76","GHSA-55h5-xmcq-c37v","GHSA-5789-5fc7-67v3","GHSA-58cw-g322-p94v","GHSA-59g5-xgcq-4qw3","GHSA-5chr-fjjv-38qv","GHSA-5hgr-hg42-57jg","GHSA-5mrq-x3x5-8v8f","GHSA-5qjq-93h5-hrgp","GHSA-5rjg-fvgr-3xxf","GHSA-5rvq-cxj2-64vf","GHSA-5x94-69rx-g8h2","GHSA-5xf7-4p34-54qr","GHSA-5xmw-vc9v-4wf2","GHSA-62p4-gmf7-7g93","GHSA-63hf-3vf5-4wqf","GHSA-63hw-fmq6-xxg2","GHSA-63vm-454h-vhhq","GHSA-65pc-fj4g-8rjx","GHSA-68j8-pq59-fqgm","GHSA-69f9-5gxw-wvc2","GHSA-6hm5-jgcp-p838","GHSA-6jhg-hg63-jvvf","GHSA-6jv3-5f52-599m","GHSA-6mq8-rvhq-8wgg","GHSA-6qv9-48xg-fc7f","GHSA-6r8x-57c9-28j4","GHSA-6w46-j5rx-g56g","GHSA-7432-952r-cw78","GHSA-752w-5fwx-jx9f","GHSA-78cv-mqj4-43f7","GHSA-79v4-65xg-pq4g","GHSA-7cx3-6m66-7c5m","GHSA-7f5h-v6xp-fcq8","GHSA-7gcm-g887-7qv7","GHSA-7gw9-cf7v-778f","GHSA-7hfw-26vp-jp8m","GHSA-7jqv-fw35-gmx9","GHSA-7p94-766c-hgjp","GHSA-82w8-qh3p-5jfq","GHSA-836r-79rf-4m37","GHSA-86qp-5c8j-p5mr","GHSA-87mj-5ggw-8qc3","GHSA-89vp-jrxv-24w8","GHSA-8c25-4j27-2rv3","GHSA-8g87-j6q8-g93x","GHSA-8mp2-v27r-99xp","GHSA-8mpj-m6qm-5qr8","GHSA-8ppf-4f7h-5ppj","GHSA-8qvm-5x2c-j2w7","GHSA-8rfp-98v4-mmr6","GHSA-8v84-f9pq-wr9x","GHSA-926x-3r5x-gfhw","GHSA-9548-qrrj-x5pj","GHSA-966j-vmvw-g2g9","GHSA-993g-76c3-p5m4","GHSA-996q-pr4m-cvgq","GHSA-9h52-p55h-vw2f","GHSA-9hjg-9r4m-mvj7","GHSA-9hw9-ch79-4vh6","GHSA-9m86-7pmv-2852","GHSA-9mvc-8737-8j8h","GHSA-9q39-rmj3-p4r2","GHSA-9wx4-h78v-vm56","GHSA-9x8q-7h8h-wcw9","GHSA-c427-h43c-vf67","GHSA-c67j-w6g6-q2cm","GHSA-c8j7-8cv4-2xmq","GHSA-c98p-7wgm-6p64","GHSA-cfh3-3jmp-rvhc","GHSA-cj93-chg6-vgv8","GHSA-cpwx-vrp4-4pq7","GHSA-cx3h-4qpv-8hc9","GHSA-cx63-2mw6-8hw5","GHSA-f2v5-7jq9-h8cg","GHSA-f4xh-w4cj-qxq8","GHSA-f83h-ghpp-7wcc","GHSA-f96h-pmfr-66vw","GHSA-fcw5-x6j4-ccmp","GHSA-ffq3-xpv3-j92q","GHSA-fg6f-75jq-6523","GHSA-fg7f-2386-8897","GHSA-fh55-r93g-j68g","GHSA-fhv5-28vv-h8m8","GHSA-fj7v-r99m-22gq","GHSA-fjqc-hq36-qh5p","GHSA-fv5p-p927-qmxr","GHSA-g3cq-j2xw-wf74","GHSA-g48c-2wqr-h844","GHSA-g7f3-828f-7h7m","GHSA-g7vv-2v7x-gj9p","GHSA-g84x-mcqj-x9qq","GHSA-g867-7843-wf8q","GHSA-g97x-gvcm-x72h","GHSA-g9xf-7f8q-9mcj","GHSA-gc5v-m9x4-r6x2","GHSA-gf7q-q4j7-hp7c","GHSA-gfwx-w7gr-fvh7","GHSA-gj48-438w-jh9v","GHSA-gm62-xv2j-4w53","GHSA-gm8q-m8mv-jj5m","GHSA-gmj6-6f8f-6699","GHSA-gr75-jv2w-4656","GHSA-gx64-gj6p-pc4c","GHSA-h35f-9h28-mq5c","GHSA-h4gh-qq45-vh27","GHSA-h5v5-8746-g7mm","GHSA-h75v-3vvj-5mfj","GHSA-h8wq-7xc4-p3qx","GHSA-hcc4-c3v8-rx92","GHSA-hg6j-4rv6-33pg","GHSA-hm4w-wwcw-mr6r","GHSA-hpj7-wq8m-9hgp","GHSA-hqmh-ppp3-xvm7","GHSA-hx9q-6w63-j58v","GHSA-j543-4vmf-qm7v","GHSA-jfx9-29x2-rv3j","GHSA-jg22-mg44-37j8","GHSA-jhmp-mqwm-3gq8","GHSA-jj3x-wxrx-4x23","GHSA-jj6c-8h6c-hppx","GHSA-jj8c-mmj3-mmgv","GHSA-jjj6-mw9f-p565","GHSA-jm6w-m3j8-898g","GHSA-jm82-fx9c-mx94","GHSA-jp82-jpqv-5vv3","GHSA-jpw9-pfvf-9f58","GHSA-jq35-7prp-9v3f","GHSA-jr27-m4p2-rc6r","GHSA-m2v9-299j-rv96","GHSA-m344-f55w-2m6j","GHSA-m449-cwjh-6pw7","GHSA-m5qp-6w8w-w647","GHSA-m6qw-4cw2-hm4m","GHSA-m959-cc7f-wv43","GHSA-mf9v-mfxr-j63j","GHSA-mf9w-mj56-hr94","GHSA-mgf9-4vpg-hj56","GHSA-mj87-hwqh-73pj","GHSA-mqcg-5x36-vfcg","GHSA-mqqc-3gqh-h2x8","GHSA-mwh4-6h8g-pg8w","GHSA-p423-j2cm-9vmq","GHSA-p4gq-832x-fm9v","GHSA-p998-jp59-783m","GHSA-pc6w-59fv-rh23","GHSA-pg7v-jwj7-p798","GHSA-phj9-mv4w-65pm","GHSA-pjwx-r37v-7724","GHSA-pp6c-gr5w-3c5g","GHSA-pppj-hq3g-57pj","GHSA-pq5p-34cr-23v9","GHSA-pq67-6m6q-mj2v","GHSA-pr2v-jx2c-wg9f","GHSA-pw6j-qg29-8w7f","GHSA-pwv6-vv43-88gr","GHSA-q25c-c977-4cmh","GHSA-q2x7-8rv6-6q7h","GHSA-qccp-gfcp-xxvc","GHSA-qcq2-496w-v96p","GHSA-qfrw-5rxm-mhh2","GHSA-qh6h-p6c9-ff54","GHSA-qh7q-6qm3-653w","GHSA-qjxf-f2mg-c6mc","GHSA-qmgc-5h2g-mvrw","GHSA-qpxp-75px-xjcp","GHSA-qvv7-cg9c-w4x3","GHSA-r4rv-85jg-w4mf","GHSA-r6ph-v2qm-q3c2","GHSA-r73j-pqj5-w3x7","GHSA-r7w7-9xr2-qq2r","GHSA-r95x-qfjj-fjj2","GHSA-rch3-82jr-f9w9","GHSA-rf74-v2fm-23pw","GHSA-rr7j-v2q5-chgv","GHSA-v42x-x7jp-845h","GHSA-v87v-83h2-53w7","GHSA-v9pg-7xvm-68hf","GHSA-vffw-93wf-4j4q","GHSA-vfmq-68hx-4jfw","GHSA-vj7q-gjh5-988w","GHSA-vjc4-5qp5-m44j","GHSA-vmhf-c436-hxj4","GHSA-vqfr-h8mv-ghfj","GHSA-vr63-x8vc-m265","GHSA-vvfj-2jqx-52jm","GHSA-w2fm-2cpv-w7v5","GHSA-w39p-vh2g-g8g5","GHSA-w7vc-732c-9m39","GHSA-w853-jp5j-5j7f","GHSA-w8p2-r796-3vmq","GHSA-wf5f-4jwr-ppcp","GHSA-wgvp-vg3v-2xq3","GHSA-whj4-6x5x-4v2j","GHSA-whvh-wf3x-g77j","GHSA-wjqc-6w8f-h24c","GHSA-wjx4-4jcj-g98j","GHSA-wp53-j4wj-2cfg","GHSA-wqp7-x3pw-xc5r","GHSA-wvwj-cvrp-7pv5","GHSA-x284-j5p8-9c5p","GHSA-x746-7m8f-x49c","GHSA-x7hp-r3qg-r3cj","GHSA-xcgm-r5h9-7989","GHSA-xg8h-j46f-w952","GHSA-xgmm-8j9v-c9wx","GHSA-xh95-f55m-82fw","GHSA-xj96-63gp-2gmr","GHSA-xm59-rqc7-hhvf","PYSEC-2024-115","PYSEC-2024-323","PYSEC-2025-183","PYSEC-2026-2085","PYSEC-2026-2132","PYSEC-2026-2208","PYSEC-2026-2209","PYSEC-2026-3455","PYSEC-2026-597","PYSEC-2026-99"],"advisoryCount":255,"providers":[]},"evidence":{"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"5c34ec93b8f084fb238b9dfb84642a3091538e9d","sourceUrl":"https://gitlab.opencode.de/sh/diwish/splitbot/kosmo/llm-service/-/blob/318cda8c49da743f2c4a18a4f4d5c36fc22102fc/uv.lock","commitSha":"318cda8c49da743f2c4a18a4f4d5c36fc22102fc","contentSha256":"72d385efaa1c9d7ef74ecd2177161e9b80f5ec89cc764f9cf3892c4a65408df2","byteCount":466608,"state":"parsed","componentCount":303}],"occurrenceCount":303},"related":{"packages":[{"id":"package:pypi:langchain-core","slug":"langchain-core-82117efb","identity":"pypi:langchain-core","label":"LangChain Core","aiRelevant":true,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["1.4.9"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-community","slug":"langchain-community-b296254c","identity":"pypi:langchain-community","label":"LangChain Community","aiRelevant":true,"provider":null,"advisoryCount":4,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain","slug":"langchain-2b3b6a0b","identity":"pypi:langchain","label":"LangChain","aiRelevant":true,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["1.3.13"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph","slug":"langgraph-6c1c645e","identity":"pypi:langgraph","label":"LangGraph","aiRelevant":true,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["1.2.9"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-openai","slug":"langchain-openai-4985188e","identity":"pypi:langchain-openai","label":"LangChain OpenAI","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.1.9"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-text-splitters","slug":"langchain-text-splitters-0c057788","identity":"pypi:langchain-text-splitters","label":"LangChain · Text Splitters","aiRelevant":true,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.1.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:anthropic","slug":"anthropic-829dc3db","identity":"pypi:anthropic","label":"Anthropic SDK","aiRelevant":true,"provider":{"id":"anthropic","label":"Anthropic"},"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.116.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.109.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tokenizers","slug":"tokenizers-7ba00902","identity":"pypi:tokenizers","label":"Hugging Face Tokenizers","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.23.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-google-community","slug":"langchain-google-community-733aba30","identity":"pypi:langchain-google-community","label":"LangChain · Google Community","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["5.0.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-mcp-adapters","slug":"langchain-mcp-adapters-1c0e13c7","identity":"pypi:langchain-mcp-adapters","label":"LangChain · MCP Adapters","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-mistralai","slug":"langchain-mistralai-52e30148","identity":"pypi:langchain-mistralai","label":"LangChain · Mistralai","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.12"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-protocol","slug":"langchain-protocol-2715aeed","identity":"pypi:langchain-protocol","label":"LangChain · Protocol","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.18"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-weaviate","slug":"langchain-weaviate-707e0daa","identity":"pypi:langchain-weaviate","label":"LangChain · Weaviate","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.8"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opencv-python","slug":"opencv-python-bfa06e24","identity":"pypi:opencv-python","label":"OpenCV","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["5.0.0.93"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tiktoken","slug":"tiktoken-06b251a3","identity":"pypi:tiktoken","label":"tiktoken","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.13.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:weaviate-client","slug":"weaviate-client-c34ddc0e","identity":"pypi:weaviate-client","label":"Weaviate Client","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["4.22.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pypdf","slug":"pypdf-a4757bde","identity":"pypi:pypdf","label":"pypdf","aiRelevant":false,"provider":null,"advisoryCount":35,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["6.14.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohttp","slug":"aiohttp-5a806a63","identity":"pypi:aiohttp","label":"aiohttp","aiRelevant":false,"provider":null,"advisoryCount":30,"licenseExpressions":["Apache-2.0","Apache-2.0 AND MIT"],"versions":["3.14.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pillow","slug":"pillow-834347dd","identity":"pypi:pillow","label":"pillow","aiRelevant":false,"provider":null,"advisoryCount":20,"licenseExpressions":["HPND","MIT-CMU"],"versions":["12.3.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mistune","slug":"mistune-883ae9a9","identity":"pypi:mistune","label":"mistune","aiRelevant":false,"provider":null,"advisoryCount":16,"licenseExpressions":["BSD-3-Clause"],"versions":["3.3.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nltk","slug":"nltk-ec2a0f85","identity":"pypi:nltk","label":"nltk","aiRelevant":false,"provider":null,"advisoryCount":15,"licenseExpressions":["Apache-2.0"],"versions":["3.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyterlab","slug":"jupyterlab-da634f79","identity":"pypi:jupyterlab","label":"jupyterlab","aiRelevant":false,"provider":null,"advisoryCount":10,"licenseExpressions":["non-standard"],"versions":["4.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tornado","slug":"tornado-ab0f364e","identity":"pypi:tornado","label":"tornado","aiRelevant":false,"provider":null,"advisoryCount":10,"licenseExpressions":["Apache-2.0"],"versions":["6.5.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:authlib","slug":"authlib-c1d999b9","identity":"pypi:authlib","label":"authlib","aiRelevant":false,"provider":null,"advisoryCount":9,"licenseExpressions":["BSD-3-Clause"],"versions":["1.7.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-multipart","slug":"python-multipart-7d2a810e","identity":"pypi:python-multipart","label":"python-multipart","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["Apache-2.0"],"versions":["0.0.32"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:starlette","slug":"starlette-beb9e527","identity":"pypi:starlette","label":"starlette","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["BSD-3-Clause"],"versions":["1.3.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-server","slug":"jupyter-server-bda3ce93","identity":"pypi:jupyter-server","label":"jupyter-server","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["non-standard"],"versions":["2.20.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyjwt","slug":"pyjwt-b1ea166e","identity":"pypi:pyjwt","label":"pyjwt","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["2.13.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urllib3","slug":"urllib3-fa68f32c","identity":"pypi:urllib3","label":"urllib3","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["2.7.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cryptography","slug":"cryptography-de36c9c8","identity":"pypi:cryptography","label":"cryptography","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["Apache-2.0 OR BSD-3-Clause"],"versions":["49.0.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyasn1","slug":"pyasn1-348780fa","identity":"pypi:pyasn1","label":"pyasn1","aiRelevant":false,"provider":null,"advisoryCount":5,"licenseExpressions":["BSD-2-Clause"],"versions":["0.6.4"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jinja2","slug":"jinja2-f7d34747","identity":"pypi:jinja2","label":"jinja2","aiRelevant":false,"provider":null,"advisoryCount":4,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langsmith","slug":"langsmith-a7ab7b96","identity":"pypi:langsmith","label":"langsmith","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["0.10.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mcp","slug":"mcp-ef053766","identity":"pypi:mcp","label":"mcp","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["1.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nbconvert","slug":"nbconvert-a72151db","identity":"pypi:nbconvert","label":"nbconvert","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["non-standard"],"versions":["7.17.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:notebook","slug":"notebook-9683036a","identity":"pypi:notebook","label":"notebook","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["non-standard"],"versions":["7.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests","slug":"requests-53653f76","identity":"pypi:requests","label":"requests","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["Apache-2.0"],"versions":["2.34.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:setuptools","slug":"setuptools-fe37c31a","identity":"pypi:setuptools","label":"setuptools","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["72.2.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:bleach","slug":"bleach-b1747264","identity":"pypi:bleach","label":"bleach","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["non-standard"],"versions":["6.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:filelock","slug":"filelock-b1c63968","identity":"pypi:filelock","label":"filelock","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT","Unlicense"],"versions":["3.29.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pdfminer-six","slug":"pdfminer-six-53ae17a4","identity":"pypi:pdfminer-six","label":"pdfminer-six","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["20260107"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:protobuf","slug":"protobuf-6e30009a","identity":"pypi:protobuf","label":"protobuf","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["BSD-3-Clause"],"versions":["5.29.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:soupsieve","slug":"soupsieve-91552d8b","identity":"pypi:soupsieve","label":"soupsieve","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["2.8.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:certifi","slug":"certifi-d4f0c37e","identity":"pypi:certifi","label":"certifi","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MPL-2.0"],"versions":["2026.6.17"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click","slug":"click-ef97f731","identity":"pypi:click","label":"click","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["8.4.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:h11","slug":"h11-48165ab1","identity":"pypi:h11","label":"h11","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.18"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-core","slug":"jupyter-core-44178c79","identity":"pypi:jupyter-core","label":"jupyter-core","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["5.9.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-classic","slug":"langchain-classic-ee5360ab","identity":"pypi:langchain-classic","label":"langchain-classic","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.0.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph-checkpoint","slug":"langgraph-checkpoint-b3039a64","identity":"pypi:langgraph-checkpoint","label":"langgraph-checkpoint","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["4.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph-sdk","slug":"langgraph-sdk-7670dc92","identity":"pypi:langgraph-sdk","label":"langgraph-sdk","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lxml","slug":"lxml-53ddfa54","identity":"pypi:lxml","label":"lxml","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["6.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:marshmallow","slug":"marshmallow-abf69093","identity":"pypi:marshmallow","label":"marshmallow","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["3.26.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:orjson","slug":"orjson-0293c856","identity":"pypi:orjson","label":"orjson","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0 OR MIT","MPL-2.0 AND (Apache-2.0 OR MIT)"],"versions":["3.11.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-settings","slug":"pydantic-settings-d677745f","identity":"pypi:pydantic-settings","label":"pydantic-settings","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["2.14.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pygments","slug":"pygments-ad71bc11","identity":"pypi:pygments","label":"pygments","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-2-Clause"],"versions":["2.20.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest","slug":"pytest-07c6f86c","identity":"pypi:pytest","label":"pytest","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["9.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dotenv","slug":"python-dotenv-27b12285","identity":"pypi:python-dotenv","label":"python-dotenv","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["1.2.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tqdm","slug":"tqdm-04b01f90","identity":"pypi:tqdm","label":"tqdm","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT AND MPL-2.0"],"versions":["4.68.4"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:unstructured","slug":"unstructured-9ec9bd94","identity":"pypi:unstructured","label":"unstructured","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0"],"versions":["0.17.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiofiles","slug":"aiofiles-41b094bb","identity":"pypi:aiofiles","label":"aiofiles","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["25.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohappyeyeballs","slug":"aiohappyeyeballs-ea4657b8","identity":"pypi:aiohappyeyeballs","label":"aiohappyeyeballs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["2.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiosignal","slug":"aiosignal-b6794e75","identity":"pypi:aiosignal","label":"aiosignal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:amqp","slug":"amqp-b7c07d93","identity":"pypi:amqp","label":"amqp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-doc","slug":"annotated-doc-9568e1af","identity":"pypi:annotated-doc","label":"annotated-doc","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-types","slug":"annotated-types-2304c38b","identity":"pypi:annotated-types","label":"annotated-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:anyio","slug":"anyio-399e5280","identity":"pypi:anyio","label":"anyio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.14.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:appnope","slug":"appnope-1881f8cd","identity":"pypi:appnope","label":"appnope","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:argon2-cffi","slug":"argon2-cffi-0666afdc","identity":"pypi:argon2-cffi","label":"argon2-cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:argon2-cffi-bindings","slug":"argon2-cffi-bindings-8c6d8583","identity":"pypi:argon2-cffi-bindings","label":"argon2-cffi-bindings","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:arrow","slug":"arrow-d0e153a5","identity":"pypi:arrow","label":"arrow","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:asttokens","slug":"asttokens-c349c5f9","identity":"pypi:asttokens","label":"asttokens","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["3.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:async-lru","slug":"async-lru-57db467a","identity":"pypi:async-lru","label":"async-lru","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:async-timeout","slug":"async-timeout-218334ed","identity":"pypi:async-timeout","label":"async-timeout","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["5.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:attrs","slug":"attrs-2e7954ac","identity":"pypi:attrs","label":"attrs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["26.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:babel","slug":"babel-c668b0a9","identity":"pypi:babel","label":"babel","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.18.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:backoff","slug":"backoff-594e7418","identity":"pypi:backoff","label":"backoff","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:beautifulsoup4","slug":"beautifulsoup4-eddf0c04","identity":"pypi:beautifulsoup4","label":"beautifulsoup4","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:billiard","slug":"billiard-87cdf8d8","identity":"pypi:billiard","label":"billiard","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.2.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cached-property","slug":"cached-property-4115aa7b","identity":"pypi:cached-property","label":"cached-property","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:celery","slug":"celery-b40d49f4","identity":"pypi:celery","label":"celery","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["5.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cffi","slug":"cffi-38e65d3e","identity":"pypi:cffi","label":"cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","MIT-0"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:chardet","slug":"chardet-69451fbd","identity":"pypi:chardet","label":"chardet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD","non-standard"],"versions":["7.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:charset-normalizer","slug":"charset-normalizer-74ccb20a","identity":"pypi:charset-normalizer","label":"charset-normalizer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click-didyoumean","slug":"click-didyoumean-4dbcd2d4","identity":"pypi:click-didyoumean","label":"click-didyoumean","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click-plugins","slug":"click-plugins-b43a6bb3","identity":"pypi:click-plugins","label":"click-plugins","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click-repl","slug":"click-repl-3c545c47","identity":"pypi:click-repl","label":"click-repl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:comm","slug":"comm-0720ed7b","identity":"pypi:comm","label":"comm","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:dataclasses-json","slug":"dataclasses-json-54bdba52","identity":"pypi:dataclasses-json","label":"dataclasses-json","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:debugpy","slug":"debugpy-71725cbb","identity":"pypi:debugpy","label":"debugpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.8.21"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:decorator","slug":"decorator-500c1fb8","identity":"pypi:decorator","label":"decorator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["5.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:defusedxml","slug":"defusedxml-fab5db42","identity":"pypi:defusedxml","label":"defusedxml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:deprecated","slug":"deprecated-e7bb8a9a","identity":"pypi:deprecated","label":"deprecated","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distro","slug":"distro-36b318e9","identity":"pypi:distro","label":"distro","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:dnspython","slug":"dnspython-33533784","identity":"pypi:dnspython","label":"dnspython","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["2.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:docstring-parser","slug":"docstring-parser-9edeecc2","identity":"pypi:docstring-parser","label":"docstring-parser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.18.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:docx2txt","slug":"docx2txt-d7a05e45","identity":"pypi:docx2txt","label":"docx2txt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["0.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:emoji","slug":"emoji-b8402ff3","identity":"pypi:emoji","label":"emoji","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:eventlet","slug":"eventlet-d9e7dce2","identity":"pypi:eventlet","label":"eventlet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.41.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:exchangelib","slug":"exchangelib-2c02f617","identity":"pypi:exchangelib","label":"exchangelib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["5.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:executing","slug":"executing-36845a5b","identity":"pypi:executing","label":"executing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi","slug":"fastapi-e52fd482","identity":"pypi:fastapi","label":"fastapi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.139.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastjsonschema","slug":"fastjsonschema-8288c29a","identity":"pypi:fastjsonschema","label":"fastjsonschema","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.21.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:filetype","slug":"filetype-60d6f43a","identity":"pypi:filetype","label":"filetype","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:flatbuffers","slug":"flatbuffers-90c67795","identity":"pypi:flatbuffers","label":"flatbuffers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["25.12.19"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fqdn","slug":"fqdn-2616214a","identity":"pypi:fqdn","label":"fqdn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:frozenlist","slug":"frozenlist-110237da","identity":"pypi:frozenlist","label":"frozenlist","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fsspec","slug":"fsspec-b1a7c311","identity":"pypi:fsspec","label":"fsspec","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2026.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-api-core","slug":"google-api-core-1f2bc06d","identity":"pypi:google-api-core","label":"google-api-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.31.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-api-python-client","slug":"google-api-python-client-5dcdb5bd","identity":"pypi:google-api-python-client","label":"google-api-python-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.198.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-auth","slug":"google-auth-42cfc01f","identity":"pypi:google-auth","label":"google-auth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.55.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-auth-httplib2","slug":"google-auth-httplib2-dd7061f9","identity":"pypi:google-auth-httplib2","label":"google-auth-httplib2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-auth-oauthlib","slug":"google-auth-oauthlib-21213e6a","identity":"pypi:google-auth-oauthlib","label":"google-auth-oauthlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-cloud-core","slug":"google-cloud-core-99cecb76","identity":"pypi:google-cloud-core","label":"google-cloud-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:google-cloud-modelarmor","slug":"google-cloud-modelarmor-f880491c","identity":"pypi:google-cloud-modelarmor","label":"google-cloud-modelarmor","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:googleapis-common-protos","slug":"googleapis-common-protos-d5ca3481","identity":"pypi:googleapis-common-protos","label":"googleapis-common-protos","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.75.