{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:5142","slug":"opencode-5142","gitlabProjectId":5142,"name":"strahlenexposition","pathWithNamespace":"uba-ki-lab/strahlenexposition","description":null,"webUrl":"https://gitlab.opencode.de/uba-ki-lab/strahlenexposition","commitSha":"1dd9cd8ca823a7998b729adce6957848cf241d54","commitUrl":"https://gitlab.opencode.de/uba-ki-lab/strahlenexposition/-/commit/1dd9cd8ca823a7998b729adce6957848cf241d54","lastActivityAt":"2025-05-19T12:18:40.157Z","headCommittedAt":"2025-05-19T12:51:35.000Z","tree":{"complete":true,"entryCount":69,"truncated":false},"files":[{"path":"poetry.lock","kind":"poetry-lock","blobSha":"681193f56a8b37b97336b2682fc1147ac3bdab1f","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/strahlenexposition/-/blob/1dd9cd8ca823a7998b729adce6957848cf241d54/poetry.lock","commitSha":"1dd9cd8ca823a7998b729adce6957848cf241d54","contentSha256":"c489b7b61f52a098139ff30c50edcca0e32753b4b014f22e0b51d2e97c950433","byteCount":258698,"state":"parsed","componentCount":102},{"path":"sbom.json","kind":"sbom-json","blobSha":"bce3149701e5462f1af80e9221c0e2967402d606","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/strahlenexposition/-/blob/1dd9cd8ca823a7998b729adce6957848cf241d54/sbom.json","commitSha":"1dd9cd8ca823a7998b729adce6957848cf241d54","contentSha256":"4352d1512c073ad9072f4876774e7e60b4d7287e992b698284e6e3054e972883","byteCount":531903,"state":"parsed","componentCount":222}],"resolvedComponentCount":324,"artifactResolvedComponentCount":324,"exactManifestPinCount":0,"packageCount":224,"ecosystems":["pypi"],"aiPackageCount":1,"licenseExpressionCount":20,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-248v-346w-9cwc","GHSA-24qx-w28j-9m6p","GHSA-2599-h6xx-hpxp","GHSA-29vq-49wr-vm6x","GHSA-2g68-c3qc-8985","GHSA-2qfp-q593-8484","GHSA-2wc2-fm75-p42x","GHSA-2xpw-w6gg-jr37","GHSA-33p9-3p43-82vq","GHSA-37w4-hwhx-4rc4","GHSA-38jv-5279-wg99","GHSA-3x9g-8vmp-wqvf","GHSA-48p4-8xcf-vxj5","GHSA-4c99-qj7h-p3vg","GHSA-4xh5-x5gv-qwph","GHSA-5239-wwwm-4pmq","GHSA-537c-gmf6-5ccf","GHSA-5789-5fc7-67v3","GHSA-58cw-g322-p94v","GHSA-58pv-8j8x-9vj2","GHSA-58qw-9mgm-455v","GHSA-597g-3phw-6986","GHSA-5mrq-x3x5-8v8f","GHSA-5rjg-fvgr-3xxf","GHSA-5wmx-573v-2qwq","GHSA-5xmw-vc9v-4wf2","GHSA-65pc-fj4g-8rjx","GHSA-68rp-wp8r-4726","GHSA-6v7p-g79w-8964","GHSA-6vgw-5pg2-w6jp","GHSA-6w46-j5rx-g56g","GHSA-73h3-mf4w-8647","GHSA-768j-98cg-p3fv","GHSA-78cv-mqj4-43f7","GHSA-79v4-65xg-pq4g","GHSA-7cx3-6m66-7c5m","GHSA-7jqv-fw35-gmx9","GHSA-836r-79rf-4m37","GHSA-87hc-h4r5-73f7","GHSA-897w-fcg9-f6xj","GHSA-8g87-j6q8-g93x","GHSA-8mp2-v27r-99xp","GHSA-8rfp-98v4-mmr6","GHSA-983w-rhvv-gwmv","GHSA-9hjg-9r4m-mvj7