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:greenlet","slug":"greenlet-cd6f7934","identity":"pypi:greenlet","label":"greenlet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","MIT AND PSF-2.0","MIT AND Python-2.0"],"versions":["3.5.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:grpcio","slug":"grpcio-40fa763c","identity":"pypi:grpcio","label":"grpcio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.78.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:grpcio-status","slug":"grpcio-status-f4c90de4","identity":"pypi:grpcio-status","label":"grpcio-status","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.71.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:hf-xet","slug":"hf-xet-732ec6c8","identity":"pypi:hf-xet","label":"hf-xet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:highlight-io","slug":"highlight-io-a0246cc7","identity":"pypi:highlight-io","label":"highlight-io","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.9.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:html2text","slug":"html2text-351f3aea","identity":"pypi:html2text","label":"html2text","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["GPL-3.0"],"versions":["2024.2.26"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:html5lib","slug":"html5lib-0ea30fe2","identity":"pypi:html5lib","label":"html5lib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpcore","slug":"httpcore-ba6ae671","identity":"pypi:httpcore","label":"httpcore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.0.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httplib2","slug":"httplib2-5ed73348","identity":"pypi:httplib2","label":"httplib2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.32.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx","slug":"httpx-a512a166","identity":"pypi:httpx","label":"httpx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx-sse","slug":"httpx-sse-0029fe64","identity":"pypi:httpx-sse","label":"httpx-sse","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:huggingface-hub","slug":"huggingface-hub-443ec6ef","identity":"pypi:huggingface-hub","label":"huggingface-hub","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["1.23.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:importlib-metadata","slug":"importlib-metadata-a3dfda3c","identity":"pypi:importlib-metadata","label":"importlib-metadata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["8.5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:inflection","slug":"inflection-ad66c7ec","identity":"pypi:inflection","label":"inflection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:iniconfig","slug":"iniconfig-1f66e358","identity":"pypi:iniconfig","label":"iniconfig","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipykernel","slug":"ipykernel-37162218","identity":"pypi:ipykernel","label":"ipykernel","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["7.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipython","slug":"ipython-7a140323","identity":"pypi:ipython","label":"ipython","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["9.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipython-pygments-lexers","slug":"ipython-pygments-lexers-6216051e","identity":"pypi:ipython-pygments-lexers","label":"ipython-pygments-lexers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipywidgets","slug":"ipywidgets-5079daea","identity":"pypi:ipywidgets","label":"ipywidgets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["8.1.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:isodate","slug":"isodate-fdef8b9b","identity":"pypi:isodate","label":"isodate","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.7.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:isoduration","slug":"isoduration-e8f86ac8","identity":"pypi:isoduration","label":"isoduration","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["20.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jedi","slug":"jedi-9eb0c211","identity":"pypi:jedi","label":"jedi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.20.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jh2","slug":"jh2-5dba0ddb","identity":"pypi:jh2","label":"jh2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["5.0.13"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jiter","slug":"jiter-d62b34e9","identity":"pypi:jiter","label":"jiter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:joblib","slug":"joblib-8cbb7872","identity":"pypi:joblib","label":"joblib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.5.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:joserfc","slug":"joserfc-f5385f6a","identity":"pypi:joserfc","label":"joserfc","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.7.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:json5","slug":"json5-79be3697","identity":"pypi:json5","label":"json5","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonpatch","slug":"jsonpatch-ce7aa354","identity":"pypi:jsonpatch","label":"jsonpatch","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.33"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonpointer","slug":"jsonpointer-a61b5f8f","identity":"pypi:jsonpointer","label":"jsonpointer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema","slug":"jsonschema-df23f5cd","identity":"pypi:jsonschema","label":"jsonschema","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.26.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema-specifications","slug":"jsonschema-specifications-5d87863a","identity":"pypi:jsonschema-specifications","label":"jsonschema-specifications","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.9.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter","slug":"jupyter-cfc2388a","identity":"pypi:jupyter","label":"jupyter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-builder","slug":"jupyter-builder-a8b1b3d0","identity":"pypi:jupyter-builder","label":"jupyter-builder","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause AND ISC AND MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-client","slug":"jupyter-client-3b4db88c","identity":"pypi:jupyter-client","label":"jupyter-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["8.9.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-console","slug":"jupyter-console-fe43250b","identity":"pypi:jupyter-console","label":"jupyter-console","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["6.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-events","slug":"jupyter-events-f8263fc3","identity":"pypi:jupyter-events","label":"jupyter-events","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.12.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-lsp","slug":"jupyter-lsp-e5008e78","identity":"pypi:jupyter-lsp","label":"jupyter-lsp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-server-terminals","slug":"jupyter-server-terminals-908697b8","identity":"pypi:jupyter-server-terminals","label":"jupyter-server-terminals","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.5.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyterlab-pygments","slug":"jupyterlab-pygments-f3159f9e","identity":"pypi:jupyterlab-pygments","label":"jupyterlab-pygments","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyterlab-server","slug":"jupyterlab-server-87bbeff5","identity":"pypi:jupyterlab-server","label":"jupyterlab-server","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.28.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyterlab-widgets","slug":"jupyterlab-widgets-e76ed5e8","identity":"pypi:jupyterlab-widgets","label":"jupyterlab-widgets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.16"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:kombu","slug":"kombu-4085784d","identity":"pypi:kombu","label":"kombu","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["5.6.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langdetect","slug":"langdetect-3c0edcca","identity":"pypi:langdetect","label":"langdetect","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.0.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph-prebuilt","slug":"langgraph-prebuilt-84c4e144","identity":"pypi:langgraph-prebuilt","label":"langgraph-prebuilt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lark","slug":"lark-56b23f4f","identity":"pypi:lark","label":"lark","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markupsafe","slug":"markupsafe-1bdd4c7f","identity":"pypi:markupsafe","label":"markupsafe","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:matplotlib-inline","slug":"matplotlib-inline-50f95e0d","identity":"pypi:matplotlib-inline","label":"matplotlib-inline","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["0.2.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:msal","slug":"msal-b77215ab","identity":"pypi:msal","label":"msal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.37.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:multidict","slug":"multidict-b407a4ac","identity":"pypi:multidict","label":"multidict","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mypy-extensions","slug":"mypy-extensions-702f6cf3","identity":"pypi:mypy-extensions","label":"mypy-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nbclient","slug":"nbclient-e201d8f1","identity":"pypi:nbclient","label":"nbclient","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nbformat","slug":"nbformat-2d86904f","identity":"pypi:nbformat","label":"nbformat","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.10.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nest-asyncio2","slug":"nest-asyncio2-ac071203","identity":"pypi:nest-asyncio2","label":"nest-asyncio2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.7.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:niquests","slug":"niquests-afbb79b2","identity":"pypi:niquests","label":"niquests","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["3.20.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:notebook-shim","slug":"notebook-shim-6d442652","identity":"pypi:notebook-shim","label":"notebook-shim","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:numpy","slug":"numpy-ba79b98d","identity":"pypi:numpy","label":"numpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib","non-standard"],"versions":["2.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:oauthlib","slug":"oauthlib-5d97cdbc","identity":"pypi:oauthlib","label":"oauthlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:olefile","slug":"olefile-c842b5c6","identity":"pypi:olefile","label":"olefile","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.47"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:onnxruntime","slug":"onnxruntime-5acdb617","identity":"pypi:onnxruntime","label":"onnxruntime","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.27.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-api","slug":"opentelemetry-api-341bc8f7","identity":"pypi:opentelemetry-api","label":"opentelemetry-api","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-distro","slug":"opentelemetry-distro-dfa51d1d","identity":"pypi:opentelemetry-distro","label":"opentelemetry-distro","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-exporter-otlp-proto-common","slug":"opentelemetry-exporter-otlp-proto-common-636ba371","identity":"pypi:opentelemetry-exporter-otlp-proto-common","label":"opentelemetry-exporter-otlp-proto-common","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-exporter-otlp-proto-grpc","slug":"opentelemetry-exporter-otlp-proto-grpc-c102a976","identity":"pypi:opentelemetry-exporter-otlp-proto-grpc","label":"opentelemetry-exporter-otlp-proto-grpc","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-exporter-otlp-proto-http","slug":"opentelemetry-exporter-otlp-proto-http-6f55af01","identity":"pypi:opentelemetry-exporter-otlp-proto-http","label":"opentelemetry-exporter-otlp-proto-http","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation","slug":"opentelemetry-instrumentation-9bcfbe9e","identity":"pypi:opentelemetry-instrumentation","label":"opentelemetry-instrumentation","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-anthropic","slug":"opentelemetry-instrumentation-anthropic-bf5e49cb","identity":"pypi:opentelemetry-instrumentation-anthropic","label":"opentelemetry-instrumentation-anthropic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-bedrock","slug":"opentelemetry-instrumentation-bedrock-8f6fc7c9","identity":"pypi:opentelemetry-instrumentation-bedrock","label":"opentelemetry-instrumentation-bedrock","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-boto","slug":"opentelemetry-instrumentation-boto-d95bfff1","identity":"pypi:opentelemetry-instrumentation-boto","label":"opentelemetry-instrumentation-boto","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-boto3sqs","slug":"opentelemetry-instrumentation-boto3sqs-e0e650a8","identity":"pypi:opentelemetry-instrumentation-boto3sqs","label":"opentelemetry-instrumentation-boto3sqs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-celery","slug":"opentelemetry-instrumentation-celery-7a39e74e","identity":"pypi:opentelemetry-instrumentation-celery","label":"opentelemetry-instrumentation-celery","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-chromadb","slug":"opentelemetry-instrumentation-chromadb-9eb598fd","identity":"pypi:opentelemetry-instrumentation-chromadb","label":"opentelemetry-instrumentation-chromadb","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-cohere","slug":"opentelemetry-instrumentation-cohere-83896a35","identity":"pypi:opentelemetry-instrumentation-cohere","label":"opentelemetry-instrumentation-cohere","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-haystack","slug":"opentelemetry-instrumentation-haystack-92025ed0","identity":"pypi:opentelemetry-instrumentation-haystack","label":"opentelemetry-instrumentation-haystack","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-langchain","slug":"opentelemetry-instrumentation-langchain-f89d1133","identity":"pypi:opentelemetry-instrumentation-langchain","label":"opentelemetry-instrumentation-langchain","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-llamaindex","slug":"opentelemetry-instrumentation-llamaindex-866eb99d","identity":"pypi:opentelemetry-instrumentation-llamaindex","label":"opentelemetry-instrumentation-llamaindex","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-logging","slug":"opentelemetry-instrumentation-logging-23ee835f","identity":"pypi:opentelemetry-instrumentation-logging","label":"opentelemetry-instrumentation-logging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-openai","slug":"opentelemetry-instrumentation-openai-68db94bf","identity":"pypi:opentelemetry-instrumentation-openai","label":"opentelemetry-instrumentation-openai","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-pinecone","slug":"opentelemetry-instrumentation-pinecone-08d2858e","identity":"pypi:opentelemetry-instrumentation-pinecone","label":"opentelemetry-instrumentation-pinecone","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-qdrant","slug":"opentelemetry-instrumentation-qdrant-3cbb3bd9","identity":"pypi:opentelemetry-instrumentation-qdrant","label":"opentelemetry-instrumentation-qdrant","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-redis","slug":"opentelemetry-instrumentation-redis-c10bb4c6","identity":"pypi:opentelemetry-instrumentation-redis","label":"opentelemetry-instrumentation-redis","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-replicate","slug":"opentelemetry-instrumentation-replicate-c6f5732e","identity":"pypi:opentelemetry-instrumentation-replicate","label":"opentelemetry-instrumentation-replicate","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-requests","slug":"opentelemetry-instrumentation-requests-baaa9f76","identity":"pypi:opentelemetry-instrumentation-requests","label":"opentelemetry-instrumentation-requests","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-sqlalchemy","slug":"opentelemetry-instrumentation-sqlalchemy-8d638a32","identity":"pypi:opentelemetry-instrumentation-sqlalchemy","label":"opentelemetry-instrumentation-sqlalchemy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-transformers","slug":"opentelemetry-instrumentation-transformers-bbb71ecf","identity":"pypi:opentelemetry-instrumentation-transformers","label":"opentelemetry-instrumentation-transformers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-vertexai","slug":"opentelemetry-instrumentation-vertexai-6a8490d9","identity":"pypi:opentelemetry-instrumentation-vertexai","label":"opentelemetry-instrumentation-vertexai","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-watsonx","slug":"opentelemetry-instrumentation-watsonx-012d35eb","identity":"pypi:opentelemetry-instrumentation-watsonx","label":"opentelemetry-instrumentation-watsonx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-instrumentation-weaviate","slug":"opentelemetry-instrumentation-weaviate-95b5df11","identity":"pypi:opentelemetry-instrumentation-weaviate","label":"opentelemetry-instrumentation-weaviate","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.33.12"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-proto","slug":"opentelemetry-proto-f15a3372","identity":"pypi:opentelemetry-proto","label":"opentelemetry-proto","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-sdk","slug":"opentelemetry-sdk-38b86085","identity":"pypi:opentelemetry-sdk","label":"opentelemetry-sdk","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-semantic-conventions","slug":"opentelemetry-semantic-conventions-15f3be17","identity":"pypi:opentelemetry-semantic-conventions","label":"opentelemetry-semantic-conventions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-semantic-conventions-ai","slug":"opentelemetry-semantic-conventions-ai-ccc88d76","identity":"pypi:opentelemetry-semantic-conventions-ai","label":"opentelemetry-semantic-conventions-ai","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opentelemetry-util-http","slug":"opentelemetry-util-http-03fc7f64","identity":"pypi:opentelemetry-util-http","label":"opentelemetry-util-http","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.49b2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ormsgpack","slug":"ormsgpack-56a067ff","identity":"pypi:ormsgpack","label":"ormsgpack","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.12.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:overrides","slug":"overrides-be2d7343","identity":"pypi:overrides","label":"overrides","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["7.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["26.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pandocfilters","slug":"pandocfilters-f452098e","identity":"pypi:pandocfilters","label":"pandocfilters","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:parso","slug":"parso-fa59fdde","identity":"pypi:parso","label":"parso","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pdfplumber","slug":"pdfplumber-ba8dca54","identity":"pypi:pdfplumber","label":"pdfplumber","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.11.10"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pexpect","slug":"pexpect-9ad65a0c","identity":"pypi:pexpect","label":"pexpect","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pikepdf","slug":"pikepdf-9b0a0b6c","identity":"pypi:pikepdf","label":"pikepdf","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MPL-2.0"],"versions":["10.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:platformdirs","slug":"platformdirs-e64002f0","identity":"pypi:platformdirs","label":"platformdirs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pluggy","slug":"pluggy-24479aaf","identity":"pypi:pluggy","label":"pluggy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prometheus-client","slug":"prometheus-client-7bd206b5","identity":"pypi:prometheus-client","label":"prometheus-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","Apache-2.0 AND BSD-2-Clause"],"versions":["0.25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prompt-toolkit","slug":"prompt-toolkit-e6f4118a","identity":"pypi:prompt-toolkit","label":"prompt-toolkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.52"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:propcache","slug":"propcache-1fcd6be4","identity":"pypi:propcache","label":"propcache","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.5.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:proto-plus","slug":"proto-plus-41237fa1","identity":"pypi:proto-plus","label":"proto-plus","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:psutil","slug":"psutil-840b9a74","identity":"pypi:psutil","label":"psutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["7.2.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ptyprocess","slug":"ptyprocess-ec2650c7","identity":"pypi:ptyprocess","label":"ptyprocess","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pure-eval","slug":"pure-eval-24d2bc1c","identity":"pypi:pure-eval","label":"pure-eval","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyasn1-modules","slug":"pyasn1-modules-6a7471e8","identity":"pypi:pyasn1-modules","label":"pyasn1-modules","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyclipper","slug":"pyclipper-aa2323ab","identity":"pypi:pyclipper","label":"pyclipper","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pycparser","slug":"pycparser-102d9d3e","identity":"pypi:pycparser","label":"pycparser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic","slug":"pydantic-4ac148ca","identity":"pypi:pydantic","label":"pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.13.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-core","slug":"pydantic-core-f9814ebc","identity":"pypi:pydantic-core","label":"pydantic-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.46.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pymongo","slug":"pymongo-367c417d","identity":"pypi:pymongo","label":"pymongo","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["4.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyncclient","slug":"pyncclient-babf6882","identity":"pypi:pyncclient","label":"pyncclient","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyparsing","slug":"pyparsing-a28b9b62","identity":"pypi:pyparsing","label":"pyparsing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.3.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pypdfium2","slug":"pypdfium2-940917eb","identity":"pypi:pypdfium2","label":"pypdfium2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyspnego","slug":"pyspnego-51559592","identity":"pypi:pyspnego","label":"pyspnego","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.12.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest-asyncio","slug":"pytest-asyncio-5e711c5a","identity":"pypi:pytest-asyncio","label":"pytest-asyncio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dateutil","slug":"python-dateutil-8eac96b7","identity":"pypi:python-dateutil","label":"python-dateutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.9.0.post0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-iso639","slug":"python-iso639-ccd49637","identity":"pypi:python-iso639","label":"python-iso639","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2026.4.20"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-json-logger","slug":"python-json-logger-f4803e0b","identity":"pypi:python-json-logger","label":"python-json-logger","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["4.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-magic","slug":"python-magic-28c4094a","identity":"pypi:python-magic","label":"python-magic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.27"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-magic-bin","slug":"python-magic-bin-bfa92dc0","identity":"pypi:python-magic-bin","label":"python-magic-bin","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["0.4.14"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-oxmsg","slug":"python-oxmsg-1cecb37a","identity":"pypi:python-oxmsg","label":"python-oxmsg","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pywin32","slug":"pywin32-9a7c83ae","identity":"pypi:pywin32","label":"pywin32","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["312"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pywinpty","slug":"pywinpty-0eb4e04a","identity":"pypi:pywinpty","label":"pywinpty","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.0.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyyaml","slug":"pyyaml-16000901","identity":"pypi:pyyaml","label":"pyyaml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyzmq","slug":"pyzmq-30b92392","identity":"pypi:pyzmq","label":"pyzmq","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["27.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:qh3","slug":"qh3-30fc4da7","identity":"pypi:qh3","label":"qh3","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.9.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:qrcode","slug":"qrcode-dc7f5ffb","identity":"pypi:qrcode","label":"qrcode","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["8.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rapidfuzz","slug":"rapidfuzz-3beab87b","identity":"pypi:rapidfuzz","label":"rapidfuzz","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.14.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rapidocr-onnxruntime","slug":"rapidocr-onnxruntime-649d0188","identity":"pypi:rapidocr-onnxruntime","label":"rapidocr-onnxruntime","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:redis","slug":"redis-94bd1499","identity":"pypi:redis","label":"redis","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["8.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:referencing","slug":"referencing-b8d98ce1","identity":"pypi:referencing","label":"referencing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.37.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:regex","slug":"regex-5e8be65e","identity":"pypi:regex","label":"regex","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 AND CNRI-Python","non-standard"],"versions":["2026.7.10"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:reportlab","slug":"reportlab-c4bc3646","identity":"pypi:reportlab","label":"reportlab","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests-mock","slug":"requests-mock-f997e834","identity":"pypi:requests-mock","label":"requests-mock","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.12.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests-ntlm","slug":"requests-ntlm-3ab6d59c","identity":"pypi:requests-ntlm","label":"requests-ntlm","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests-oauthlib","slug":"requests-oauthlib-865bff2a","identity":"pypi:requests-oauthlib","label":"requests-oauthlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests-toolbelt","slug":"requests-toolbelt-bb89e811","identity":"pypi:requests-toolbelt","label":"requests-toolbelt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rfc3339-validator","slug":"rfc3339-validator-433f6951","identity":"pypi:rfc3339-validator","label":"rfc3339-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rfc3986-validator","slug":"rfc3986-validator-723c00af","identity":"pypi:rfc3986-validator","label":"rfc3986-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rfc3987-syntax","slug":"rfc3987-syntax-1f7c3c6b","identity":"pypi:rfc3987-syntax","label":"rfc3987-syntax","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rpds-py","slug":"rpds-py-67c64be8","identity":"pypi:rpds-py","label":"rpds-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2026.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:send2trash","slug":"send2trash-9494ed34","identity":"pypi:send2trash","label":"send2trash","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:shapely","slug":"shapely-1cd2f2ba","identity":"pypi:shapely","label":"shapely","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:six","slug":"six-3c3888bd","identity":"pypi:six","label":"six","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sniffio","slug":"sniffio-83f32c9d","identity":"pypi:sniffio","label":"sniffio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sqlalchemy","slug":"sqlalchemy-5de7c53b","identity":"pypi:sqlalchemy","label":"sqlalchemy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.51"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sse-starlette","slug":"sse-starlette-94ef666b","identity":"pypi:sse-starlette","label":"sse-starlette","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.4.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sspilib","slug":"sspilib-cdfba389","identity":"pypi:sspilib","label":"sspilib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:stack-data","slug":"stack-data-d640fe0e","identity":"pypi:stack-data","label":"stack-data","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tenacity","slug":"tenacity-415454f8","identity":"pypi:tenacity","label":"tenacity","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["9.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:terminado","slug":"terminado-9ae7e4c0","identity":"pypi:terminado","label":"terminado","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.18.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tinycss2","slug":"tinycss2-301fccf6","identity":"pypi:tinycss2","label":"tinycss2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:traitlets","slug":"traitlets-52bd6ddb","identity":"pypi:traitlets","label":"traitlets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.15.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.16.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspect","slug":"typing-inspect-bffee874","identity":"pypi:typing-inspect","label":"typing-inspect","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspection","slug":"typing-inspection-0abeb500","identity":"pypi:typing-inspection","label":"typing-inspection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tzdata","slug":"tzdata-f80b3bb7","identity":"pypi:tzdata","label":"tzdata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2026.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tzlocal","slug":"tzlocal-7dbb909c","identity":"pypi:tzlocal","label":"tzlocal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["5.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:unstructured-client","slug":"unstructured-client-182f0adb","identity":"pypi:unstructured-client","label":"unstructured-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.45.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uri-template","slug":"uri-template-04c43560","identity":"pypi:uri-template","label":"uri-template","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uritemplate","slug":"uritemplate-02f8e588","identity":"pypi:uritemplate","label":"uritemplate","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uritools","slug":"uritools-75c85cd3","identity":"pypi:uritools","label":"uritools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urlextract","slug":"urlextract-e0b99c49","identity":"pypi:urlextract","label":"urlextract","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urllib3-future","slug":"urllib3-future-fd77948f","identity":"pypi:urllib3-future","label":"urllib3-future","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.22.901"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uuid-utils","slug":"uuid-utils-c3d356a2","identity":"pypi:uuid-utils","label":"uuid-utils","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["0.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uvicorn","slug":"uvicorn-07c7a595","identity":"pypi:uvicorn","label":"uvicorn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.51.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:validators","slug":"validators-7f3ecc07","identity":"pypi:validators","label":"validators","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.35.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:vine","slug":"vine-fa93acc9","identity":"pypi:vine","label":"vine","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wassima","slug":"wassima-de972895","identity":"pypi:wassima","label":"wassima","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wcwidth","slug":"wcwidth-038a8957","identity":"pypi:wcwidth","label":"wcwidth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:webcolors","slug":"webcolors-380e4f6b","identity":"pypi:webcolors","label":"webcolors","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["25.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:webencodings","slug":"webencodings-04815c4d","identity":"pypi:webencodings","label":"webencodings","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:websocket-client","slug":"websocket-client-af182b1a","identity":"pypi:websocket-client","label":"websocket-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:websockets","slug":"websockets-047236a0","identity":"pypi:websockets","label":"websockets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["15.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:widgetsnbextension","slug":"widgetsnbextension-8ee19027","identity":"pypi:widgetsnbextension","label":"widgetsnbextension","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["4.0.15"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wrapt","slug":"wrapt-505c01f2","identity":"pypi:wrapt","label":"wrapt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.17.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:xxhash","slug":"xxhash-908d556a","identity":"pypi:xxhash","label":"xxhash","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["3.8.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:yarl","slug":"yarl-05cd1b35","identity":"pypi:yarl","label":"yarl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.24.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:zipp","slug":"zipp-75ac1ddb","identity":"pypi:zipp","label":"zipp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:zstandard","slug":"zstandard-8fab007a","identity":"pypi:zstandard","label":"zstandard","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]}],"vulnerabilities":[{"id":"GHSA-248m-82v9-q6g6","slug":"ghsa-248m-82v9-q6g6-26728681","dossier":false,"summary":"pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams","aliases":["CVE-2026-48156","PYSEC-2026-3004"],"sourceIds":["GHSA-248m-82v9-q6g6","PYSEC-2026-3004"],"published":"2026-06-12T18:29:59Z","modified":"2026-07-13T16:43:52.833287270Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-248m-82v9-q6g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48156"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3791"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/507d7c9aa6ea83389b954b9c3c0c528fe5d5da70"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.12.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248m-82v9-q6g6"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-248v-346w-9cwc","slug":"ghsa-248v-346w-9cwc-8a7dbdf1","dossier":false,"summary":"Certifi removes GLOBALTRUST root certificate","aliases":["CVE-2024-39689","PYSEC-2024-230"],"sourceIds":["GHSA-248v-346w-9cwc","PYSEC-2024-230"],"published":"2024-07-05T19:15:10Z","modified":"2026-06-10T17:14:18.786020835Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39689"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463"},{"type":"PACKAGE","url":"https://github.com/certifi/python-certifi"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2024-230.yaml"},{"type":"ARTICLE","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241206-0001"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241206-0001/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248v-346w-9cwc"}],"versionKeys":["pypi:certifi@2024.6.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-24qx-w28j-9m6p","slug":"ghsa-24qx-w28j-9m6p-97a1f20a","dossier":false,"summary":"Jupyter Server has a  CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)","aliases":["CVE-2026-40110","PYSEC-2026-2187"],"sourceIds":["GHSA-24qx-w28j-9m6p","PYSEC-2026-2187"],"published":"2026-05-05T16:54:31Z","modified":"2026-07-13T07:26:55.845862407Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40110"},{"type":"REPORT","url":"https://github.com/jupyter-server/jupyter_server/pull/603"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40110"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40110.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466912"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2c2j-9gv5-cj73","slug":"ghsa-2c2j-9gv5-cj73-60bc1f35","dossier":false,"summary":"Starlette has possible denial-of-service vector when parsing large files in multipart forms","aliases":["CVE-2025-54121","PYSEC-2026-1941"],"sourceIds":["GHSA-2c2j-9gv5-cj73","PYSEC-2026-1941"],"published":"2025-07-21T19:34:23Z","modified":"2026-07-07T17:57:05.760766451Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54121"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"WEB","url":"https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14"},{"type":"WEB","url":"https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2c2j-9gv5-cj73"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-2fqr-mr3j-6wp8","slug":"ghsa-2fqr-mr3j-6wp8-5ee7c60f","dossier":false,"summary":"aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence","aliases":["CVE-2026-54279","PYSEC-2026-2112"],"sourceIds":["GHSA-2fqr-mr3j-6wp8","PYSEC-2026-2112"],"published":"2026-06-15T20:08:51Z","modified":"2026-07-13T07:26:35.059071977Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2g6r-c272-w58r","slug":"ghsa-2g6r-c272-w58r-4bbbcb01","dossier":false,"summary":"LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages","aliases":["CVE-2026-26013","PYSEC-2026-2562"],"sourceIds":["GHSA-2g6r-c272-w58r","PYSEC-2026-2562"],"published":"2026-02-11T14:23:13Z","modified":"2026-07-13T16:43:30.756724986Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-2g6r-c272-w58r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26013"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/2b4b1dc29a833d4053deba4c2b77a3848c834565"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.11"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2g6r-c272-w58r"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-2hm2-hc3v-44h9","slug":"ghsa-2hm2-hc3v-44h9-93b1e859","dossier":false,"summary":"Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id=\"toc_N\"` content","aliases":["CVE-2026-59930","PYSEC-2026-2218"],"sourceIds":["GHSA-2hm2-hc3v-44h9","PYSEC-2026-2218"],"published":"2026-07-08T17:17:28.867Z","modified":"2026-07-20T21:46:43.352385519Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59930"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2218.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2q4j-m29v-hq73","slug":"ghsa-2q4j-m29v-hq73-b4b89bc3","dossier":false,"summary":"pypdf has possible Infinite Loop when processing outlines/bookmarks","aliases":["CVE-2026-24688","PYSEC-2026-1827"],"sourceIds":["GHSA-2q4j-m29v-hq73","PYSEC-2026-1827"],"published":"2026-01-26T23:37:57Z","modified":"2026-07-07T17:56:12.815561375Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-2q4j-m29v-hq73"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24688"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3610"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/b1282f8dcdc1a7b41ceab6740ffddfdf31b1fec1"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.6.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2q4j-m29v-hq73"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2rw7-x74f-jg35","slug":"ghsa-2rw7-x74f-jg35-d822b126","dossier":false,"summary":"pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams","aliases":["CVE-2026-27628","PYSEC-2026-3005"],"sourceIds":["GHSA-2rw7-x74f-jg35","PYSEC-2026-3005"],"published":"2026-02-25T16:09:03Z","modified":"2026-07-13T16:42:58.625591114Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-2rw7-x74f-jg35"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27628"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/issues/3654"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/f0a462d36971cf077d74492a348d0d06fd60ea4d"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2rw7-x74f-jg35"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2vrm-gr82-f7m5","slug":"ghsa-2vrm-gr82-f7m5-5092ea0c","dossier":false,"summary":"AIOHTTP has CRLF injection through multipart part content type header construction","aliases":["CVE-2026-34514","PYSEC-2026-2096"],"sourceIds":["GHSA-2vrm-gr82-f7m5","PYSEC-2026-2096"],"published":"2026-04-01T21:16:59.417Z","modified":"2026-07-13T07:26:28.471600737Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2vrm-gr82-f7m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34514"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2wc2-fm75-p42x","slug":"ghsa-2wc2-fm75-p42x-9941d681","dossier":false,"summary":"Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists","aliases":["CVE-2026-49476","PYSEC-2026-3071"],"sourceIds":["GHSA-2wc2-fm75-p42x","PYSEC-2026-3071"],"published":"2026-07-09T13:37:40Z","modified":"2026-07-13T16:43:32.898354818Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x"},{"type":"PACKAGE","url":"https://github.com/facelessuser/soupsieve"},{"type":"PACKAGE","url":"https://pypi.org/project/soupsieve"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2wc2-fm75-p42x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49476"}],"versionKeys":["pypi:soupsieve@2.6","pypi:soupsieve@2.7","pypi:soupsieve@2.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-2xpw-w6gg-jr37","slug":"ghsa-2xpw-w6gg-jr37-91cead57","dossier":true,"summary":"urllib3 streaming API improperly handles highly compressed data","aliases":["CVE-2025-66471","PYSEC-2026-1994"],"sourceIds":["GHSA-2xpw-w6gg-jr37","PYSEC-2026-1994"],"published":"2025-12-05T18:15:54Z","modified":"2026-07-07T17:56:33.872074196Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-33p9-3p43-82vq","slug":"ghsa-33p9-3p43-82vq-f6a57ddd","dossier":false,"summary":"Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability","aliases":["CVE-2025-30167","PYSEC-2026-1477"],"sourceIds":["GHSA-33p9-3p43-82vq","PYSEC-2026-1477"],"published":"2025-06-04T21:00:23Z","modified":"2026-07-07T17:57:34.145908633Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/security/advisories/GHSA-33p9-3p43-82vq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30167"},{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/commit/5e8965600adda6b416692ce7e85ecb2bd814bd52"},{"type":"PACKAGE","url":"https://github.com/jupyter/jupyter_core"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-33p9-3p43-82vq"}],"versionKeys":["pypi:jupyter-core@5.7.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-3644-q5cj-c5c7","slug":"ghsa-3644-q5cj-c5c7-4c578cf2","dossier":false,"summary":"LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","aliases":["CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"sourceIds":["GHSA-3644-q5cj-c5c7","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"published":"2026-05-13T15:29:30Z","modified":"2026-07-13T16:43:39.736848907Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45134"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3644-q5cj-c5c7"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-classic"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"}],"versionKeys":["pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4"],"packageCount":3,"repositoryCount":3},{"id":"GHSA-37w4-hwhx-4rc4","slug":"ghsa-37w4-hwhx-4rc4-705a8c0a","dossier":false,"summary":"JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request","aliases":["BIT-jupyterlab-2026-42266","CVE-2026-42266","PYSEC-2026-164"],"sourceIds":["GHSA-37w4-hwhx-4rc4","PYSEC-2026-164"],"published":"2026-05-05T20:53:18Z","modified":"2026-06-08T20:31:00.051032052Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42266"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"FIX","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyterlab/PYSEC-2026-164.yaml"},{"type":"WEB","url":"https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html"},{"type":"WEB","url":"https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations"}],"versionKeys":["pypi:jupyterlab@4.4.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-38jv-5279-wg99","slug":"ghsa-38jv-5279-wg99-c9df8f7b","dossier":true,"summary":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)","aliases":["CVE-2026-21441","PYSEC-2026-1996"],"sourceIds":["GHSA-38jv-5279-wg99","PYSEC-2026-1996"],"published":"2026-01-07T19:18:14Z","modified":"2026-07-07T17:56:31.346111893Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38jv-5279-wg99"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-3crg-w4f6-42mx","slug":"ghsa-3crg-w4f6-42mx-48ac41a9","dossier":false,"summary":"pypdf: Manipulated XMP metadata entity declarations can exhaust RAM","aliases":["CVE-2026-40260","PYSEC-2026-3006"],"sourceIds":["GHSA-3crg-w4f6-42mx","PYSEC-2026-3006"],"published":"2026-04-10T20:59:36Z","modified":"2026-07-13T16:42:24.793622978Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-3crg-w4f6-42mx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40260"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3724"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/b15a374e5ca648d4878e57c3b2c0551e7f8cc7f8"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3crg-w4f6-42mx"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-3wq7-rqq7-wx6j","slug":"ghsa-3wq7-rqq7-wx6j-29b8d785","dossier":false,"summary":"AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS","aliases":["CVE-2026-34517","PYSEC-2026-2099"],"sourceIds":["GHSA-3wq7-rqq7-wx6j","PYSEC-2026-2099"],"published":"2026-04-01T21:16:59.870Z","modified":"2026-07-13T07:26:13.561233517Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-3wq7-rqq7-wx6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34517"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/cbb774f38330563422ca0c413a71021d7b944145"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-3x9g-8vmp-wqvf","slug":"ghsa-3x9g-8vmp-wqvf-6d03bf5f","dossier":false,"summary":"Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient","aliases":["CVE-2026-49853","PYSEC-2026-3387"],"sourceIds":["GHSA-3x9g-8vmp-wqvf","PYSEC-2026-3387"],"published":"2026-06-15T20:20:00Z","modified":"2026-07-13T16:42:55.378655356Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3x9g-8vmp-wqvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49853"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-428g-f7cq-pgp5","slug":"ghsa-428g-f7cq-pgp5-bfab95ee","dossier":false,"summary":"Marshmallow has DoS in Schema.load(many)","aliases":["CVE-2025-68480","PYSEC-2026-1605"],"sourceIds":["GHSA-428g-f7cq-pgp5","PYSEC-2026-1605"],"published":"2025-12-22T20:20:07Z","modified":"2026-07-07T17:56:15.810789183Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68480"},{"type":"WEB","url":"https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508"},{"type":"PACKAGE","url":"https://github.com/marshmallow-code/marshmallow"},{"type":"PACKAGE","url":"https://pypi.org/project/marshmallow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-428g-f7cq-pgp5"}],"versionKeys":["pypi:marshmallow@3.24.2","pypi:marshmallow@3.26.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-45hq-cxwh-f6vc","slug":"ghsa-45hq-cxwh-f6vc-d18d2872","dossier":true,"summary":"Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading","aliases":["BIT-pillow-2026-55379","CVE-2026-55379","PYSEC-2026-2255"],"sourceIds":["GHSA-45hq-cxwh-f6vc","PYSEC-2026-2255"],"published":"2026-07-06T19:17:08.577Z","modified":"2026-07-22T02:59:39.058744123Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55379"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-45pg-36p6-83v9","slug":"ghsa-45pg-36p6-83v9-9505da12","dossier":false,"summary":"Langchain SQL Injection vulnerability","aliases":["CVE-2024-8309","PYSEC-2024-115","PYSEC-2026-1507"],"sourceIds":["GHSA-45pg-36p6-83v9"],"published":"2024-10-29T15:32:05Z","modified":"2026-07-07T17:57:12.591755527Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8309"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/64c317eba05fbac0c6a6fc5aa192bc0d7130972e"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-115.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-469j-vmhf-r6v7","slug":"ghsa-469j-vmhf-r6v7-df07d853","dossier":false,"summary":"NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite","aliases":["CVE-2026-33236","PYSEC-2026-2237"],"sourceIds":["GHSA-469j-vmhf-r6v7","PYSEC-2026-2237"],"published":"2026-03-19T12:42:42Z","modified":"2026-07-13T07:26:54.270611709Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/nltk/nltk/security/advisories/GHSA-469j-vmhf-r6v7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33236"},{"type":"FIX","url":"https://github.com/nltk/nltk/commit/89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-33236"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33236.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2449824"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-48p4-8xcf-vxj5","slug":"ghsa-48p4-8xcf-vxj5-13f12656","dossier":false,"summary":"urllib3 does not control redirects in browsers and Node.js","aliases":["CVE-2025-50182","PYSEC-2026-1997"],"sourceIds":["GHSA-48p4-8xcf-vxj5","PYSEC-2026-1997"],"published":"2025-06-18T17:50:11Z","modified":"2026-07-07T17:57:08.881416805Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-4c99-qj7h-p3vg","slug":"ghsa-4c99-qj7h-p3vg-9bb362f6","dossier":false,"summary":"nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames","aliases":["CVE-2026-39377","PYSEC-2026-2229"],"sourceIds":["GHSA-4c99-qj7h-p3vg","PYSEC-2026-2229"],"published":"2026-04-21T01:16:05.937Z","modified":"2026-07-13T07:26:39.970591013Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-4c99-qj7h-p3vg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39377"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.1"}],"versionKeys":["pypi:nbconvert@7.16.6"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4f6g-68pf-7vhv","slug":"ghsa-4f6g-68pf-7vhv-c3002af6","dossier":false,"summary":"pypdf has possible long runtimes for malformed startxref","aliases":["CVE-2026-22691","PYSEC-2026-1828"],"sourceIds":["GHSA-4f6g-68pf-7vhv","PYSEC-2026-1828"],"published":"2026-01-09T19:48:57Z","modified":"2026-07-07T17:56:05.491150444Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-4f6g-68pf-7vhv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22691"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3594"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/294165726b646bb7799be1cc787f593f2fdbcf45"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.6.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4f6g-68pf-7vhv"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4fvr-rgm6-gqmc","slug":"ghsa-4fvr-rgm6-gqmc-c8b35c87","dossier":false,"summary":"aiohttp: HTTP/1 Pipelined Requests Queue Without Limit","aliases":["CVE-2026-54273","PYSEC-2026-2107"],"sourceIds":["GHSA-4fvr-rgm6-gqmc","PYSEC-2026-2107"],"published":"2026-06-15T20:10:32Z","modified":"2026-07-13T07:26:17.316378610Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4j32-57v6-6g45","slug":"ghsa-4j32-57v6-6g45-cd8913d1","dossier":false,"summary":"Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs","aliases":["CVE-2026-59925","PYSEC-2026-2213"],"sourceIds":["GHSA-4j32-57v6-6g45","PYSEC-2026-2213"],"published":"2026-07-08T17:17:28.183Z","modified":"2026-07-20T21:46:43.348949802Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59925"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2213.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4m7w-qmgq-4wj5","slug":"ghsa-4m7w-qmgq-4wj5-f98433d3","dossier":false,"summary":"aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections","aliases":["CVE-2026-54275","PYSEC-2026-237"],"sourceIds":["GHSA-4m7w-qmgq-4wj5","PYSEC-2026-237"],"published":"2026-06-15T20:11:13Z","modified":"2026-06-27T11:26:29.646102490Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4m7w-qmgq-4wj5"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4pxv-j86v-mhcw","slug":"ghsa-4pxv-j86v-mhcw-e5838cfe","dossier":false,"summary":"pypdf: Possible long runtimes for wrong size values in incremental mode","aliases":["CVE-2026-41313","PYSEC-2026-3007"],"sourceIds":["GHSA-4pxv-j86v-mhcw","PYSEC-2026-3007"],"published":"2026-04-16T21:30:12Z","modified":"2026-07-13T16:43:42.160859361Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-4pxv-j86v-mhcw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41313"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3735"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/c50a0104cf083356f7c7f5d61410466a57f5c88a"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4pxv-j86v-mhcw"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4x4j-2g7c-83w6","slug":"ghsa-4x4j-2g7c-83w6-326c14d2","dossier":true,"summary":"Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path","aliases":["BIT-pillow-2026-55798","CVE-2026-55798","PYSEC-2026-2257"],"sourceIds":["GHSA-4x4j-2g7c-83w6","PYSEC-2026-2257"],"published":"2026-07-06T19:17:08.830Z","modified":"2026-07-22T02:59:40.755856576Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55798"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8a"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/88194166691b7b603529b8b036ab3ab9cedd2de4"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/b0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2257.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-4xc4-762w-m6cg","slug":"ghsa-4xc4-762w-m6cg-fd09c73f","dossier":false,"summary":"pypdf has possible long runtimes for missing /Root object with large /Size values","aliases":["CVE-2026-22690","PYSEC-2026-1829"],"sourceIds":["GHSA-4xc4-762w-m6cg","PYSEC-2026-1829"],"published":"2026-01-09T19:48:22Z","modified":"2026-07-07T17:56:40.246085806Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-4xc4-762w-m6cg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22690"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3594"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/294165726b646bb7799be1cc787f593f2fdbcf45"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.6.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4xc4-762w-m6cg"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4xgf-cpjx-pc3j","slug":"ghsa-4xgf-cpjx-pc3j-c1284f87","dossier":false,"summary":"pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size","aliases":["CVE-2026-58203"],"sourceIds":["GHSA-4xgf-cpjx-pc3j"],"published":"2026-06-19T22:10:42Z","modified":"2026-07-08T08:12:48.604645024Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j"},{"type":"PACKAGE","url":"https://github.com/pydantic/pydantic-settings"}],"versionKeys":["pypi:pydantic-settings@2.12.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5239-wwwm-4pmq","slug":"ghsa-5239-wwwm-4pmq-228840e4","dossier":true,"summary":"Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching","aliases":["CVE-2026-4539","PYSEC-2026-2987"],"sourceIds":["GHSA-5239-wwwm-4pmq","PYSEC-2026-2987"],"published":"2026-03-22T06:30:15Z","modified":"2026-07-13T16:42:36.989801915Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4539"},{"type":"WEB","url":"https://github.com/pygments/pygments/issues/3058"},{"type":"WEB","url":"https://github.com/pygments/pygments/pull/3064"},{"type":"WEB","url":"https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc"},{"type":"PACKAGE","url":"https://github.com/pygments/pygments"},{"type":"WEB","url":"https://github.com/pygments/pygments/releases/tag/2.20.0"},{"type":"WEB","url":"https://vuldb.com/?ctiid.352327"},{"type":"WEB","url":"https://vuldb.com/?id.352327"},{"type":"WEB","url":"https://vuldb.com/?submit.774685"},{"type":"PACKAGE","url":"https://pypi.org/project/pygments"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5239-wwwm-4pmq"}],"versionKeys":["pypi:pygments@2.19.1","pypi:pygments@2.19.2"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-52x6-gq3r-vpf4","slug":"ghsa-52x6-gq3r-vpf4-d634019a","dossier":false,"summary":"pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction","aliases":["CVE-2026-54530","PYSEC-2026-3009"],"sourceIds":["GHSA-52x6-gq3r-vpf4","PYSEC-2026-3009"],"published":"2026-06-16T14:05:40Z","modified":"2026-07-13T16:43:09.668829202Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-52x6-gq3r-vpf4"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3830"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.13.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-52x6-gq3r-vpf4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54530"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-537c-gmf6-5ccf","slug":"ghsa-537c-gmf6-5ccf-23a24e16","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-537c-gmf6-5ccf"],"published":"2026-06-15T20:12:27Z","modified":"2026-06-16T19:59:26.897634900Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260609.txt"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-54jq-c3m8-4m76","slug":"ghsa-54jq-c3m8-4m76-bba4b2d3","dossier":false,"summary":"AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components","aliases":["CVE-2025-69226","PYSEC-2026-1097"],"sourceIds":["GHSA-54jq-c3m8-4m76","PYSEC-2026-1097"],"published":"2026-01-05T23:09:51Z","modified":"2026-07-07T17:57:12.462419549Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-54jq-c3m8-4m76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69226"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f2a86fd5ac0383000d1715afddfa704413f0711e"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-54jq-c3m8-4m76"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-55h5-xmcq-c37v","slug":"ghsa-55h5-xmcq-c37v-35177962","dossier":false,"summary":"pypdf: Possible long runtimes for repeated malformed cross-reference entries","aliases":["CVE-2026-59937"],"sourceIds":["GHSA-55h5-xmcq-c37v"],"published":"2026-07-23T15:07:33Z","modified":"2026-07-29T21:14:53.988004211Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59937"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3887"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50dae"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.14.0"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5789-5fc7-67v3","slug":"ghsa-5789-5fc7-67v3-d09440f9","dossier":false,"summary":"Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories","aliases":["CVE-2026-35397","PYSEC-2026-68"],"sourceIds":["GHSA-5789-5fc7-67v3","PYSEC-2026-68"],"published":"2026-05-05T16:49:10Z","modified":"2026-06-06T00:30:08.780496042Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35397"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-68.yaml"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-58cw-g322-p94v","slug":"ghsa-58cw-g322-p94v-a1eee673","dossier":false,"summary":"Mistune has XSS via unescaped figclass/figwidth in Figure directive","aliases":["CVE-2026-44896","PYSEC-2026-168"],"sourceIds":["GHSA-58cw-g322-p94v","PYSEC-2026-168"],"published":"2026-05-08T23:43:12Z","modified":"2026-06-08T23:45:17.995583404Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/security/advisories/GHSA-58cw-g322-p94v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44896"},{"type":"WEB","url":"https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-168.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-59g5-xgcq-4qw3","slug":"ghsa-59g5-xgcq-4qw3-949fce0e","dossier":false,"summary":"Denial of service (DoS) via deformation `multipart/form-data` boundary","aliases":["CVE-2024-53981","PYSEC-2026-1851"],"sourceIds":["GHSA-59g5-xgcq-4qw3","PYSEC-2026-1851"],"published":"2024-12-02T21:37:04Z","modified":"2026-07-07T17:56:30.840745333Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-59g5-xgcq-4qw3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53981"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/commit/c4fe4d3cebc08c660e57dd709af1ffa7059b3177"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-59g5-xgcq-4qw3"}],"versionKeys":["pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5chr-fjjv-38qv","slug":"ghsa-5chr-fjjv-38qv-5f3dd755","dossier":false,"summary":"langchain-core allows unauthorized users to read arbitrary files from the host file system","aliases":["CVE-2024-10940","PYSEC-2026-1517"],"sourceIds":["GHSA-5chr-fjjv-38qv","PYSEC-2026-1517"],"published":"2025-03-20T12:32:41Z","modified":"2026-07-07T17:56:35.905913395Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10940"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/7d481f10102f43559cc57bcad7eba291067939ee"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c1e742347f9701aadba8920e4d1f79a636e50b68"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/e711034713259ae448981bc0fd1d7a5671499c31"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://huntr.com/bounties/be1ee1cb-2147-4ff4-a57b-b6045271cf27"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5chr-fjjv-38qv"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5hgr-hg42-57jg","slug":"ghsa-5hgr-hg42-57jg-7ca5115e","dossier":false,"summary":"pypdf: Inefficient decoding of FlateDecode PNG predictor streams","aliases":["CVE-2026-49460","PYSEC-2026-3010"],"sourceIds":["GHSA-5hgr-hg42-57jg","PYSEC-2026-3010"],"published":"2026-06-16T13:46:42Z","modified":"2026-07-13T16:42:25.325556250Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-5hgr-hg42-57jg"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3806"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.12.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5hgr-hg42-57jg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49460"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5mrq-x3x5-8v8f","slug":"ghsa-5mrq-x3x5-8v8f-c6e2734e","dossier":false,"summary":"Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart","aliases":["CVE-2026-40934","PYSEC-2026-69"],"sourceIds":["GHSA-5mrq-x3x5-8v8f","PYSEC-2026-69"],"published":"2026-05-05T17:03:24Z","modified":"2026-06-06T00:45:47.735760264Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40934"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-69.yaml"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5qjq-93h5-hrgp","slug":"ghsa-5qjq-93h5-hrgp-c5495e01","dossier":false,"summary":"pypdf: Possible large memory usage for wrong image dimensions","aliases":["CVE-2026-59938"],"sourceIds":["GHSA-5qjq-93h5-hrgp"],"published":"2026-07-23T15:06:58Z","modified":"2026-07-29T21:14:52.909510373Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59938"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3888"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.14.0"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5rjg-fvgr-3xxf","slug":"ghsa-5rjg-fvgr-3xxf-79d39e6b","dossier":false,"summary":"setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write","aliases":["BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49"],"sourceIds":["GHSA-5rjg-fvgr-3xxf","PYSEC-2025-49"],"published":"2025-05-17T16:15:19Z","modified":"2026-05-11T00:26:34.671259971Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273"},{"type":"REPORT","url":"https://github.com/pypa/setuptools/issues/4946"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@72.2.0","pypi:setuptools@75.8.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-5rvq-cxj2-64vf","slug":"ghsa-5rvq-cxj2-64vf-5e3e7388","dossier":false,"summary":"python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service","aliases":["CVE-2026-53539","PYSEC-2026-3036"],"sourceIds":["GHSA-5rvq-cxj2-64vf","PYSEC-2026-3036"],"published":"2026-06-15T20:24:09Z","modified":"2026-07-13T16:42:40.830680801Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5rvq-cxj2-64vf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53539"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-5x94-69rx-g8h2","slug":"ghsa-5x94-69rx-g8h2-0bc05f88","dossier":true,"summary":"Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`","aliases":["BIT-pillow-2026-54060","CVE-2026-54060","PYSEC-2026-2254"],"sourceIds":["GHSA-5x94-69rx-g8h2","PYSEC-2026-2254"],"published":"2026-07-06T19:17:08.270Z","modified":"2026-07-22T02:59:38.824757212Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54060"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-5xf7-4p34-54qr","slug":"ghsa-5xf7-4p34-54qr-f10a0476","dossier":false,"summary":"pypdf: Possible infinite loop for not terminated inline images","aliases":["CVE-2026-59936"],"sourceIds":["GHSA-5xf7-4p34-54qr"],"published":"2026-07-23T16:36:41Z","modified":"2026-07-29T21:14:53.202932754Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-5xf7-4p34-54qr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59936"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3891"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/ec3b14596186c40caca7cf8ab9b2155203e01b5b"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.14.1"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5xmw-vc9v-4wf2","slug":"ghsa-5xmw-vc9v-4wf2-86a8861a","dossier":false,"summary":"Pillow has a heap buffer overflow with nested list coordinates","aliases":["BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251"],"sourceIds":["GHSA-5xmw-vc9v-4wf2","PYSEC-2026-2251"],"published":"2026-05-04T20:18:27Z","modified":"2026-07-13T07:26:28.768890335Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5xmw-vc9v-4wf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42309"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-62p4-gmf7-7g93","slug":"ghsa-62p4-gmf7-7g93-cb81341c","dossier":true,"summary":"Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)","aliases":["BIT-pillow-2026-54058","CVE-2026-54058","PYSEC-2026-3493"],"sourceIds":["GHSA-62p4-gmf7-7g93","PYSEC-2026-3493"],"published":"2026-07-20T21:08:13Z","modified":"2026-07-23T15:11:42.568996050Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54058"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9719"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-62p4-gmf7-7g93"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-63hf-3vf5-4wqf","slug":"ghsa-63hf-3vf5-4wqf-aadd9f0f","dossier":false,"summary":"AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass","aliases":["CVE-2026-34520","PYSEC-2026-2102"],"sourceIds":["GHSA-63hf-3vf5-4wqf","PYSEC-2026-2102"],"published":"2026-04-01T21:17:00.333Z","modified":"2026-07-15T22:00:51.319409225Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hf-3vf5-4wqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34520"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2026-2102.yaml"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-63hw-fmq6-xxg2","slug":"ghsa-63hw-fmq6-xxg2-00aac622","dossier":false,"summary":"aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines","aliases":["CVE-2026-54277","PYSEC-2026-2110"],"sourceIds":["GHSA-63hw-fmq6-xxg2","PYSEC-2026-2110"],"published":"2026-06-15T20:09:16Z","modified":"2026-07-13T07:26:29.010491244Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hw-fmq6-xxg2"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5ab61bb4cd88f19b712f12c7c9295fe262bf804d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-63vm-454h-vhhq","slug":"ghsa-63vm-454h-vhhq-296aa7fc","dossier":false,"summary":"pyasn1 has a DoS vulnerability in decoder","aliases":["CVE-2026-23490","PYSEC-2026-1810"],"sourceIds":["GHSA-63vm-454h-vhhq","PYSEC-2026-1810"],"published":"2026-01-16T19:19:25Z","modified":"2026-07-21T15:30:39.563600361Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23490"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/be353d755f42ea36539b4f5053c652ddf56979a6"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4148"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4147"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4146"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4145"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4144"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4143"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4142"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4141"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4140"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4139"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4138"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:39894"},{"type":"PACKAGE","url":"https://github.com/pyasn1/pyasn1"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/blob/0f07d7242a78ab4d129b26256d7474f7168cf536/pyasn1/codec/ber/decoder.py#L496"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/02/msg00002.html"}],"versionKeys":["pypi:pyasn1@0.6.1"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-07-08T17:45:15.021597323Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7"],"packageCount":1,"repositoryCount":17},{"id":"GHSA-68j8-pq59-fqgm","slug":"ghsa-68j8-pq59-fqgm-94af8991","dossier":false,"summary":"NLTK has a Path Traversal issue","aliases":["CVE-2026-0847","PYSEC-2026-98"],"sourceIds":["GHSA-68j8-pq59-fqgm","PYSEC-2026-98"],"published":"2026-03-04T19:16:10.683Z","modified":"2026-06-10T17:02:23.764228465Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0847"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-98.yaml"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/fc69914f-36a9-4c18-8503-10013b39f966"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-68j8-pq59-fqgm"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-69f9-5gxw-wvc2","slug":"ghsa-69f9-5gxw-wvc2-eec14573","dossier":false,"summary":"AIOHTTP's unicode processing of header values could cause parsing discrepancies","aliases":["CVE-2025-69224","PYSEC-2026-1099"],"sourceIds":["GHSA-69f9-5gxw-wvc2","PYSEC-2026-1099"],"published":"2026-01-05T22:58:57Z","modified":"2026-07-07T17:56:40.774148412Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-69f9-5gxw-wvc2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69224"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/32677f2adfd907420c078dda6b79225c6f4ebce0"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69f9-5gxw-wvc2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6hm5-jgcp-p838","slug":"ghsa-6hm5-jgcp-p838-200e0a21","dossier":false,"summary":"Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)","aliases":["CVE-2026-12072"],"sourceIds":["GHSA-6hm5-jgcp-p838"],"published":"2026-07-31T16:50:55Z","modified":"2026-07-31T17:00:21.718036171Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-6hm5-jgcp-p838"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6jhg-hg63-jvvf","slug":"ghsa-6jhg-hg63-jvvf-74cd77d8","dossier":false,"summary":"AIOHTTP vulnerable to  denial of service through large payloads","aliases":["CVE-2025-69228","PYSEC-2026-1100"],"sourceIds":["GHSA-6jhg-hg63-jvvf","PYSEC-2026-1100"],"published":"2026-01-05T23:13:14Z","modified":"2026-07-07T17:57:35.249454020Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69228"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jhg-hg63-jvvf"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6jv3-5f52-599m","slug":"ghsa-6jv3-5f52-599m-dd700d26","dossier":false,"summary":"python-multipart: Semicolon treated as querystring field separator enables parameter smuggling","aliases":["CVE-2026-53538","PYSEC-2026-3037"],"sourceIds":["GHSA-6jv3-5f52-599m","PYSEC-2026-3037"],"published":"2026-06-15T20:22:25Z","modified":"2026-07-13T16:43:47.733262470Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jv3-5f52-599m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53538"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-6mq8-rvhq-8wgg","slug":"ghsa-6mq8-rvhq-8wgg-d94d738f","dossier":false,"summary":"AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb","aliases":["CVE-2025-69223","PYSEC-2026-1101"],"sourceIds":["GHSA-6mq8-rvhq-8wgg","PYSEC-2026-1101"],"published":"2026-01-05T22:58:41Z","modified":"2026-07-07T17:56:11.402262091Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69223"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6mq8-rvhq-8wgg"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6qv9-48xg-fc7f","slug":"ghsa-6qv9-48xg-fc7f-6f0bc426","dossier":false,"summary":"LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates","aliases":["CVE-2025-65106","PYSEC-2026-1518"],"sourceIds":["GHSA-6qv9-48xg-fc7f","PYSEC-2026-1518"],"published":"2025-11-20T17:42:12Z","modified":"2026-07-07T17:57:16.939269197Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-6qv9-48xg-fc7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65106"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c4b6ba254e1a49ed91f2e268e6484011c540542a"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/fa7789d6c21222b85211755d822ef698d3b34e00"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6qv9-48xg-fc7f"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-6r8x-57c9-28j4","slug":"ghsa-6r8x-57c9-28j4-3a620dbf","dossier":true,"summary":"Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow","aliases":["BIT-pillow-2026-59199","CVE-2026-59199","PYSEC-2026-3451"],"sourceIds":["GHSA-6r8x-57c9-28j4","PYSEC-2026-3451"],"published":"2026-07-14T16:17:01.937Z","modified":"2026-07-22T02:59:40.188047466Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59199"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9703"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3451.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-6w46-j5rx-g56g","slug":"ghsa-6w46-j5rx-g56g-5324d549","dossier":false,"summary":"pytest has vulnerable tmpdir handling","aliases":["CVE-2025-71176","PYSEC-2026-1845"],"sourceIds":["GHSA-6w46-j5rx-g56g","PYSEC-2026-1845"],"published":"2026-01-22T06:30:29Z","modified":"2026-07-07T17:56:26.471696626Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71176"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/issues/13669"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/pull/14343"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/commit/95d8423bd24992deea5b9df32555fa1741679e2c"},{"type":"PACKAGE","url":"https://github.com/pytest-dev/pytes"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/releases/tag/9.0.3"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/01/21/5"},{"type":"PACKAGE","url":"https://pypi.org/project/pytest"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6w46-j5rx-g56g"}],"versionKeys":["pypi:pytest@7.2.2","pypi:pytest@7.4.4","pypi:pytest@8.3.2","pypi:pytest@9.0.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-7432-952r-cw78","slug":"ghsa-7432-952r-cw78-bf3fc71f","dossier":false,"summary":"Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle","aliases":["CVE-2026-28490","PYSEC-2026-2116"],"sourceIds":["GHSA-7432-952r-cw78","PYSEC-2026-2116"],"published":"2026-03-16T15:17:28Z","modified":"2026-07-13T07:26:14.887077371Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-7432-952r-cw78"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28490"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/48b345f29f6c459f11c6a40162b6c0b742ef2e22"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"ADVISORY","url":"https://github.com/authlib/authlib/releases/tag/v1.6.9"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-752w-5fwx-jx9f","slug":"ghsa-752w-5fwx-jx9f-389afa77","dossier":false,"summary":"PyJWT accepts unknown `crit` header extensions","aliases":["CVE-2026-32597","PYSEC-2026-120"],"sourceIds":["GHSA-752w-5fwx-jx9f","PYSEC-2026-120"],"published":"2026-03-13T19:55:09.500Z","modified":"2026-06-08T19:15:12.447890578Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32597"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-120.yaml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/05/msg00008.html"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-78cv-mqj4-43f7","slug":"ghsa-78cv-mqj4-43f7-2021f695","dossier":false,"summary":"Tornado has incomplete validation of cookie attributes","aliases":["CVE-2026-35536","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287"],"sourceIds":["GHSA-78cv-mqj4-43f7","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287"],"published":"2026-03-11T22:17:00Z","modified":"2026-07-13T16:45:06.531920939Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35536"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fqwm-6jpj-5wxc"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-79v4-65xg-pq4g","slug":"ghsa-79v4-65xg-pq4g-b911b371","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":["CVE-2024-12797","PYSEC-2026-1284"],"sourceIds":["GHSA-79v4-65xg-pq4g","PYSEC-2026-1284"],"published":"2025-02-11T18:06:42Z","modified":"2026-07-07T17:57:01.916729628Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12797"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20250211.txt"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-79v4-65xg-pq4g"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7cx3-6m66-7c5m","slug":"ghsa-7cx3-6m66-7c5m-cde5125c","dossier":false,"summary":"Tornado vulnerable to excessive logging caused by malformed multipart form data","aliases":["CVE-2025-47287","PYSEC-2026-1974"],"sourceIds":["GHSA-7cx3-6m66-7c5m","PYSEC-2026-1974"],"published":"2025-05-16T14:12:40Z","modified":"2026-07-07T17:56:45.268719923Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47287"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7cx3-6m66-7c5m"}],"versionKeys":["pypi:tornado@6.4.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-7f5h-v6xp-fcq8","slug":"ghsa-7f5h-v6xp-fcq8-9393173e","dossier":false,"summary":"Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``","aliases":["CVE-2025-62727","PYSEC-2026-1942"],"sourceIds":["GHSA-7f5h-v6xp-fcq8","PYSEC-2026-1942"],"published":"2025-10-28T20:38:01Z","modified":"2026-07-07T17:56:07.620081354Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-7f5h-v6xp-fcq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62727"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/4ea6e22b489ec388d6004cfbca52dd5b147127c5"},{"type":"INTRODUCED","url":"https://github.com/Kludex/starlette/commit/69ed26a85956ef4bd0161807eb27abf49be7cd3c"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/Kludex/starlette/releases/tag/0.49.1"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7f5h-v6xp-fcq8"}],"versionKeys":["pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-7gcm-g887-7qv7","slug":"ghsa-7gcm-g887-7qv7-55bb9ff1","dossier":false,"summary":"protobuf affected by a JSON recursion depth bypass","aliases":["CVE-2026-0994","PYSEC-2026-1805"],"sourceIds":["GHSA-7gcm-g887-7qv7","PYSEC-2026-1805"],"published":"2026-01-23T15:31:35Z","modified":"2026-07-07T17:56:36.712428283Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0994"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/issues/25070"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/pull/25239"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/5ebddcb1bcbe51d1fe323baa145e85f4f23128cf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/d2b001626d137c62dfee6c88c87324102531868b"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7gcm-g887-7qv7"}],"versionKeys":["pypi:protobuf@4.25.7","pypi:protobuf@4.25.8","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4","pypi:protobuf@6.31.1","pypi:protobuf@6.32.0","pypi:protobuf@6.33.0","pypi:protobuf@6.33.1","pypi:protobuf@6.33.4"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-7gw9-cf7v-778f","slug":"ghsa-7gw9-cf7v-778f-8b6e5034","dossier":false,"summary":"pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM","aliases":["CVE-2026-41312","PYSEC-2026-3011"],"sourceIds":["GHSA-7gw9-cf7v-778f","PYSEC-2026-3011"],"published":"2026-04-16T21:30:00Z","modified":"2026-07-13T16:42:36.454088588Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-7gw9-cf7v-778f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41312"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3734"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7gw9-cf7v-778f"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-7hfw-26vp-jp8m","slug":"ghsa-7hfw-26vp-jp8m-d08917d7","dossier":false,"summary":"PyPDF's Manipulated FlateDecode streams can exhaust RAM","aliases":["CVE-2025-55197","PYSEC-2026-1830"],"sourceIds":["GHSA-7hfw-26vp-jp8m","PYSEC-2026-1830"],"published":"2025-08-13T19:51:24Z","modified":"2026-07-07T17:57:06.843769097Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-7hfw-26vp-jp8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55197"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/issues/3429"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3430"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/blob/0dd57738bbdcdb63f0fb43d8a6b3d222b6946595/pypdf/filters.py#L72-L143"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.0.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7hfw-26vp-jp8m"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-7jqv-fw35-gmx9","slug":"ghsa-7jqv-fw35-gmx9-d6bf4abd","dossier":false,"summary":"nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding","aliases":["CVE-2026-39378","PYSEC-2026-2230"],"sourceIds":["GHSA-7jqv-fw35-gmx9","PYSEC-2026-2230"],"published":"2026-04-21T01:16:06.073Z","modified":"2026-07-13T07:26:18.607056830Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-7jqv-fw35-gmx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39378"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.1"}],"versionKeys":["pypi:nbconvert@7.16.6"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-7p94-766c-hgjp","slug":"ghsa-7p94-766c-hgjp-50b78c94","dossier":false,"summary":"NLTK has a Zip Slip Vulnerability","aliases":["CVE-2025-14009","PYSEC-2026-96"],"sourceIds":["GHSA-7p94-766c-hgjp","PYSEC-2026-96"],"published":"2026-02-18T18:24:19.410Z","modified":"2026-06-10T17:02:23.646726882Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14009"},{"type":"WEB","url":"https://github.com/nltk/nltk/pull/3468"},{"type":"WEB","url":"https://github.com/nltk/nltk/commit/1056b323af6462455571302e766b67cf300aea18"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://github.com/nltk/nltk/blob/4154eb85e832f266660a09286c7e37e308292284/ChangeLog#L1"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-96.yaml"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/49ecbc02-054e-4470-b2e0-b267936cc4e4"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7p94-766c-hgjp"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-82w8-qh3p-5jfq","slug":"ghsa-82w8-qh3p-5jfq-a05ef51e","dossier":false,"summary":"Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS","aliases":["CVE-2026-54283","PYSEC-2026-249"],"sourceIds":["GHSA-82w8-qh3p-5jfq","PYSEC-2026-249"],"published":"2026-06-15T20:39:53Z","modified":"2026-06-27T11:26:15.727496147Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-836r-79rf-4m37","slug":"ghsa-836r-79rf-4m37-54a23e8e","dossier":false,"summary":"Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser","aliases":["CVE-2026-49477","PYSEC-2026-3072"],"sourceIds":["GHSA-836r-79rf-4m37","PYSEC-2026-3072"],"published":"2026-07-09T13:37:46Z","modified":"2026-07-13T16:42:45.934231028Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37"},{"type":"PACKAGE","url":"https://github.com/facelessuser/soupsieve"},{"type":"PACKAGE","url":"https://pypi.org/project/soupsieve"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-836r-79rf-4m37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49477"}],"versionKeys":["pypi:soupsieve@2.6","pypi:soupsieve@2.7","pypi:soupsieve@2.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-86qp-5c8j-p5mr","slug":"ghsa-86qp-5c8j-p5mr-13e563cb","dossier":false,"summary":"Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks","aliases":["CVE-2026-48710","PYSEC-2026-161","X41-2026-002"],"sourceIds":["GHSA-86qp-5c8j-p5mr","PYSEC-2026-161"],"published":"2026-05-22T13:10:03Z","modified":"2026-07-24T15:49:06.735363896Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48710"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6"},{"type":"WEB","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette"},{"type":"ARTICLE","url":"https://www.secwest.net/starlette"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-48710"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json"},{"type":"WEB","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481742"},{"type":"DETECTION","url":"https://badhost.org/"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48710"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:44696"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:43038"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"ARTICLE","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/"},{"type":"ADVISORY","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette/"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-87mj-5ggw-8qc3","slug":"ghsa-87mj-5ggw-8qc3-307f9690","dossier":false,"summary":"pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream","aliases":["CVE-2026-33699","PYSEC-2026-3012"],"sourceIds":["GHSA-87mj-5ggw-8qc3","PYSEC-2026-3012"],"published":"2026-03-25T20:05:22Z","modified":"2026-07-13T16:42:35.293920191Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-87mj-5ggw-8qc3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33699"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3693"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.9.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-87mj-5ggw-8qc3"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-89vp-jrxv-24w8","slug":"ghsa-89vp-jrxv-24w8-56cdaa85","dossier":false,"summary":"JupyterLab: PyPI extension blocklist package-name canonicalization bypass","aliases":[],"sourceIds":["GHSA-89vp-jrxv-24w8"],"published":"2026-07-22T23:14:27Z","modified":"2026-07-22T23:30:29.705646293Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"}],"versionKeys":["pypi:jupyterlab@4.6.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8c25-4j27-2rv3","slug":"ghsa-8c25-4j27-2rv3-4e2c246a","dossier":false,"summary":"Mistune: XSS via percent-encoded javascript URI bypass in safe_url()","aliases":["CVE-2026-59923","PYSEC-2026-2211"],"sourceIds":["GHSA-8c25-4j27-2rv3","PYSEC-2026-2211"],"published":"2026-07-08T17:17:27.910Z","modified":"2026-07-20T21:46:43.351006286Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59923"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2211.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8g87-j6q8-g93x","slug":"ghsa-8g87-j6q8-g93x-2e837b39","dossier":false,"summary":"Mistune Math Plugin has an XSS Escape Bypass","aliases":["CVE-2026-44708","PYSEC-2026-2206"],"sourceIds":["GHSA-8g87-j6q8-g93x","PYSEC-2026-2206"],"published":"2026-05-08T23:40:04Z","modified":"2026-07-13T07:26:26.365066334Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8g87-j6q8-g93x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44708"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8mp2-v27r-99xp","slug":"ghsa-8mp2-v27r-99xp-3e3baa33","dossier":false,"summary":"Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input","aliases":["CVE-2026-33079","PYSEC-2026-2651"],"sourceIds":["GHSA-8mp2-v27r-99xp","PYSEC-2026-2651"],"published":"2026-05-06T16:52:43Z","modified":"2026-07-13T16:42:39.431792280Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8mp2-v27r-99xp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33079"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://github.com/lepture/mistune/blob/df23edd60b43b639d2e6760ef9dd3d618aa11c21/src/mistune/helpers.py#L20-L25"},{"type":"PACKAGE","url":"https://pypi.org/project/mistune"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8mp2-v27r-99xp"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8mpj-m6qm-5qr8","slug":"ghsa-8mpj-m6qm-5qr8-24abd1d9","dossier":false,"summary":"Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files","aliases":["CVE-2026-59927","PYSEC-2026-2215"],"sourceIds":["GHSA-8mpj-m6qm-5qr8","PYSEC-2026-2215"],"published":"2026-07-08T17:17:28.450Z","modified":"2026-07-20T21:30:45.969881443Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59927"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2215.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8ppf-4f7h-5ppj","slug":"ghsa-8ppf-4f7h-5ppj-4d7d140d","dossier":false,"summary":"pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service","aliases":["CVE-2026-59885","PYSEC-2026-3456"],"sourceIds":["GHSA-8ppf-4f7h-5ppj","PYSEC-2026-3456"],"published":"2026-07-14T17:17:14.880Z","modified":"2026-07-23T09:29:39.188829469Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59885"},{"type":"FIX","url":"https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9"},{"type":"PACKAGE","url":"https://github.com/pyasn1/pyasn1"},{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"}],"versionKeys":["pypi:pyasn1@0.6.1","pypi:pyasn1@0.6.3"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-8qvm-5x2c-j2w7","slug":"ghsa-8qvm-5x2c-j2w7-8a075519","dossier":false,"summary":"protobuf-python has a potential Denial of Service issue","aliases":["CVE-2025-4565","PYSEC-2026-1806"],"sourceIds":["GHSA-8qvm-5x2c-j2w7","PYSEC-2026-1806"],"published":"2025-06-16T16:02:58Z","modified":"2026-07-07T17:57:09.877491994Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-735f-pc8j-v9w8"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8qvm-5x2c-j2w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4565"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/blob/main/python/google/protobuf/internal/decoder_test.py#L87-L98"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/blob/main/python/google/protobuf/internal/message_test.py#L1436-L1478"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/tree/main/python#implementation-backends"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8qvm-5x2c-j2w7"}],"versionKeys":["pypi:protobuf@4.25.7","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-8rfp-98v4-mmr6","slug":"ghsa-8rfp-98v4-mmr6-7ea7e5dd","dossier":false,"summary":"Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output","aliases":[],"sourceIds":["GHSA-8rfp-98v4-mmr6"],"published":"2026-06-16T14:06:29Z","modified":"2026-06-18T13:29:27.505774604Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/mozilla/bleach/security/advisories/GHSA-8rfp-98v4-mmr6"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2023812"},{"type":"PACKAGE","url":"https://github.com/mozilla/bleach"}],"versionKeys":["pypi:bleach@6.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8v84-f9pq-wr9x","slug":"ghsa-8v84-f9pq-wr9x-6c1b185f","dossier":true,"summary":"Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading","aliases":["BIT-pillow-2026-54059","CVE-2026-54059","PYSEC-2026-2253"],"sourceIds":["GHSA-8v84-f9pq-wr9x","PYSEC-2026-2253"],"published":"2026-07-06T19:17:08.127Z","modified":"2026-07-22T02:59:41.148041376Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54059"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2253.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-926x-3r5x-gfhw","slug":"ghsa-926x-3r5x-gfhw-b7d12e65","dossier":false,"summary":"LangChain has incomplete f-string validation in prompt templates","aliases":["CVE-2026-40087","PYSEC-2026-2563"],"sourceIds":["GHSA-926x-3r5x-gfhw","PYSEC-2026-2563"],"published":"2026-04-08T21:51:32Z","modified":"2026-07-13T16:42:42.901211235Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-926x-3r5x-gfhw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40087"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36612"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36613"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/6bab0ba3c12328008ddca3e0d54ff5a6151cd27b"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/af2ed47c6f008cdd551f3c0d87db3774c8dfe258"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.84"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.28"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-926x-3r5x-gfhw"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-9548-qrrj-x5pj","slug":"ghsa-9548-qrrj-x5pj-6121f213","dossier":false,"summary":"AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections","aliases":["CVE-2025-53643","PYSEC-2026-1104"],"sourceIds":["GHSA-9548-qrrj-x5pj","PYSEC-2026-1104"],"published":"2025-07-14T19:33:31Z","modified":"2026-07-07T17:56:52.935544397Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9548-qrrj-x5pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53643"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9548-qrrj-x5pj"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-966j-vmvw-g2g9","slug":"ghsa-966j-vmvw-g2g9-dad9a989","dossier":false,"summary":"AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect","aliases":["CVE-2026-34518","PYSEC-2026-2100"],"sourceIds":["GHSA-966j-vmvw-g2g9","PYSEC-2026-2100"],"published":"2026-04-01T21:17:00.020Z","modified":"2026-07-13T07:26:39.502317923Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-966j-vmvw-g2g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34518"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-993g-76c3-p5m4","slug":"ghsa-993g-76c3-p5m4-f823cd66","dossier":false,"summary":"PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes","aliases":["CVE-2026-48522","PYSEC-2026-175"],"sourceIds":["GHSA-993g-76c3-p5m4","PYSEC-2026-175"],"published":"2026-05-28T16:16:29.150Z","modified":"2026-06-16T14:44:20.882510824Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48522"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-175.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-996q-pr4m-cvgq","slug":"ghsa-996q-pr4m-cvgq-d5dc33e5","dossier":false,"summary":"pypdf has a possible infinite loop when processing TreeObject","aliases":["CVE-2026-27024","PYSEC-2026-3013"],"sourceIds":["GHSA-996q-pr4m-cvgq","PYSEC-2026-3013"],"published":"2026-02-18T22:40:49Z","modified":"2026-07-13T16:43:40.532306824Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-996q-pr4m-cvgq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27024"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3645"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/bd2f6d052fe5941e85e37082c2a43453d48d1295"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.7.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-996q-pr4m-cvgq"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9h52-p55h-vw2f","slug":"ghsa-9h52-p55h-vw2f-fc4c91e7","dossier":false,"summary":"Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default","aliases":["CVE-2025-66416","PYSEC-2026-1617"],"sourceIds":["GHSA-9h52-p55h-vw2f","PYSEC-2026-1617"],"published":"2025-12-02T16:52:08Z","modified":"2026-07-16T18:45:48.199773308Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-9h52-p55h-vw2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66416"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/d3a184119e4479ea6a63590bc41f01dc06e3fa99"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9h52-p55h-vw2f"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mcp/PYSEC-2026-1617.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-9hjg-9r4m-mvj7","slug":"ghsa-9hjg-9r4m-mvj7-32d7b63e","dossier":false,"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"sourceIds":["GHSA-9hjg-9r4m-mvj7","PYSEC-2026-1872"],"published":"2025-06-09T19:06:08Z","modified":"2026-07-07T17:56:56.234172558Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6965"},{"type":"FIX","url":"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2025/Jun/2"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-9hw9-ch79-4vh6","slug":"ghsa-9hw9-ch79-4vh6-1ebda54f","dossier":true,"summary":"Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch","aliases":["BIT-pillow-2026-59205","CVE-2026-59205","PYSEC-2026-3453"],"sourceIds":["GHSA-9hw9-ch79-4vh6","PYSEC-2026-3453"],"published":"2026-07-14T16:17:02.370Z","modified":"2026-07-22T02:59:40.628222965Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59205"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9715"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-9m86-7pmv-2852","slug":"ghsa-9m86-7pmv-2852-af0bf52f","dossier":false,"summary":"pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams","aliases":["CVE-2026-28804","PYSEC-2026-3014"],"sourceIds":["GHSA-9m86-7pmv-2852","PYSEC-2026-3014"],"published":"2026-03-02T22:03:45Z","modified":"2026-07-13T16:42:53.625666226Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28804"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3666"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.7.5"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9m86-7pmv-2852"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9mvc-8737-8j8h","slug":"ghsa-9mvc-8737-8j8h-7d8c6e58","dossier":false,"summary":"pypdf possibly has long runtimes for malformed FlateDecode streams","aliases":["CVE-2026-27026","PYSEC-2026-3015"],"sourceIds":["GHSA-9mvc-8737-8j8h","PYSEC-2026-3015"],"published":"2026-02-18T22:41:24Z","modified":"2026-07-13T16:42:59.576223829Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-9mvc-8737-8j8h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27026"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3644"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/7905842d833f899f1d3228af7e7467ad80277016"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.7.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9mvc-8737-8j8h"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9q39-rmj3-p4r2","slug":"ghsa-9q39-rmj3-p4r2-67d5744e","dossier":false,"summary":"HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering","aliases":["BIT-jupyter-base-notebook-2024-43805","BIT-jupyter-notebook-2024-43805","BIT-jupyterlab-2024-43805","CVE-2024-43805","PYSEC-2026-1481","PYSEC-2026-2536"],"sourceIds":["GHSA-9q39-rmj3-p4r2","PYSEC-2026-1481"],"published":"2024-08-29T17:55:53Z","modified":"2026-07-13T16:43:05.974128183Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43805"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/06ad9de836f155add7d3d651ef936cc4c5ea8093"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/88e24baac551196f9cb3de16bd060a7ab1597674"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9q39-rmj3-p4r2"}],"versionKeys":["pypi:notebook@7.0.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9wx4-h78v-vm56","slug":"ghsa-9wx4-h78v-vm56-6a334c57","dossier":false,"summary":"Requests `Session` object does not verify requests after making first request with verify=False","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"sourceIds":["GHSA-9wx4-h78v-vm56","PYSEC-2026-1873"],"published":"2024-05-20T20:15:00Z","modified":"2026-07-07T17:57:17.012984050Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6655"},{"type":"FIX","url":"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wx4-h78v-vm56"}],"versionKeys":["pypi:requests@2.31.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9x8q-7h8h-wcw9","slug":"ghsa-9x8q-7h8h-wcw9-af94166e","dossier":false,"summary":"aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect","aliases":["CVE-2026-54280","PYSEC-2026-2113"],"sourceIds":["GHSA-9x8q-7h8h-wcw9","PYSEC-2026-2113"],"published":"2026-06-15T20:10:44Z","modified":"2026-07-13T07:26:14.649569270Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9x8q-7h8h-wcw9"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c427-h43c-vf67","slug":"ghsa-c427-h43c-vf67-fa5b38aa","dossier":false,"summary":"AIOHTTP accepts duplicate Host headers","aliases":["CVE-2026-34525","PYSEC-2026-2103"],"sourceIds":["GHSA-c427-h43c-vf67","PYSEC-2026-2103"],"published":"2026-04-01T21:17:00.490Z","modified":"2026-07-13T07:26:42.158681139Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34525"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c67j-w6g6-q2cm","slug":"ghsa-c67j-w6g6-q2cm-a4c5c0cf","dossier":false,"summary":"LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs","aliases":["CVE-2025-68664","PYSEC-2026-373"],"sourceIds":["GHSA-c67j-w6g6-q2cm","PYSEC-2026-373"],"published":"2025-12-23T18:46:13Z","modified":"2026-07-02T13:00:05.018724776Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68664"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34455"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34458"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/d9ec4c5cc78960abd37da79b0250f5642e6f0ce6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.81"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.5"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c67j-w6g6-q2cm"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-c8j7-8cv4-2xmq","slug":"ghsa-c8j7-8cv4-2xmq-1ef013c3","dossier":false,"summary":"Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)","aliases":["CVE-2026-59922","PYSEC-2026-2210"],"sourceIds":["GHSA-c8j7-8cv4-2xmq","PYSEC-2026-2210"],"published":"2026-07-08T17:17:27.770Z","modified":"2026-07-20T21:46:39.999565306Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59922"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2210.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-c98p-7wgm-6p64","slug":"ghsa-c98p-7wgm-6p64-ef7ac7e3","dossier":false,"summary":"Tornado: Quadratic DoS via Repeated Header Coalescing","aliases":["CVE-2025-67725","PYSEC-2025-266"],"sourceIds":["GHSA-c98p-7wgm-6p64","PYSEC-2025-266"],"published":"2025-12-12T06:15:41.380Z","modified":"2026-07-20T19:15:27.567094965Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67725"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-266.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-cfh3-3jmp-rvhc","slug":"ghsa-cfh3-3jmp-rvhc-4e95572c","dossier":false,"summary":"Pillow affected by out-of-bounds write when loading PSD images","aliases":["BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249"],"sourceIds":["GHSA-cfh3-3jmp-rvhc","PYSEC-2026-2249"],"published":"2026-02-11T14:22:50Z","modified":"2026-07-13T07:26:49.514806069Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25990"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9427"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-25990"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14873"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14874"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:28385"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4128"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4942"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-cj93-chg6-vgv8","slug":"ghsa-cj93-chg6-vgv8-f22674c0","dossier":false,"summary":"pypdf: Possible large memory usage for large offsets for layout mode text","aliases":["CVE-2026-48155","PYSEC-2026-3016"],"sourceIds":["GHSA-cj93-chg6-vgv8","PYSEC-2026-3016"],"published":"2026-06-12T18:29:15Z","modified":"2026-07-13T16:43:35.317206583Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-cj93-chg6-vgv8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48155"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3790"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.12.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cj93-chg6-vgv8"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-cpwx-vrp4-4pq7","slug":"ghsa-cpwx-vrp4-4pq7-799bdc98","dossier":false,"summary":"Jinja2 vulnerable to sandbox breakout through attr filter selecting format method","aliases":["CVE-2025-27516","PYSEC-2026-1471"],"sourceIds":["GHSA-cpwx-vrp4-4pq7","PYSEC-2026-1471"],"published":"2025-03-05T20:40:14Z","modified":"2026-07-07T17:56:16.836141266Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-cpwx-vrp4-4pq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27516"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/90457bbf33b8662926ae65cdde4c4c32e756e403"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00045.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cpwx-vrp4-4pq7"}],"versionKeys":["pypi:jinja2@3.1.3","pypi:jinja2@3.1.5"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cx3h-4qpv-8hc9","slug":"ghsa-cx3h-4qpv-8hc9-3078b6fa","dossier":false,"summary":"Tornado has out-of-bounds memory access via C extension","aliases":["CVE-2026-49854","PYSEC-2026-3388"],"sourceIds":["GHSA-cx3h-4qpv-8hc9","PYSEC-2026-3388"],"published":"2026-06-12T18:30:19Z","modified":"2026-07-13T16:43:34.663472817Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.6"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx3h-4qpv-8hc9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49854"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-cx63-2mw6-8hw5","slug":"ghsa-cx63-2mw6-8hw5-1754ad59","dossier":false,"summary":"setuptools vulnerable to Command Injection via package URL","aliases":["BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918"],"sourceIds":["GHSA-cx63-2mw6-8hw5","PYSEC-2026-1918"],"published":"2024-07-15T03:30:57Z","modified":"2026-07-07T17:57:13.326243614Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6345"},{"type":"WEB","url":"https://github.com/pypa/setuptools/pull/4332"},{"type":"WEB","url":"https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html"},{"type":"PACKAGE","url":"https://pypi.org/project/setuptools"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx63-2mw6-8hw5"}],"versionKeys":["pypi:setuptools@69.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f2v5-7jq9-h8cg","slug":"ghsa-f2v5-7jq9-h8cg-c32868fb","dossier":false,"summary":"pypdf: Manipulated RunLengthDecode streams can exhaust RAM","aliases":["CVE-2026-28351","PYSEC-2026-3017"],"sourceIds":["GHSA-f2v5-7jq9-h8cg","PYSEC-2026-3017"],"published":"2026-02-28T02:46:10Z","modified":"2026-07-13T16:43:26.452272481Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-f2v5-7jq9-h8cg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28351"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3664"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/f309c6003746414dc7b5048c19e6d879ff2dc858"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.7.4"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f2v5-7jq9-h8cg"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f4xh-w4cj-qxq8","slug":"ghsa-f4xh-w4cj-qxq8-981d76df","dossier":false,"summary":"LangSmith SDK TracingMiddleware: Arbitrary server-side file read","aliases":["CVE-2026-59152"],"sourceIds":["GHSA-f4xh-w4cj-qxq8"],"published":"2026-06-19T22:10:34Z","modified":"2026-07-08T08:26:43.324048749Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-f4xh-w4cj-qxq8"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"}],"versionKeys":["pypi:langsmith@0.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f83h-ghpp-7wcc","slug":"ghsa-f83h-ghpp-7wcc-fde96eee","dossier":false,"summary":"Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc","aliases":["CVE-2025-70559","PYSEC-2026-1761"],"sourceIds":["GHSA-f83h-ghpp-7wcc","PYSEC-2026-1761"],"published":"2025-11-07T23:17:05Z","modified":"2026-07-08T07:38:27.593871221Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-f83h-ghpp-7wcc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70559"},{"type":"WEB","url":"https://github.com/pdfminer/pdfminer.six/commit/b808ee05dd7f0c8ea8ec34bdf394d40e63501086"},{"type":"PACKAGE","url":"https://github.com/pdfminer/pdfminer.six"},{"type":"PACKAGE","url":"https://pypi.org/project/pdfminer-six"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f83h-ghpp-7wcc"}],"versionKeys":["pypi:pdfminer-six@20240706"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f96h-pmfr-66vw","slug":"ghsa-f96h-pmfr-66vw-6763f20e","dossier":false,"summary":"Starlette Denial of service (DoS) via multipart/form-data","aliases":["CVE-2024-47874","PYSEC-2026-1943"],"sourceIds":["GHSA-f96h-pmfr-66vw","PYSEC-2026-1943"],"published":"2024-10-15T18:12:57Z","modified":"2026-07-07T17:57:05.823442628Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47874"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/fd038f3070c302bff17ef7d173dbb0b007617733"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f96h-pmfr-66vw"}],"versionKeys":["pypi:starlette@0.37.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fcw5-x6j4-ccmp","slug":"ghsa-fcw5-x6j4-ccmp-6b9a05f5","dossier":false,"summary":"Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP","aliases":["CVE-2026-44727","PYSEC-2026-366"],"sourceIds":["GHSA-fcw5-x6j4-ccmp","PYSEC-2026-366"],"published":"2026-06-18T15:04:07Z","modified":"2026-07-22T12:46:58.982015256Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44727"},{"type":"WEB","url":"https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:43038"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-44727"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491516"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fcw5-x6j4-ccmp"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-366.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-server"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44727.json"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-ffq3-xpv3-j92q","slug":"ghsa-ffq3-xpv3-j92q-22580948","dossier":false,"summary":"Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions","aliases":["CVE-2026-59928","PYSEC-2026-2216"],"sourceIds":["GHSA-ffq3-xpv3-j92q","PYSEC-2026-2216"],"published":"2026-07-08T17:17:28.600Z","modified":"2026-07-20T21:30:38.320453360Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59928"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2216.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fg6f-75jq-6523","slug":"ghsa-fg6f-75jq-6523-c927e5c8","dossier":false,"summary":"Authlib has 1-click Account Takeover vulnerability","aliases":["CVE-2025-68158","PYSEC-2026-1201"],"sourceIds":["GHSA-fg6f-75jq-6523","PYSEC-2026-1201"],"published":"2026-01-08T22:40:56Z","modified":"2026-07-07T17:56:30.898731290Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-fg6f-75jq-6523"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68158"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/2808378611dd6fb2532b189a9087877d8f0c0489"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/7974f45e4d7492ab5f527577677f2770ce423228"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fg6f-75jq-6523"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fg7f-2386-8897","slug":"ghsa-fg7f-2386-8897-44d94e2f","dossier":false,"summary":"Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex","aliases":["CVE-2026-12061"],"sourceIds":["GHSA-fg7f-2386-8897"],"published":"2026-07-31T16:51:09Z","modified":"2026-07-31T17:00:20.623483859Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-fg7f-2386-8897"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-fh55-r93g-j68g","slug":"ghsa-fh55-r93g-j68g-a231bc8e","dossier":false,"summary":"AIOHTTP Vulnerable to Cookie Parser Warning Storm","aliases":["CVE-2025-69230","PYSEC-2026-1105"],"sourceIds":["GHSA-fh55-r93g-j68g","PYSEC-2026-1105"],"published":"2026-01-05T23:13:46Z","modified":"2026-07-07T17:56:34.702331996Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-fh55-r93g-j68g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69230"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/64629a0834f94e46d9881f4e99c41a137e1f3326"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh55-r93g-j68g"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-fhv5-28vv-h8m8","slug":"ghsa-fhv5-28vv-h8m8-c54a3f91","dossier":false,"summary":"PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)","aliases":["CVE-2026-48524","PYSEC-2026-177"],"sourceIds":["GHSA-fhv5-28vv-h8m8","PYSEC-2026-177"],"published":"2026-05-28T16:16:29.403Z","modified":"2026-06-16T15:44:20.804330301Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48524"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-177.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-fj7v-r99m-22gq","slug":"ghsa-fj7v-r99m-22gq-e36cfebd","dossier":true,"summary":"Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images","aliases":["BIT-pillow-2026-59198","CVE-2026-59198","PYSEC-2026-3494"],"sourceIds":["GHSA-fj7v-r99m-22gq","PYSEC-2026-3494"],"published":"2026-07-20T23:09:36Z","modified":"2026-07-23T15:11:28.382441947Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-fj7v-r99m-22gq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59198"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9709"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/eada3cbd7fb9963ee90673fb7b5270124a0d5f4b"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fj7v-r99m-22gq"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-fjqc-hq36-qh5p","slug":"ghsa-fjqc-hq36-qh5p-fbc7458c","dossier":false,"summary":"LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading","aliases":["CVE-2026-48775","PYSEC-2026-2573"],"sourceIds":["GHSA-fjqc-hq36-qh5p","PYSEC-2026-2573"],"published":"2026-06-25T18:25:42Z","modified":"2026-07-13T16:42:57.455268050Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-fjqc-hq36-qh5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48775"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"PACKAGE","url":"https://pypi.org/project/langgraph-checkpoint"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fjqc-hq36-qh5p"}],"versionKeys":["pypi:langgraph-checkpoint@4.0.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fv5p-p927-qmxr","slug":"ghsa-fv5p-p927-qmxr-2692dd04","dossier":false,"summary":"LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass","aliases":["CVE-2026-41481","PYSEC-2026-77"],"sourceIds":["GHSA-fv5p-p927-qmxr","PYSEC-2026-77"],"published":"2026-04-16T22:53:32Z","modified":"2026-06-06T01:15:07.890699366Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-fv5p-p927-qmxr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41481"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-text-splitters/PYSEC-2026-77.yaml"}],"versionKeys":["pypi:langchain-text-splitters@1.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g3cq-j2xw-wf74","slug":"ghsa-g3cq-j2xw-wf74-4475e17b","dossier":false,"summary":"aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup","aliases":["CVE-2026-54278","PYSEC-2026-2111"],"sourceIds":["GHSA-g3cq-j2xw-wf74","PYSEC-2026-2111"],"published":"2026-06-15T20:09:51Z","modified":"2026-07-13T07:26:25.190325605Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g3cq-j2xw-wf74"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-g48c-2wqr-h844","slug":"ghsa-g48c-2wqr-h844-48f35247","dossier":false,"summary":"LangGraph checkpoint loading has unsafe msgpack deserialization","aliases":["CVE-2026-28277","PYSEC-2026-83"],"sourceIds":["GHSA-g48c-2wqr-h844","PYSEC-2026-83"],"published":"2026-03-05T20:16:15.677Z","modified":"2026-06-06T01:00:08.116125988Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-g48c-2wqr-h844"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28277"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langgraph/PYSEC-2026-83.yaml"}],"versionKeys":["pypi:langgraph@0.1.1","pypi:langgraph@0.3.21","pypi:langgraph@1.0.6"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-g7f3-828f-7h7m","slug":"ghsa-g7f3-828f-7h7m-12134915","dossier":false,"summary":"Authlib : JWE zip=DEF decompression bomb enables DoS","aliases":["CVE-2025-62706","PYSEC-2026-1202"],"sourceIds":["GHSA-g7f3-828f-7h7m","PYSEC-2026-1202"],"published":"2025-10-10T22:54:03Z","modified":"2026-07-07T17:57:19.270494442Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-g7f3-828f-7h7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62706"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/e0863d5129316b1790eee5f14cece32a03b8184d"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00032.html"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7f3-828f-7h7m"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g7vv-2v7x-gj9p","slug":"ghsa-g7vv-2v7x-gj9p-5ef970c3","dossier":false,"summary":"tqdm CLI arguments injection attack","aliases":["CVE-2024-34062","PYSEC-2026-1976"],"sourceIds":["GHSA-g7vv-2v7x-gj9p","PYSEC-2026-1976"],"published":"2024-05-03T19:33:28Z","modified":"2026-07-07T17:56:20.187915678Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"},{"type":"WEB","url":"https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316"},{"type":"PACKAGE","url":"https://github.com/tqdm/tqdm"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC"},{"type":"PACKAGE","url":"https://pypi.org/project/tqdm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7vv-2v7x-gj9p"}],"versionKeys":["pypi:tqdm@4.66.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g84x-mcqj-x9qq","slug":"ghsa-g84x-mcqj-x9qq-fc677e5d","dossier":false,"summary":"AIOHTTP vulnerable to DoS through chunked messages","aliases":["CVE-2025-69229","PYSEC-2026-1106"],"sourceIds":["GHSA-g84x-mcqj-x9qq","PYSEC-2026-1106"],"published":"2026-01-05T23:13:29Z","modified":"2026-07-07T17:56:31.463290158Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g84x-mcqj-x9qq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g84x-mcqj-x9qq"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-g867-7843-wf8q","slug":"ghsa-g867-7843-wf8q-293fb10e","dossier":false,"summary":"pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)","aliases":["CVE-2026-59935"],"sourceIds":["GHSA-g867-7843-wf8q"],"published":"2026-07-23T16:37:07Z","modified":"2026-07-29T21:14:53.453173973Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59935"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3892"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.14.2"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g97x-gvcm-x72h","slug":"ghsa-g97x-gvcm-x72h-ff087202","dossier":false,"summary":"Mistune: XSS via unescaped class option in Admonition directive","aliases":["CVE-2026-59926","PYSEC-2026-2214"],"sourceIds":["GHSA-g97x-gvcm-x72h","PYSEC-2026-2214"],"published":"2026-07-08T17:17:28.323Z","modified":"2026-07-20T21:46:40.083797845Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/security/advisories/GHSA-g97x-gvcm-x72h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59926"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2214.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g9xf-7f8q-9mcj","slug":"ghsa-g9xf-7f8q-9mcj-1d6967a3","dossier":false,"summary":"pypdf: Possible infinite loop when processing threads/articles in writer","aliases":["CVE-2026-54651","PYSEC-2026-3018"],"sourceIds":["GHSA-g9xf-7f8q-9mcj","PYSEC-2026-3018"],"published":"2026-07-09T21:09:53Z","modified":"2026-07-13T16:42:31.458290509Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9xf-7f8q-9mcj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54651"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3839"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.13.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g9xf-7f8q-9mcj"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gc5v-m9x4-r6x2","slug":"ghsa-gc5v-m9x4-r6x2-b9828ad8","dossier":true,"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"sourceIds":["GHSA-gc5v-m9x4-r6x2","PYSEC-2026-2275"],"published":"2026-03-25T16:56:28Z","modified":"2026-07-13T07:26:34.091663004Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645"},{"type":"FIX","url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"ADVISORY","url":"https://github.com/psf/requests/releases/tag/v2.33.0"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3","pypi:requests@2.32.4","pypi:requests@2.32.5"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-gf7q-q4j7-hp7c","slug":"ghsa-gf7q-q4j7-hp7c-0edc7a7a","dossier":false,"summary":"Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()","aliases":["CVE-2026-5422","PYSEC-2026-2532"],"sourceIds":["GHSA-gf7q-q4j7-hp7c","PYSEC-2026-2532"],"published":"2026-06-02T12:31:26Z","modified":"2026-07-13T16:43:48.932414937Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5422"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://huntr.com/bounties/24a36953-6490-466f-8cb2-a90d1ca56e0f"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-server"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gf7q-q4j7-hp7c"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gfwx-w7gr-fvh7","slug":"ghsa-gfwx-w7gr-fvh7-16d22532","dossier":false,"summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk","aliases":["CVE-2026-33230","PYSEC-2026-2235"],"sourceIds":["GHSA-gfwx-w7gr-fvh7","PYSEC-2026-2235"],"published":"2026-03-18T20:23:33Z","modified":"2026-07-13T07:26:40.492720011Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/nltk/nltk/security/advisories/GHSA-gfwx-w7gr-fvh7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33230"},{"type":"FIX","url":"https://github.com/nltk/nltk/commit/1c3f799607eeb088cab2491dcf806ae83c29ad8f"},{"type":"FIX","url":"https://github.com/nltk/nltk/commit/40d0bc1d484a3458d6a63ecb5ba4957ab16ba14e"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-gj48-438w-jh9v","slug":"ghsa-gj48-438w-jh9v-02216692","dossier":false,"summary":"Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes","aliases":[],"sourceIds":["GHSA-gj48-438w-jh9v"],"published":"2026-06-16T14:07:49Z","modified":"2026-06-18T18:29:26.517334064Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/mozilla/bleach/security/advisories/GHSA-gj48-438w-jh9v"},{"type":"PACKAGE","url":"https://github.com/mozilla/bleach"},{"type":"WEB","url":"https://github.com/mozilla/bleach/releases/tag/v6.4.0"}],"versionKeys":["pypi:bleach@6.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gm62-xv2j-4w53","slug":"ghsa-gm62-xv2j-4w53-5befa184","dossier":true,"summary":"urllib3 allows an unbounded number of links in the decompression chain","aliases":["CVE-2025-66418","PYSEC-2026-1998"],"sourceIds":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"published":"2025-12-05T18:15:19Z","modified":"2026-07-07T17:57:28.931610368Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm62-xv2j-4w53"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-gm8q-m8mv-jj5m","slug":"ghsa-gm8q-m8mv-jj5m-f488c667","dossier":false,"summary":"Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write","aliases":["CVE-2025-64712","PYSEC-2026-558"],"sourceIds":["GHSA-gm8q-m8mv-jj5m","PYSEC-2026-558"],"published":"2026-02-03T17:43:56Z","modified":"2026-07-13T16:15:34.752594062Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Unstructured-IO/unstructured/security/advisories/GHSA-gm8q-m8mv-jj5m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64712"},{"type":"WEB","url":"https://github.com/Unstructured-IO/unstructured/commit/b01d35b2373fd087d2e15162b9c021663c97155d"},{"type":"PACKAGE","url":"https://github.com/Unstructured-IO/unstructured"},{"type":"PACKAGE","url":"https://pypi.org/project/unstructured"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm8q-m8mv-jj5m"}],"versionKeys":["pypi:unstructured@0.16.12","pypi:unstructured@0.17.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-gmj6-6f8f-6699","slug":"ghsa-gmj6-6f8f-6699-e3e02f35","dossier":false,"summary":"Jinja has a sandbox breakout through malicious filenames","aliases":["CVE-2024-56201","PYSEC-2026-1472"],"sourceIds":["GHSA-gmj6-6f8f-6699","PYSEC-2026-1472"],"published":"2024-12-23T17:54:12Z","modified":"2026-07-07T17:56:55.074166933Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-gmj6-6f8f-6699"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56201"},{"type":"WEB","url":"https://github.com/pallets/jinja/issues/1792"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/767b23617628419ae3709ccfb02f9602ae9fe51f"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gmj6-6f8f-6699"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gr75-jv2w-4656","slug":"ghsa-gr75-jv2w-4656-a5b8c61e","dossier":false,"summary":"LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","aliases":["CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556"],"sourceIds":["GHSA-gr75-jv2w-4656","PYSEC-2026-2192"],"published":"2026-06-16T15:03:14Z","modified":"2026-07-13T16:43:09.845932020Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-gr75-jv2w-4656"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55443"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"}],"versionKeys":["pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langchain@1.2.6","pypi:langchain@1.3.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-gx64-gj6p-pc4c","slug":"ghsa-gx64-gj6p-pc4c-8fabc035","dossier":false,"summary":"JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab","aliases":[],"sourceIds":["GHSA-gx64-gj6p-pc4c"],"published":"2026-07-22T23:14:44Z","modified":"2026-07-22T23:30:29.672918877Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:jupyterlab@4.6.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-h35f-9h28-mq5c","slug":"ghsa-h35f-9h28-mq5c-f3238ba1","dossier":true,"summary":"setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+","aliases":["BIT-setuptools-2026-59890","CVE-2026-59890","PYSEC-2026-3447"],"sourceIds":["GHSA-h35f-9h28-mq5c","PYSEC-2026-3447"],"published":"2026-07-08T17:17:27.020Z","modified":"2026-07-23T09:29:39.408842775Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"ADVISORY","url":"https://github.com/pypa/setuptools/releases/tag/v83.0.0"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@72.2.0","pypi:setuptools@75.8.0","pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@82.0.1"],"packageCount":1,"repositoryCount":14},{"id":"GHSA-h4gh-qq45-vh27","slug":"ghsa-h4gh-qq45-vh27-43490265","dossier":false,"summary":"pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-h4gh-qq45-vh27"],"published":"2024-09-03T21:59:48Z","modified":"2026-02-04T03:06:49.280647Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20240903.txt"}],"versionKeys":["pypi:cryptography@42.0.8"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h5v5-8746-g7mm","slug":"ghsa-h5v5-8746-g7mm-7b4783af","dossier":false,"summary":"JupyterLab PluginManager lock-rule enforcement bypass","aliases":[],"sourceIds":["GHSA-h5v5-8746-g7mm"],"published":"2026-07-22T23:13:34Z","modified":"2026-07-22T23:15:29.669982172Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:jupyterlab@4.6.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-h75v-3vvj-5mfj","slug":"ghsa-h75v-3vvj-5mfj-d8fc6bb7","dossier":false,"summary":"Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter","aliases":["CVE-2024-34064","PYSEC-2026-1474"],"sourceIds":["GHSA-h75v-3vvj-5mfj","PYSEC-2026-1474"],"published":"2024-05-06T14:20:59Z","modified":"2026-07-07T17:57:30.872296178Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34064"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h75v-3vvj-5mfj"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h8wq-7xc4-p3qx","slug":"ghsa-h8wq-7xc4-p3qx-d8f6b020","dossier":false,"summary":"NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()","aliases":["CVE-2026-0846","PYSEC-2026-97"],"sourceIds":["GHSA-h8wq-7xc4-p3qx","PYSEC-2026-97"],"published":"2026-03-09T20:16:05.703Z","modified":"2026-06-10T17:02:23.828594589Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0846"},{"type":"WEB","url":"https://github.com/nltk/nltk/pull/3485"},{"type":"WEB","url":"https://github.com/nltk/nltk/commit/b2e1164bf89277f79b65406c829b99fb20ca1974"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-97.yaml"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/007b84f8-418e-4300-99d0-bf504c2f97eb"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h8wq-7xc4-p3qx"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-hcc4-c3v8-rx92","slug":"ghsa-hcc4-c3v8-rx92-ddf32b5c","dossier":false,"summary":"AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector","aliases":["CVE-2026-34513","PYSEC-2026-2095"],"sourceIds":["GHSA-hcc4-c3v8-rx92","PYSEC-2026-2095"],"published":"2026-04-01T21:16:59.267Z","modified":"2026-07-13T07:26:43.174352940Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hcc4-c3v8-rx92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34513"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hg6j-4rv6-33pg","slug":"ghsa-hg6j-4rv6-33pg-d0ac8db0","dossier":false,"summary":"AIOHTTP is vulnerable to cross-origin redirect with per-request cookies","aliases":["CVE-2026-47265","PYSEC-2026-2105"],"sourceIds":["GHSA-hg6j-4rv6-33pg","PYSEC-2026-2105"],"published":"2026-06-02T20:16:37.903Z","modified":"2026-07-13T07:26:51.969507320Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hg6j-4rv6-33pg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47265"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hm4w-wwcw-mr6r","slug":"ghsa-hm4w-wwcw-mr6r-b3d243f3","dossier":false,"summary":"pyasn1: Uncontrolled resource consumption when converting decoded REAL values","aliases":["CVE-2026-59886","PYSEC-2026-3457"],"sourceIds":["GHSA-hm4w-wwcw-mr6r","PYSEC-2026-3457"],"published":"2026-07-14T17:17:15.010Z","modified":"2026-07-23T09:29:38.810475714Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59886"},{"type":"FIX","url":"https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886"},{"type":"PACKAGE","url":"https://github.com/pyasn1/pyasn1"},{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"}],"versionKeys":["pypi:pyasn1@0.6.1","pypi:pyasn1@0.6.3"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-hpj7-wq8m-9hgp","slug":"ghsa-hpj7-wq8m-9hgp-fac25647","dossier":false,"summary":"aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges","aliases":["CVE-2026-54276","PYSEC-2026-2109"],"sourceIds":["GHSA-hpj7-wq8m-9hgp","PYSEC-2026-2109"],"published":"2026-06-15T20:09:06Z","modified":"2026-07-13T07:26:28.701980401Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hpj7-wq8m-9hgp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/38d16060037e1bfcd6d677abababa3c2a4bb58fa"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hqmh-ppp3-xvm7","slug":"ghsa-hqmh-ppp3-xvm7-c347f679","dossier":false,"summary":"pypdf: manipulated stream length values can exhaust RAM","aliases":["CVE-2026-31826","PYSEC-2026-3019"],"sourceIds":["GHSA-hqmh-ppp3-xvm7","PYSEC-2026-3019"],"published":"2026-03-11T00:14:02Z","modified":"2026-07-13T16:43:52.358788786Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-hqmh-ppp3-xvm7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31826"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3675"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/3c550b3196adeba1506a26e57c09c09fac75e9aa"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.8.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hqmh-ppp3-xvm7"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-hx9q-6w63-j58v","slug":"ghsa-hx9q-6w63-j58v-8d6e2248","dossier":false,"summary":"orjson does not limit recursion for deeply nested JSON documents","aliases":["CVE-2025-67221","PYSEC-2026-107"],"sourceIds":["GHSA-hx9q-6w63-j58v","PYSEC-2026-107"],"published":"2026-01-22T17:16:01.433Z","modified":"2026-06-10T17:02:27.794281728Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67221"},{"type":"WEB","url":"https://github.com/ijl/orjson/issues/620"},{"type":"WEB","url":"https://github.com/kpatsakis/CVE-2025-67221/issues/1"},{"type":"WEB","url":"https://github.com/ijl/orjson/commit/62bb185b70785ded49c79c26f8c9781f1e6fe370"},{"type":"PACKAGE","url":"https://github.com/ijl/orjson"},{"type":"EVIDENCE","url":"https://github.com/kpatsakis/orjson_vulnerability"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/orjson/PYSEC-2026-107.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hx9q-6w63-j58v"}],"versionKeys":["pypi:orjson@3.10.14","pypi:orjson@3.10.15","pypi:orjson@3.11.4","pypi:orjson@3.11.5"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-j543-4vmf-qm7v","slug":"ghsa-j543-4vmf-qm7v-f9f33226","dossier":false,"summary":"pypdf: Possible large memory usage for form XObjects during text extraction","aliases":["CVE-2026-49461","PYSEC-2026-3020"],"sourceIds":["GHSA-j543-4vmf-qm7v","PYSEC-2026-3020"],"published":"2026-06-16T13:47:08Z","modified":"2026-07-13T16:43:16.995390006Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-j543-4vmf-qm7v"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3805"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.12.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-j543-4vmf-qm7v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49461"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jfx9-29x2-rv3j","slug":"ghsa-jfx9-29x2-rv3j-dcd6f117","dossier":false,"summary":"pypdf can exhaust RAM via manipulated LZWDecode streams","aliases":["CVE-2025-62708","PYSEC-2026-1831"],"sourceIds":["GHSA-jfx9-29x2-rv3j","PYSEC-2026-1831"],"published":"2025-10-22T19:40:50Z","modified":"2026-07-07T17:56:05.697066629Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jfx9-29x2-rv3j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62708"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3502"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/e51d07807ffcdaf18077b9486dadb3dc05b368da"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.1.3"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jfx9-29x2-rv3j"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jg22-mg44-37j8","slug":"ghsa-jg22-mg44-37j8-b8064c77","dossier":false,"summary":"AIOHTTP is Vulnerable to Deserialization of Untrusted Data","aliases":["CVE-2026-34993","PYSEC-2026-2104"],"sourceIds":["GHSA-jg22-mg44-37j8","PYSEC-2026-2104"],"published":"2026-06-02T20:16:34.857Z","modified":"2026-07-13T07:26:37.684367184Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-jhmp-mqwm-3gq8","slug":"ghsa-jhmp-mqwm-3gq8-3b1c10a9","dossier":false,"summary":"Tornado: Quadratic DoS via Crafted Multipart Parameters","aliases":["CVE-2025-67726","PYSEC-2025-267"],"sourceIds":["GHSA-jhmp-mqwm-3gq8","PYSEC-2025-267"],"published":"2025-12-12T07:15:44.920Z","modified":"2026-07-20T19:15:27.583657512Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67726"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-267.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-jj3x-wxrx-4x23","slug":"ghsa-jj3x-wxrx-4x23-407bafac","dossier":false,"summary":"AIOHTTP vulnerable to DoS when bypassing asserts","aliases":["CVE-2025-69227","PYSEC-2026-1107"],"sourceIds":["GHSA-jj3x-wxrx-4x23","PYSEC-2026-1107"],"published":"2026-01-05T23:10:15Z","modified":"2026-07-07T17:57:17.782415842Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jj3x-wxrx-4x23"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69227"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj3x-wxrx-4x23"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-jj6c-8h6c-hppx","slug":"ghsa-jj6c-8h6c-hppx-b7b56d5e","dossier":false,"summary":"pypdf has long runtimes for wrong size values in cross-reference and object streams","aliases":["CVE-2026-41168","PYSEC-2026-3021"],"sourceIds":["GHSA-jj6c-8h6c-hppx","PYSEC-2026-3021"],"published":"2026-04-15T19:43:09Z","modified":"2026-07-13T16:43:07.020121646Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jj6c-8h6c-hppx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41168"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3733"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/62338e9d36419cf193ccec7331784f45df1d70b3"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj6c-8h6c-hppx"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jj8c-mmj3-mmgv","slug":"ghsa-jj8c-mmj3-mmgv-216e3367","dossier":false,"summary":"Authlib: Cross-site request forging when using cache","aliases":["CVE-2026-41425","PYSEC-2026-25"],"sourceIds":["GHSA-jj8c-mmj3-mmgv","PYSEC-2026-25"],"published":"2026-04-16T22:38:03Z","modified":"2026-06-05T14:45:30.092809707Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41425"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-25.yaml"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jjj6-mw9f-p565","slug":"ghsa-jjj6-mw9f-p565-ed2d1f46","dossier":true,"summary":"Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()","aliases":["BIT-pillow-2026-59200","CVE-2026-59200","PYSEC-2026-3495"],"sourceIds":["GHSA-jjj6-mw9f-p565","PYSEC-2026-3495"],"published":"2026-07-20T23:11:29Z","modified":"2026-07-23T15:11:28.034031834Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59200"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9718"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jjj6-mw9f-p565"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-jm6w-m3j8-898g","slug":"ghsa-jm6w-m3j8-898g-326a1845","dossier":false,"summary":"Unauthenticated remote shutdown in nltk.app.wordnet_app","aliases":["CVE-2026-33231","PYSEC-2026-2236"],"sourceIds":["GHSA-jm6w-m3j8-898g","PYSEC-2026-2236"],"published":"2026-03-19T12:42:20Z","modified":"2026-07-13T07:26:55.331693381Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/nltk/nltk/security/advisories/GHSA-jm6w-m3j8-898g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33231"},{"type":"FIX","url":"https://github.com/nltk/nltk/commit/bbaae83db86a0f49e00f5b0db44a7254c268de9b"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-33231"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33231.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2449836"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-jm82-fx9c-mx94","slug":"ghsa-jm82-fx9c-mx94-7c7a70d5","dossier":false,"summary":"pypdf: Missing stream length values ignore defined limits","aliases":["CVE-2026-57204"],"sourceIds":["GHSA-jm82-fx9c-mx94"],"published":"2026-06-18T14:28:49Z","modified":"2026-07-08T08:27:12.200342088Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jm82-fx9c-mx94"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3871"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.13.3"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jp82-jpqv-5vv3","slug":"ghsa-jp82-jpqv-5vv3-4d50530e","dossier":false,"summary":"Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname","aliases":["CVE-2026-54282","PYSEC-2026-248"],"sourceIds":["GHSA-jp82-jpqv-5vv3","PYSEC-2026-248"],"published":"2026-06-15T20:38:08Z","modified":"2026-07-15T22:30:44.498280076Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54282"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-248.yaml"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-jpw9-pfvf-9f58","slug":"ghsa-jpw9-pfvf-9f58-39682a8f","dossier":false,"summary":"MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal","aliases":["CVE-2026-52869","PYSEC-2026-3482"],"sourceIds":["GHSA-jpw9-pfvf-9f58","PYSEC-2026-3482"],"published":"2026-07-16T19:58:53Z","modified":"2026-07-23T15:11:29.023312800Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52869"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2690"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2719"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/1abcca2408a6b50e10ec601181f63f9978705c00"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/ce267b6fc515dc4efc1dc70b6975b16ff0feef0a"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jpw9-pfvf-9f58"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-jq35-7prp-9v3f","slug":"ghsa-jq35-7prp-9v3f-75660907","dossier":false,"summary":"PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys","aliases":["CVE-2026-48523","PYSEC-2026-176"],"sourceIds":["GHSA-jq35-7prp-9v3f","PYSEC-2026-176"],"published":"2026-05-28T16:16:29.280Z","modified":"2026-06-16T15:44:20.868973576Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48523"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-176.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-jr27-m4p2-rc6r","slug":"ghsa-jr27-m4p2-rc6r-4991bc00","dossier":false,"summary":"Denial of Service in pyasn1 via Unbounded Recursion","aliases":["CVE-2026-30922","PYSEC-2026-2263"],"sourceIds":["GHSA-jr27-m4p2-rc6r","PYSEC-2026-2263"],"published":"2026-03-17T16:17:33Z","modified":"2026-07-21T15:30:39.553074080Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30922"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/5a49bd1fe93b5b866a1210f6bf0a3924f21572c8"},{"type":"FIX","url":"https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:22970"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:22987"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:41928"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6309"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6568"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6720"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6912"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6926"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/05/msg00001.html"}],"versionKeys":["pypi:pyasn1@0.6.1"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-m2v9-299j-rv96","slug":"ghsa-m2v9-299j-rv96-e4973cc9","dossier":false,"summary":"pypdf: Possible infinite loop when processing outlines/bookmarks in writer","aliases":["CVE-2026-54531","PYSEC-2026-3022"],"sourceIds":["GHSA-m2v9-299j-rv96","PYSEC-2026-3022"],"published":"2026-06-16T14:05:57Z","modified":"2026-07-13T16:43:49.403109632Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-m2v9-299j-rv96"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3830"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.13.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m2v9-299j-rv96"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54531"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-m344-f55w-2m6j","slug":"ghsa-m344-f55w-2m6j-43fc4846","dossier":false,"summary":"Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding","aliases":["CVE-2026-28498","PYSEC-2026-2117"],"sourceIds":["GHSA-m344-f55w-2m6j","PYSEC-2026-2117"],"published":"2026-03-16T16:15:06Z","modified":"2026-07-13T07:26:18.508336668Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-m344-f55w-2m6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28498"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/b9bb2b25bf8b7e01512d847a95c1749646eaa72b"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"ADVISORY","url":"https://github.com/authlib/authlib/releases/tag/v1.6.9"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-28498"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28498.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6309"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6497"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6567"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6568"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6720"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6912"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2448182"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-m449-cwjh-6pw7","slug":"ghsa-m449-cwjh-6pw7-1a7936bf","dossier":false,"summary":"pypdf's LZWDecode streams be manipulated to exhaust RAM","aliases":["CVE-2025-66019","PYSEC-2026-1832"],"sourceIds":["GHSA-m449-cwjh-6pw7","PYSEC-2026-1832"],"published":"2025-11-24T22:42:07Z","modified":"2026-07-07T17:56:14.246224195Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jfx9-29x2-rv3j"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-m449-cwjh-6pw7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66019"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/96186725e5e6f237129a58a97cd19204a9ce40b2"},{"type":"WEB","url":"https://aydinnyunus.github.io/2025/12/20/cve-2025-66019-pypdf-lzw-dos"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.4.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m449-cwjh-6pw7"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-m5qp-6w8w-w647","slug":"ghsa-m5qp-6w8w-w647-495897bd","dossier":false,"summary":"AIOHTTP has a Multipart Header Size Bypass","aliases":["CVE-2026-34516","PYSEC-2026-2098"],"sourceIds":["GHSA-m5qp-6w8w-w647","PYSEC-2026-2098"],"published":"2026-04-01T21:16:59.723Z","modified":"2026-07-13T07:26:19.821892403Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m5qp-6w8w-w647"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34516"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/8a74257b3804c9aac0bf644af93070f68f6c5a6f"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-m6qw-4cw2-hm4m","slug":"ghsa-m6qw-4cw2-hm4m-3f6d3ee7","dossier":false,"summary":"aiohttp: CRLF injection in multipart headers","aliases":["CVE-2026-50269","PYSEC-2026-2106"],"sourceIds":["GHSA-m6qw-4cw2-hm4m","PYSEC-2026-2106"],"published":"2026-06-15T20:07:26Z","modified":"2026-07-13T07:26:17.983947245Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-m959-cc7f-wv43","slug":"ghsa-m959-cc7f-wv43-3b497c67","dossier":false,"summary":"cryptography has incomplete DNS name constraint enforcement on peer names","aliases":["CVE-2026-34073","PYSEC-2026-35"],"sourceIds":["GHSA-m959-cc7f-wv43","PYSEC-2026-35"],"published":"2026-03-27T19:56:21Z","modified":"2026-06-05T18:00:13.915417385Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34073"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-35.yaml"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mf9v-mfxr-j63j","slug":"ghsa-mf9v-mfxr-j63j-1a7db6d4","dossier":false,"summary":"urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API","aliases":["CVE-2026-44432","PYSEC-2026-142"],"sourceIds":["GHSA-mf9v-mfxr-j63j","PYSEC-2026-142"],"published":"2026-05-11T14:51:45Z","modified":"2026-06-08T20:00:12.284378628Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mf9w-mj56-hr94","slug":"ghsa-mf9w-mj56-hr94-a492e0f4","dossier":false,"summary":"python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback","aliases":["CVE-2026-28684","PYSEC-2026-2270"],"sourceIds":["GHSA-mf9w-mj56-hr94","PYSEC-2026-2270"],"published":"2026-04-20T17:16:33.087Z","modified":"2026-07-13T07:26:26.604845458Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/security/advisories/GHSA-mf9w-mj56-hr94"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28684"},{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311"},{"type":"WEB","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311.patch"},{"type":"PACKAGE","url":"https://github.com/theskumar/python-dotenv"},{"type":"ADVISORY","url":"https://github.com/theskumar/python-dotenv/releases/tag/v1.2.2"}],"versionKeys":["pypi:python-dotenv@1.0.1","pypi:python-dotenv@1.1.0","pypi:python-dotenv@1.1.1","pypi:python-dotenv@1.2.1"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-mgf9-4vpg-hj56","slug":"ghsa-mgf9-4vpg-hj56-00729355","dossier":false,"summary":"tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)","aliases":["CVE-2026-49855","PYSEC-2026-3389"],"sourceIds":["GHSA-mgf9-4vpg-hj56","PYSEC-2026-3389"],"published":"2026-06-15T20:19:28Z","modified":"2026-07-13T16:43:27.241564365Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mgf9-4vpg-hj56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49855"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-mj87-hwqh-73pj","slug":"ghsa-mj87-hwqh-73pj-92a4d569","dossier":false,"summary":"python-multipart affected by Denial of Service via large multipart preamble or epilogue data","aliases":["CVE-2026-40347","PYSEC-2026-3038"],"sourceIds":["GHSA-mj87-hwqh-73pj","PYSEC-2026-3038"],"published":"2026-04-15T19:45:44Z","modified":"2026-07-13T16:43:05.220439399Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-mj87-hwqh-73pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40347"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/releases/tag/0.0.26"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mj87-hwqh-73pj"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-mqcg-5x36-vfcg","slug":"ghsa-mqcg-5x36-vfcg-bd7ad531","dossier":false,"summary":"JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content","aliases":["BIT-jupyter-base-notebook-2026-42557","BIT-jupyter-notebook-2026-42557","BIT-jupyterlab-2026-42557","CVE-2026-42557","PYSEC-2026-2537","PYSEC-2026-2681"],"sourceIds":["GHSA-mqcg-5x36-vfcg","PYSEC-2026-2537","PYSEC-2026-2681"],"published":"2026-05-06T21:43:44Z","modified":"2026-07-13T16:43:04.081738235Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42557"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-files"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqcg-5x36-vfcg"},{"type":"PACKAGE","url":"https://pypi.org/project/notebook"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:notebook@7.0.7"],"packageCount":2,"repositoryCount":1},{"id":"GHSA-mqqc-3gqh-h2x8","slug":"ghsa-mqqc-3gqh-h2x8-6d702daf","dossier":false,"summary":"AIOHTTP has unicode match groups in regexes for ASCII protocol elements","aliases":["CVE-2025-69225","PYSEC-2026-1109"],"sourceIds":["GHSA-mqqc-3gqh-h2x8","PYSEC-2026-1109"],"published":"2026-01-05T23:09:30Z","modified":"2026-07-07T17:56:18.569417663Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69225"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqqc-3gqh-h2x8"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mwh4-6h8g-pg8w","slug":"ghsa-mwh4-6h8g-pg8w-881420d8","dossier":false,"summary":"AIOHTTP has HTTP response splitting via \\r in reason phrase","aliases":["CVE-2026-34519","PYSEC-2026-2101"],"sourceIds":["GHSA-mwh4-6h8g-pg8w","PYSEC-2026-2101"],"published":"2026-04-01T21:17:00.170Z","modified":"2026-07-13T07:26:39.246105773Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mwh4-6h8g-pg8w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34519"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53b35a2f8869c37a133e60bf1a82a1c01642ba2b"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-p423-j2cm-9vmq","slug":"ghsa-p423-j2cm-9vmq-1455bc4c","dossier":false,"summary":"Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs","aliases":["CVE-2026-39892","PYSEC-2026-36"],"sourceIds":["GHSA-p423-j2cm-9vmq","PYSEC-2026-36"],"published":"2026-04-08T19:23:08Z","modified":"2026-06-05T18:00:15.295914184Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39892"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml"}],"versionKeys":["pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-p4gq-832x-fm9v","slug":"ghsa-p4gq-832x-fm9v-9f1db448","dossier":false,"summary":"Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read","aliases":["CVE-2026-54293","PYSEC-2026-2078"],"sourceIds":["GHSA-p4gq-832x-fm9v","PYSEC-2026-2078"],"published":"2026-06-16T14:34:15Z","modified":"2026-07-21T12:46:29.659855804Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/nltk/nltk/security/advisories/GHSA-p4gq-832x-fm9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54293"},{"type":"FIX","url":"https://github.com/nltk/nltk/pull/3575"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:42644"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-54293"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491486"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-2078.yaml"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54293.json"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-p998-jp59-783m","slug":"ghsa-p998-jp59-783m-17c88f0d","dossier":false,"summary":"AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows","aliases":["CVE-2026-34515","PYSEC-2026-2097"],"sourceIds":["GHSA-p998-jp59-783m","PYSEC-2026-2097"],"published":"2026-04-01T21:16:59.570Z","modified":"2026-07-13T07:26:55.790859426Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34515"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-pc6w-59fv-rh23","slug":"ghsa-pc6w-59fv-rh23-cab9cb2f","dossier":false,"summary":"Langchain Community Vulnerable to XML External Entity (XXE) Attacks","aliases":["CVE-2025-6984","PYSEC-2026-1515"],"sourceIds":["GHSA-pc6w-59fv-rh23","PYSEC-2026-1515"],"published":"2025-09-04T12:30:42Z","modified":"2026-07-07T17:56:45.822570559Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6984"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain-community"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23"},{"type":"WEB","url":"https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pc6w-59fv-rh23"}],"versionKeys":["pypi:langchain-community@0.2.7","pypi:langchain-community@0.3.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pg7v-jwj7-p798","slug":"ghsa-pg7v-jwj7-p798-7c77aab5","dossier":false,"summary":"Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service","aliases":["BIT-pillow-2026-59203","CVE-2026-59203","PYSEC-2026-3452"],"sourceIds":["GHSA-pg7v-jwj7-p798","PYSEC-2026-3452"],"published":"2026-07-14T16:17:02.063Z","modified":"2026-07-22T02:59:40.501589790Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59203"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9708"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3452.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"}],"versionKeys":["pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-phj9-mv4w-65pm","slug":"ghsa-phj9-mv4w-65pm-481e7dc3","dossier":true,"summary":"Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`","aliases":["BIT-pillow-2026-55380","CVE-2026-55380","PYSEC-2026-2256"],"sourceIds":["GHSA-phj9-mv4w-65pm","PYSEC-2026-2256"],"published":"2026-07-06T19:17:08.703Z","modified":"2026-07-22T02:59:41.562749940Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55380"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-pjwx-r37v-7724","slug":"ghsa-pjwx-r37v-7724-2297a72a","dossier":false,"summary":"LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists","aliases":["CVE-2026-44843","PYSEC-2026-2564"],"sourceIds":["GHSA-pjwx-r37v-7724","PYSEC-2026-2564"],"published":"2026-05-08T23:07:32Z","modified":"2026-07-13T16:42:39.210995356Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-pjwx-r37v-7724"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44843"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pjwx-r37v-7724"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pp6c-gr5w-3c5g","slug":"ghsa-pp6c-gr5w-3c5g-de40aafe","dossier":false,"summary":"python-multipart has Denial of Service via unbounded multipart part headers","aliases":["CVE-2026-42561","PYSEC-2026-3039"],"sourceIds":["GHSA-pp6c-gr5w-3c5g","PYSEC-2026-3039"],"published":"2026-05-06T21:56:14Z","modified":"2026-07-13T16:42:24.725022295Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-pp6c-gr5w-3c5g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42561"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pp6c-gr5w-3c5g"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-pppj-hq3g-57pj","slug":"ghsa-pppj-hq3g-57pj-cec62aea","dossier":false,"summary":"JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)","aliases":[],"sourceIds":["GHSA-pppj-hq3g-57pj"],"published":"2026-07-22T23:16:18Z","modified":"2026-07-22T23:30:29.674484297Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:L"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:jupyterlab@4.6.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pq5p-34cr-23v9","slug":"ghsa-pq5p-34cr-23v9-127ea2b8","dossier":false,"summary":"Authlib is vulnerable to Denial of Service via Oversized JOSE Segments","aliases":["CVE-2025-61920","PYSEC-2026-1203"],"sourceIds":["GHSA-pq5p-34cr-23v9","PYSEC-2026-1203"],"published":"2025-10-10T20:26:43Z","modified":"2026-07-07T17:56:17.886883361Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-pq5p-34cr-23v9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61920"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/867e3f87b072347a1ae9cf6983cc8bbf88447e5e"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00032.html"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq5p-34cr-23v9"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-pq67-6m6q-mj2v","slug":"ghsa-pq67-6m6q-mj2v-3522d1d4","dossier":false,"summary":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","aliases":["CVE-2025-50181","PYSEC-2026-1999"],"sourceIds":["GHSA-pq67-6m6q-mj2v","PYSEC-2026-1999"],"published":"2025-06-18T17:50:00Z","modified":"2026-07-07T17:56:41.872294653Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-pr2v-jx2c-wg9f","slug":"ghsa-pr2v-jx2c-wg9f-1ca6d67c","dossier":false,"summary":"Tornado vulnerable to Header Injection and XSS via reason argument","aliases":["CVE-2025-67724","PYSEC-2025-265"],"sourceIds":["GHSA-pr2v-jx2c-wg9f","PYSEC-2025-265"],"published":"2025-12-12T06:15:41.213Z","modified":"2026-07-20T19:00:24.953994999Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pr2v-jx2c-wg9f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67724"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/9c163aebeaad9e6e7d28bac1f33580eb00b0e421"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-265.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-pw6j-qg29-8w7f","slug":"ghsa-pw6j-qg29-8w7f-fb4d7ed6","dossier":false,"summary":"Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse","aliases":[],"sourceIds":["GHSA-pw6j-qg29-8w7f"],"published":"2026-06-15T20:37:24Z","modified":"2026-06-16T22:59:25.768721886Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-pwv6-vv43-88gr","slug":"ghsa-pwv6-vv43-88gr-c5f811d0","dossier":true,"summary":"Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)","aliases":["BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252"],"sourceIds":["GHSA-pwv6-vv43-88gr","PYSEC-2026-2252"],"published":"2026-05-04T20:20:31Z","modified":"2026-07-13T07:26:52.198871129Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42311"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9520"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-q25c-c977-4cmh","slug":"ghsa-q25c-c977-4cmh-8e74e348","dossier":false,"summary":"Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever","aliases":["CVE-2024-3095","PYSEC-2026-1516"],"sourceIds":["GHSA-q25c-c977-4cmh","PYSEC-2026-1516"],"published":"2024-06-06T21:30:36Z","modified":"2026-07-07T17:57:27.127785500Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3095"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/24451"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-community%3D%3D0.2.9"},{"type":"WEB","url":"https://huntr.com/bounties/e62d4895-2901-405b-9559-38276b6a5273"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q25c-c977-4cmh"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-q2x7-8rv6-6q7h","slug":"ghsa-q2x7-8rv6-6q7h-1113a288","dossier":false,"summary":"Jinja has a sandbox breakout through indirect reference to format method","aliases":["CVE-2024-56326","PYSEC-2026-1475"],"sourceIds":["GHSA-q2x7-8rv6-6q7h","PYSEC-2026-1475"],"published":"2024-12-23T17:56:08Z","modified":"2026-07-07T17:56:44.376174317Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56326"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2x7-8rv6-6q7h"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qccp-gfcp-xxvc","slug":"ghsa-qccp-gfcp-xxvc-0d988969","dossier":true,"summary":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects","aliases":["CVE-2026-44431","PYSEC-2026-141"],"sourceIds":["GHSA-qccp-gfcp-xxvc","PYSEC-2026-141"],"published":"2026-05-11T14:51:20Z","modified":"2026-05-20T09:19:20.983812Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-qcq2-496w-v96p","slug":"ghsa-qcq2-496w-v96p-f873dd58","dossier":false,"summary":"Mistune: Potential DoS via quadratic-time parsing in parse_link_text","aliases":["CVE-2026-49851","PYSEC-2026-2652"],"sourceIds":["GHSA-qcq2-496w-v96p","PYSEC-2026-2652"],"published":"2026-07-09T23:52:27Z","modified":"2026-07-23T05:15:25.338180329Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49851"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-49851"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492304"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49851.json"},{"type":"PACKAGE","url":"https://pypi.org/project/mistune"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qcq2-496w-v96p"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qfrw-5rxm-mhh2","slug":"ghsa-qfrw-5rxm-mhh2-586619d0","dossier":false,"summary":"Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution","aliases":["CVE-2026-59929","PYSEC-2026-2217"],"sourceIds":["GHSA-qfrw-5rxm-mhh2","PYSEC-2026-2217"],"published":"2026-07-08T17:17:28.737Z","modified":"2026-07-20T21:46:41.246867209Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-qfrw-5rxm-mhh2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59929"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2217.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qh6h-p6c9-ff54","slug":"ghsa-qh6h-p6c9-ff54-caf42ff5","dossier":false,"summary":"LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions","aliases":["CVE-2026-34070","PYSEC-2026-2193"],"sourceIds":["GHSA-qh6h-p6c9-ff54","PYSEC-2026-2193"],"published":"2026-03-27T19:45:00Z","modified":"2026-07-13T07:26:33.913236655Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-qh6h-p6c9-ff54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34070"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/27add913474e01e33bededf4096151130ba0d47c"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core==1.2.22"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34070"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34070.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24766"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453287"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-qh7q-6qm3-653w","slug":"ghsa-qh7q-6qm3-653w-ce7f1a0b","dossier":false,"summary":"Jupyter Server has an open redirection vulnerability in `next` query parameter","aliases":["CVE-2025-61669","PYSEC-2026-67"],"sourceIds":["GHSA-qh7q-6qm3-653w","PYSEC-2026-67"],"published":"2026-05-05T16:16:10.133Z","modified":"2026-06-05T18:00:15.359519984Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-qh7q-6qm3-653w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61669"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-67.yaml"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qjxf-f2mg-c6mc","slug":"ghsa-qjxf-f2mg-c6mc-58d52008","dossier":false,"summary":"Tornado is vulnerable to DoS due to too many multipart parts","aliases":["CVE-2026-31958","PYSEC-2026-140"],"sourceIds":["GHSA-qjxf-f2mg-c6mc","PYSEC-2026-140"],"published":"2026-03-11T20:16:16.617Z","modified":"2026-06-08T20:00:14.385003861Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31958"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-qmgc-5h2g-mvrw","slug":"ghsa-qmgc-5h2g-mvrw-199eacc8","dossier":false,"summary":"filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock","aliases":["CVE-2026-22701","PYSEC-2026-1374"],"sourceIds":["GHSA-qmgc-5h2g-mvrw","PYSEC-2026-1374"],"published":"2026-01-13T18:44:55Z","modified":"2026-07-07T17:56:19.485233787Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22701"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qmgc-5h2g-mvrw"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-qpxp-75px-xjcp","slug":"ghsa-qpxp-75px-xjcp-68d210e7","dossier":false,"summary":"pypdf has inefficient decoding of array-based streams","aliases":["CVE-2026-33123","PYSEC-2026-3023"],"sourceIds":["GHSA-qpxp-75px-xjcp","PYSEC-2026-3023"],"published":"2026-03-18T16:17:31Z","modified":"2026-07-13T16:43:25.259140299Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-qpxp-75px-xjcp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33123"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3686"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.9.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qpxp-75px-xjcp"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qvv7-cg9c-w4x3","slug":"ghsa-qvv7-cg9c-w4x3-da2ef5e7","dossier":false,"summary":"Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode","aliases":["CVE-2026-12075"],"sourceIds":["GHSA-qvv7-cg9c-w4x3"],"published":"2026-07-31T16:51:29Z","modified":"2026-07-31T17:00:21.024112203Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-qvv7-cg9c-w4x3"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-r4rv-85jg-w4mf","slug":"ghsa-r4rv-85jg-w4mf-c97959dd","dossier":false,"summary":"Mistune: Arbitrary File Read via Include directive path traversal","aliases":["CVE-2026-59924","PYSEC-2026-2212"],"sourceIds":["GHSA-r4rv-85jg-w4mf","PYSEC-2026-2212"],"published":"2026-07-08T17:17:28.050Z","modified":"2026-07-20T21:46:41.298212805Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59924"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2212.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-r6ph-v2qm-q3c2","slug":"ghsa-r6ph-v2qm-q3c2-c75907df","dossier":false,"summary":"cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves","aliases":["CVE-2026-26007","PYSEC-2026-2141"],"sourceIds":["GHSA-r6ph-v2qm-q3c2","PYSEC-2026-2141"],"published":"2026-02-10T21:27:06Z","modified":"2026-07-13T07:26:47.289183808Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26007"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pyca/cryptography/releases/tag/46.0.5"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-26007"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:12176"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13553"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13672"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19355"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21517"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22330"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22993"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2694"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-r73j-pqj5-w3x7","slug":"ghsa-r73j-pqj5-w3x7-8d4d543f","dossier":false,"summary":"Pillow has a PDF Parsing Trailer Infinite Loop (DoS)","aliases":["BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874"],"sourceIds":["GHSA-r73j-pqj5-w3x7","PYSEC-2026-2874"],"published":"2026-05-04T20:19:30Z","modified":"2026-07-13T16:42:37.358429541Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-r73j-pqj5-w3x7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42310"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9519"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3bf614e4b8615d0ce1d5039efaf6db447fe7c468"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r73j-pqj5-w3x7"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-r7w7-9xr2-qq2r","slug":"ghsa-r7w7-9xr2-qq2r-7a3a0a91","dossier":false,"summary":"langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding","aliases":["CVE-2026-41488","PYSEC-2026-76"],"sourceIds":["GHSA-r7w7-9xr2-qq2r","PYSEC-2026-76"],"published":"2026-04-16T23:00:12Z","modified":"2026-06-06T01:15:07.912179267Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-r7w7-9xr2-qq2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41488"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-openai/PYSEC-2026-76.yaml"}],"versionKeys":["pypi:langchain-openai@0.2.8","pypi:langchain-openai@1.1.7","pypi:langchain-openai@1.1.9"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-r95x-qfjj-fjj2","slug":"ghsa-r95x-qfjj-fjj2-df4fdb80","dossier":false,"summary":"Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect","aliases":["CVE-2026-44681","PYSEC-2026-188"],"sourceIds":["GHSA-r95x-qfjj-fjj2","PYSEC-2026-188"],"published":"2026-05-13T01:36:03Z","modified":"2026-06-09T00:00:25.468861825Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44681"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/authlib/authlib/releases/tag/v1.6.12"},{"type":"WEB","url":"https://github.com/authlib/authlib/releases/tag/v1.7.1"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-188.yaml"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-rch3-82jr-f9w9","slug":"ghsa-rch3-82jr-f9w9-c220441f","dossier":false,"summary":"Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS","aliases":["BIT-jupyter-base-notebook-2026-40171","BIT-jupyter-notebook-2026-40171","BIT-jupyterlab-2026-40171","CVE-2026-40171","PYSEC-2026-2538","PYSEC-2026-2682"],"sourceIds":["GHSA-rch3-82jr-f9w9","PYSEC-2026-2538","PYSEC-2026-2682"],"published":"2026-04-30T17:25:47Z","modified":"2026-07-13T16:42:47.886298772Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40171"},{"type":"PACKAGE","url":"https://github.com/jupyter/notebook"},{"type":"WEB","url":"https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rch3-82jr-f9w9"},{"type":"PACKAGE","url":"https://pypi.org/project/notebook"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:notebook@7.0.7"],"packageCount":2,"repositoryCount":1},{"id":"GHSA-rf74-v2fm-23pw","slug":"ghsa-rf74-v2fm-23pw-dfe729f1","dossier":false,"summary":"Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS","aliases":[],"sourceIds":["GHSA-rf74-v2fm-23pw"],"published":"2026-03-18T20:17:43Z","modified":"2026-03-25T23:29:13.324989Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-rr7j-v2q5-chgv","slug":"ghsa-rr7j-v2q5-chgv-a773969e","dossier":false,"summary":"LangSmith SDK: Streaming token events bypass output redaction","aliases":["CVE-2026-41182","PYSEC-2026-2583"],"sourceIds":["GHSA-rr7j-v2q5-chgv","PYSEC-2026-2583"],"published":"2026-04-16T01:20:37Z","modified":"2026-07-13T16:43:37.566182133Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-rr7j-v2q5-chgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41182"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rr7j-v2q5-chgv"}],"versionKeys":["pypi:langsmith@0.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-v42x-x7jp-845h","slug":"ghsa-v42x-x7jp-845h-25baa2bb","dossier":false,"summary":"jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used","aliases":["CVE-2026-6657","PYSEC-2026-3472"],"sourceIds":["GHSA-v42x-x7jp-845h","PYSEC-2026-3472"],"published":"2026-06-03T18:33:10Z","modified":"2026-07-23T15:11:47.231076569Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6657"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://huntr.com/bounties/18f642db-3569-43b3-b58d-ff97be4b09d7"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-server"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v42x-x7jp-845h"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-v87v-83h2-53w7","slug":"ghsa-v87v-83h2-53w7-36afb5ef","dossier":false,"summary":"Mistune Heading ID Attribute has Injection XSS","aliases":["CVE-2026-44897","PYSEC-2026-2207"],"sourceIds":["GHSA-v87v-83h2-53w7","PYSEC-2026-2207"],"published":"2026-05-09T00:13:12Z","modified":"2026-07-13T07:26:47.040339656Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-v87v-83h2-53w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44897"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-v9pg-7xvm-68hf","slug":"ghsa-v9pg-7xvm-68hf-bd9c7524","dossier":false,"summary":"python-multipart: Negative Content-Length in parse_form buffers the entire body in memory","aliases":["CVE-2026-53540","PYSEC-2026-3040"],"sourceIds":["GHSA-v9pg-7xvm-68hf","PYSEC-2026-3040"],"published":"2026-06-15T20:23:45Z","modified":"2026-07-13T16:43:20.711288699Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-v9pg-7xvm-68hf"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v9pg-7xvm-68hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53540"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-vffw-93wf-4j4q","slug":"ghsa-vffw-93wf-4j4q-3828c302","dossier":false,"summary":"python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters","aliases":["CVE-2026-53537","PYSEC-2026-3041"],"sourceIds":["GHSA-vffw-93wf-4j4q","PYSEC-2026-3041"],"published":"2026-06-15T20:20:51Z","modified":"2026-07-15T22:30:45.845963114Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-vffw-93wf-4j4q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53537"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vffw-93wf-4j4q"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/blob/main/vulns/python-multipart/PYSEC-2026-3041.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-vfmq-68hx-4jfw","slug":"ghsa-vfmq-68hx-4jfw-7287cb04","dossier":false,"summary":"lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files","aliases":["CVE-2026-41066","PYSEC-2026-87"],"sourceIds":["GHSA-vfmq-68hx-4jfw","PYSEC-2026-87"],"published":"2026-04-21T20:38:44Z","modified":"2026-06-06T01:15:07.932706387Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41066"},{"type":"REPORT","url":"https://bugs.launchpad.net/lxml/+bug/2146291"},{"type":"PACKAGE","url":"https://github.com/lxml/lxml"},{"type":"WEB","url":"https://github.com/lxml/lxml/releases/tag/lxml-6.1.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/lxml/PYSEC-2026-87.yaml"}],"versionKeys":["pypi:lxml@5.3.0","pypi:lxml@5.4.0","pypi:lxml@6.0.2"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-vj7q-gjh5-988w","slug":"ghsa-vj7q-gjh5-988w-54882ae8","dossier":false,"summary":"MCP Python SDK: WebSocket server transport does not support Host/Origin validation","aliases":["CVE-2026-59950","PYSEC-2026-3483"],"sourceIds":["GHSA-vj7q-gjh5-988w","PYSEC-2026-3483"],"published":"2026-07-16T20:14:34Z","modified":"2026-07-23T15:11:47.407353087Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-vj7q-gjh5-988w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59950"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2992"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.28.1"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vj7q-gjh5-988w"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-vjc4-5qp5-m44j","slug":"ghsa-vjc4-5qp5-m44j-08063b19","dossier":false,"summary":"Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service","aliases":["BIT-pillow-2026-59204","CVE-2026-59204","PYSEC-2026-3496"],"sourceIds":["GHSA-vjc4-5qp5-m44j","PYSEC-2026-3496"],"published":"2026-07-20T23:18:32Z","modified":"2026-07-23T15:11:20.720915099Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59204"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9704"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vjc4-5qp5-m44j"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-vmhf-c436-hxj4","slug":"ghsa-vmhf-c436-hxj4-2356488f","dossier":false,"summary":"JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol","aliases":[],"sourceIds":["GHSA-vmhf-c436-hxj4"],"published":"2026-06-19T15:11:17Z","modified":"2026-06-22T18:29:21.418806301Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.9"}],"versionKeys":["pypi:jupyterlab@4.4.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vqfr-h8mv-ghfj","slug":"ghsa-vqfr-h8mv-ghfj-49515033","dossier":false,"summary":"h11 accepts some malformed Chunked-Encoding bodies","aliases":["CVE-2025-43859","PYSEC-2026-348"],"sourceIds":["GHSA-vqfr-h8mv-ghfj","PYSEC-2026-348"],"published":"2025-04-24T16:07:56Z","modified":"2026-07-01T20:22:54.082067Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43859"},{"type":"WEB","url":"https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h11"},{"type":"PACKAGE","url":"https://pypi.org/project/h11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqfr-h8mv-ghfj"}],"versionKeys":["pypi:h11@0.14.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-vr63-x8vc-m265","slug":"ghsa-vr63-x8vc-m265-7041f46b","dossier":false,"summary":"pypdf possibly loops infinitely when reading DCT inline images without EOF marker","aliases":["CVE-2025-62707","PYSEC-2026-1833"],"sourceIds":["GHSA-vr63-x8vc-m265","PYSEC-2026-1833"],"published":"2025-10-22T19:40:47Z","modified":"2026-07-07T17:56:08.279731969Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-vr63-x8vc-m265"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62707"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3501"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/f2864d6dd9bac7cecd3f4f54308b25ebbfa178f8"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.1.3"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vr63-x8vc-m265"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vvfj-2jqx-52jm","slug":"ghsa-vvfj-2jqx-52jm-5fd8a3bd","dossier":false,"summary":"JupyterLab LaTeX typesetter links did not enforce `noopener` attribute","aliases":["BIT-jupyterlab-2025-59842","CVE-2025-59842","PYSEC-2026-1482"],"sourceIds":["GHSA-vvfj-2jqx-52jm","PYSEC-2026-1482"],"published":"2025-09-26T14:26:40Z","modified":"2026-07-07T17:57:38.072715082Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vvfj-2jqx-52jm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59842"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/88ef373039a8cc09f27d3814382a512d9033675c"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vvfj-2jqx-52jm"}],"versionKeys":["pypi:jupyterlab@4.4.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-w2fm-2cpv-w7v5","slug":"ghsa-w2fm-2cpv-w7v5-c2f7701a","dossier":false,"summary":"aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage","aliases":["CVE-2026-22815","PYSEC-2026-2094"],"sourceIds":["GHSA-w2fm-2cpv-w7v5","PYSEC-2026-2094"],"published":"2026-04-01T19:45:17Z","modified":"2026-07-13T07:26:28.950069528Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-w2fm-2cpv-w7v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22815"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-w39p-vh2g-g8g5","slug":"ghsa-w39p-vh2g-g8g5-47880dfe","dossier":false,"summary":"LangGraph SDK has unsafe URL path construction","aliases":["CVE-2026-48776","PYSEC-2026-2194","PYSEC-2026-2575"],"sourceIds":["GHSA-w39p-vh2g-g8g5","PYSEC-2026-2194","PYSEC-2026-2575"],"published":"2026-06-17T10:55:15.113Z","modified":"2026-07-21T15:15:50.659527533Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-w39p-vh2g-g8g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48776"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w39p-vh2g-g8g5"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/releases/tag/sdk%3D%3D0.3.15"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langgraph-sdk/PYSEC-2026-2575.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langgraph/PYSEC-2026-2194.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/langgraph-sdk"}],"versionKeys":["pypi:langgraph-sdk@0.3.3","pypi:langgraph@0.1.1"],"packageCount":2,"repositoryCount":2},{"id":"GHSA-w7vc-732c-9m39","slug":"ghsa-w7vc-732c-9m39-90a52664","dossier":false,"summary":"PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS","aliases":["CVE-2026-48525","PYSEC-2026-178"],"sourceIds":["GHSA-w7vc-732c-9m39","PYSEC-2026-178"],"published":"2026-05-28T16:16:29.533Z","modified":"2026-06-16T15:44:21.139278330Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48525"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-178.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-w853-jp5j-5j7f","slug":"ghsa-w853-jp5j-5j7f-2786386f","dossier":false,"summary":"filelock has a TOCTOU race condition which allows symlink attacks during lock file creation","aliases":["CVE-2025-68146","PYSEC-2026-1375"],"sourceIds":["GHSA-w853-jp5j-5j7f","PYSEC-2026-1375"],"published":"2025-12-16T20:52:55Z","modified":"2026-07-07T17:56:10.949145470Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/releases/tag/3.20.1"},{"type":"WEB","url":"https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants"},{"type":"WEB","url":"https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w853-jp5j-5j7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68146"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-w8p2-r796-3vmq","slug":"ghsa-w8p2-r796-3vmq-0e5f6b4f","dossier":false,"summary":"Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type","aliases":["CVE-2026-41479","PYSEC-2026-2119"],"sourceIds":["GHSA-w8p2-r796-3vmq","PYSEC-2026-2119"],"published":"2026-06-08T17:52:04Z","modified":"2026-07-18T17:30:29.215396840Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-w8p2-r796-3vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41479"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-2119.yaml"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-wf5f-4jwr-ppcp","slug":"ghsa-wf5f-4jwr-ppcp-6aafc086","dossier":false,"summary":"Arbitrary Code Execution in pdfminer.six via Crafted PDF Input","aliases":["CVE-2025-64512","PYSEC-2026-1762"],"sourceIds":["GHSA-wf5f-4jwr-ppcp","PYSEC-2026-1762"],"published":"2025-11-07T20:52:24Z","modified":"2026-07-07T17:56:32.052583560Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-wf5f-4jwr-ppcp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64512"},{"type":"WEB","url":"https://github.com/pdfminer/pdfminer.six/commit/b808ee05dd7f0c8ea8ec34bdf394d40e63501086"},{"type":"PACKAGE","url":"https://github.com/pdfminer/pdfminer.six"},{"type":"WEB","url":"https://github.com/pdfminer/pdfminer.six/releases/tag/20251107"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/11/msg00017.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00005.html"},{"type":"PACKAGE","url":"https://pypi.org/project/pdfminer-six"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wf5f-4jwr-ppcp"}],"versionKeys":["pypi:pdfminer-six@20240706"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-wgvp-vg3v-2xq3","slug":"ghsa-wgvp-vg3v-2xq3-bebe6cfc","dossier":false,"summary":"pypdf has possible long runtimes/large memory usage for large /ToUnicode streams","aliases":["CVE-2026-27025","PYSEC-2026-3024"],"sourceIds":["GHSA-wgvp-vg3v-2xq3","PYSEC-2026-3024"],"published":"2026-02-18T22:41:13Z","modified":"2026-07-13T16:43:04.734501329Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-wgvp-vg3v-2xq3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27025"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3646"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/77d7b8d7cfbe8dd179858dfa42666f73fc6e57a2"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.7.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wgvp-vg3v-2xq3"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-whj4-6x5x-4v2j","slug":"ghsa-whj4-6x5x-4v2j-eb5fc6a1","dossier":false,"summary":"FITS GZIP decompression bomb in Pillow","aliases":["BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250"],"sourceIds":["GHSA-whj4-6x5x-4v2j","PYSEC-2026-2250"],"published":"2026-04-13T19:22:35Z","modified":"2026-07-13T07:26:24.246094941Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40192"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9521"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40192"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16008"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16009"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17609"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17611"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19375"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21017"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22465"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22629"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22840"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-whvh-wf3x-g77j","slug":"ghsa-whvh-wf3x-g77j-38e6ead5","dossier":false,"summary":"JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)","aliases":[],"sourceIds":["GHSA-whvh-wf3x-g77j"],"published":"2026-07-22T23:12:22Z","modified":"2026-07-22T23:15:29.688424393Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:jupyterlab@4.6.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-wjqc-6w8f-h24c","slug":"ghsa-wjqc-6w8f-h24c-6b0b96ea","dossier":false,"summary":"pypdf: Manipulated XMP metadata streams can exhaust RAM","aliases":["CVE-2026-48735","PYSEC-2026-3025"],"sourceIds":["GHSA-wjqc-6w8f-h24c","PYSEC-2026-3025"],"published":"2026-06-16T13:45:58Z","modified":"2026-07-13T16:42:29.123625634Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-wjqc-6w8f-h24c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48735"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3796"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.12.1"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wjqc-6w8f-h24c"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-wjx4-4jcj-g98j","slug":"ghsa-wjx4-4jcj-g98j-e937161b","dossier":false,"summary":"Pillow has an integer overflow when processing fonts","aliases":["BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165"],"sourceIds":["GHSA-wjx4-4jcj-g98j","PYSEC-2026-165"],"published":"2026-05-04T20:18:45Z","modified":"2026-06-08T23:45:16.414580348Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42308"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-wp53-j4wj-2cfg","slug":"ghsa-wp53-j4wj-2cfg-22cec3c5","dossier":false,"summary":"Python-Multipart has Arbitrary File Write via Non-Default Configuration","aliases":["CVE-2026-24486","PYSEC-2026-1852"],"sourceIds":["GHSA-wp53-j4wj-2cfg","PYSEC-2026-1852"],"published":"2026-01-26T23:28:05Z","modified":"2026-07-07T17:57:28.813401667Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-wp53-j4wj-2cfg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24486"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/commit/9433f4bbc9652bdde82bbe380984e32f8cfc89c4"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/releases/tag/0.0.22"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wp53-j4wj-2cfg"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-wqp7-x3pw-xc5r","slug":"ghsa-wqp7-x3pw-xc5r-4caabf81","dossier":false,"summary":"Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows","aliases":["CVE-2026-48818","PYSEC-2026-2281"],"sourceIds":["GHSA-wqp7-x3pw-xc5r","PYSEC-2026-2281"],"published":"2026-06-15T20:16:30Z","modified":"2026-07-13T07:26:44.976412482Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-wqp7-x3pw-xc5r"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48818"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48818.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30087"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490020"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/fd53168a7767b6b55ba5af787fd88f49e33cabc5"},{"type":"FIX","url":"https://github.com/Kludex/starlette/pull/3287"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-wvwj-cvrp-7pv5","slug":"ghsa-wvwj-cvrp-7pv5-e187e76a","dossier":false,"summary":"Authlib JWS JWK Header Injection: Signature Verification Bypass","aliases":["CVE-2026-27962","PYSEC-2026-287"],"sourceIds":["GHSA-wvwj-cvrp-7pv5","PYSEC-2026-287"],"published":"2026-03-16T15:17:15Z","modified":"2026-07-13T16:15:15.641042659Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/authlib/authlib/security/advisories/GHSA-wvwj-cvrp-7pv5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27962"},{"type":"WEB","url":"https://github.com/authlib/authlib/commit/a5d4b2d4c9e46bfa11c82f85fdc2bcc0b50ae681"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://github.com/authlib/authlib/releases/tag/v1.6.9"},{"type":"PACKAGE","url":"https://pypi.org/project/authlib"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wvwj-cvrp-7pv5"}],"versionKeys":["pypi:authlib@1.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-x284-j5p8-9c5p","slug":"ghsa-x284-j5p8-9c5p-9dc7590e","dossier":false,"summary":"pypdf: Manipulated FlateDecode image dimensions can exhaust RAM","aliases":["CVE-2026-41314","PYSEC-2026-3026"],"sourceIds":["GHSA-x284-j5p8-9c5p","PYSEC-2026-3026"],"published":"2026-04-16T21:30:25Z","modified":"2026-07-13T16:43:30.190503912Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-x284-j5p8-9c5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41314"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3734"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.2"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x284-j5p8-9c5p"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-x746-7m8f-x49c","slug":"ghsa-x746-7m8f-x49c-c0349d3f","dossier":false,"summary":"Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`","aliases":["CVE-2026-48817","PYSEC-2026-2280"],"sourceIds":["GHSA-x746-7m8f-x49c","PYSEC-2026-2280"],"published":"2026-06-15T20:16:05Z","modified":"2026-07-13T07:26:54.069698774Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48817"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-x7hp-r3qg-r3cj","slug":"ghsa-x7hp-r3qg-r3cj-a6a2390f","dossier":false,"summary":"pypdf: Manipulated FlateDecode XFA streams can exhaust RAM","aliases":["CVE-2026-27888","PYSEC-2026-3027"],"sourceIds":["GHSA-x7hp-r3qg-r3cj","PYSEC-2026-3027"],"published":"2026-02-26T19:55:33Z","modified":"2026-07-13T16:43:05.154122042Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-x7hp-r3qg-r3cj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27888"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/pull/3658"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/commit/7a4c8246ed48d9d328fb596942271da47b6d109c"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.7.3"},{"type":"PACKAGE","url":"https://pypi.org/project/pypdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x7hp-r3qg-r3cj"}],"versionKeys":["pypi:pypdf@5.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-xcgm-r5h9-7989","slug":"ghsa-xcgm-r5h9-7989-77bcbc26","dossier":false,"summary":"aiohttp: Incomplete websocket frame payloads bypass memory limits","aliases":["CVE-2026-54274","PYSEC-2026-2108"],"sourceIds":["GHSA-xcgm-r5h9-7989","PYSEC-2026-2108"],"published":"2026-06-15T20:11:22Z","modified":"2026-07-13T07:26:54.330692251Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-xg8h-j46f-w952","slug":"ghsa-xg8h-j46f-w952-da36a616","dossier":false,"summary":"Pillow vulnerability can cause write buffer overflow on BCn encoding","aliases":["BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61"],"sourceIds":["GHSA-xg8h-j46f-w952","PYSEC-2025-61"],"published":"2025-07-01T17:29:37Z","modified":"2026-02-04T03:49:31.268130Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48379"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9041"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2025-61.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/11.3.0"}],"versionKeys":["pypi:pillow@11.2.1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-xgmm-8j9v-c9wx","slug":"ghsa-xgmm-8j9v-c9wx-bc6db7ad","dossier":false,"summary":"PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed","aliases":["CVE-2026-48526","PYSEC-2026-179"],"sourceIds":["GHSA-xgmm-8j9v-c9wx","PYSEC-2026-179"],"published":"2026-05-28T16:16:29.657Z","modified":"2026-06-16T15:44:21.766942950Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48526"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-179.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-xh95-f55m-82fw","slug":"ghsa-xh95-f55m-82fw-6e557f3c","dossier":false,"summary":"Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)","aliases":["CVE-2026-12074"],"sourceIds":["GHSA-xh95-f55m-82fw"],"published":"2026-07-31T16:50:41Z","modified":"2026-07-31T17:00:21.729863168Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-xh95-f55m-82fw"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-xj96-63gp-2gmr","slug":"ghsa-xj96-63gp-2gmr-85e1cf15","dossier":false,"summary":"Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`","aliases":["BIT-pillow-2026-59197","CVE-2026-59197","PYSEC-2026-3454"],"sourceIds":["GHSA-xj96-63gp-2gmr","PYSEC-2026-3454"],"published":"2026-07-14T17:17:14.487Z","modified":"2026-07-22T11:11:36.231472645Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59197"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9695"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-xm59-rqc7-hhvf","slug":"ghsa-xm59-rqc7-hhvf-9413791b","dossier":false,"summary":"nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows","aliases":["CVE-2025-53000","PYSEC-2026-1691"],"sourceIds":["GHSA-xm59-rqc7-hhvf","PYSEC-2026-1691"],"published":"2025-12-18T22:03:08Z","modified":"2026-07-07T17:56:11.809154672Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-xm59-rqc7-hhvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53000"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/issues/2258"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/commit/c9ac1d1040459ed1ff9eb34e9918ce5a87cf9d71"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/blob/4f61702f5c7524d8a3c4ac0d5fc33a6ac2fa36a7/nbconvert/preprocessors/svg2pdf.py#L104"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.0"},{"type":"WEB","url":"https://www.imperva.com/blog/code-execution-in-jupyter-notebook-exports"},{"type":"PACKAGE","url":"https://pypi.org/project/nbconvert"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xm59-rqc7-hhvf"}],"versionKeys":["pypi:nbconvert@7.16.6"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2024-323","slug":"pysec-2024-323-1dd96856","dossier":false,"summary":null,"aliases":["CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514"],"sourceIds":["PYSEC-2024-323"],"published":"2024-09-17T12:15:02.977Z","modified":"2026-07-13T07:26:23.643495355Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"}],"versionKeys":["pypi:langchain@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-183","slug":"pysec-2025-183-08217171","dossier":false,"summary":null,"aliases":["CVE-2025-45768"],"sourceIds":["PYSEC-2025-183"],"published":"2025-07-31T21:15:27.320Z","modified":"2026-05-21T15:00:28.178881228Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla"},{"type":"REPORT","url":"https://gist.github.com/ZupeiNie/6f65e564f2067b876321d3dfdbb76569"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":2},{"id":"PYSEC-2026-2085","slug":"pysec-2026-2085-e081ac1d","dossier":false,"summary":null,"aliases":["CVE-2026-12252"],"sourceIds":["PYSEC-2026-2085"],"published":"2026-07-04T02:16:23.603Z","modified":"2026-07-09T12:00:05.700183399Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://huntr.com/bounties/f5c93982-0cc9-4e2e-bb85-1b6ab29a2efb"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-2132","slug":"pysec-2026-2132-627bf7c7","dossier":true,"summary":null,"aliases":["CVE-2026-7246","GHSA-47fr-3ffg-hgmw"],"sourceIds":["PYSEC-2026-2132"],"published":"2026-04-30T14:16:36.433Z","modified":"2026-07-13T07:15:21.899333658Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-7246"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464121"},{"type":"FIX","url":"https://github.com/pallets/click/releases/tag/8.3.3"},{"type":"EVIDENCE","url":"https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw"}],"versionKeys":["pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1"],"packageCount":1,"repositoryCount":14},{"id":"PYSEC-2026-2208","slug":"pysec-2026-2208-4dad303d","dossier":false,"summary":null,"aliases":["CVE-2026-44898","GHSA-6269-cqxg-mhhv"],"sourceIds":["PYSEC-2026-2208"],"published":"2026-05-26T21:16:39.810Z","modified":"2026-07-13T07:15:28.986856174Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-6269-cqxg-mhhv"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2209","slug":"pysec-2026-2209-f89c37e9","dossier":false,"summary":null,"aliases":["CVE-2026-44899","GHSA-ccfx-mfmx-2fx9"],"sourceIds":["PYSEC-2026-2209"],"published":"2026-05-26T21:16:39.953Z","modified":"2026-07-13T07:15:29.089597285Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-ccfx-mfmx-2fx9"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-3455","slug":"pysec-2026-3455-73e6f483","dossier":false,"summary":null,"aliases":["CVE-2026-59884","GHSA-m4p7-r5rc-7g4j"],"sourceIds":["PYSEC-2026-3455"],"published":"2026-07-14T17:17:14.750Z","modified":"2026-07-22T11:00:08.839373736Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"},{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j"},{"type":"FIX","url":"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5"}],"versionKeys":["pypi:pyasn1@0.6.1","pypi:pyasn1@0.6.3"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2026-597","slug":"pysec-2026-597-f85c09cd","dossier":false,"summary":null,"aliases":["CVE-2026-12243"],"sourceIds":["PYSEC-2026-597"],"published":"2026-06-30T01:16:29.063Z","modified":"2026-07-01T18:15:06.027046365Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://huntr.com/bounties/39aa9354-54ca-4e77-96da-580eb1fe6ed1"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-99","slug":"pysec-2026-99-2c63e84f","dossier":false,"summary":null,"aliases":["CVE-2026-0848"],"sourceIds":["PYSEC-2026-99"],"published":"2026-03-05T21:16:14.263Z","modified":"2026-05-20T09:19:09.284207Z","checkedAt":"2026-07-31T19:03:09.699Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://huntr.com/bounties/08b109bb-ac24-403f-9422-1c246ce60202"}],"versionKeys":["pypi:nltk@3.9.1","pypi:nltk@3.9.2"],"packageCount":1,"repositoryCount":3}]}}
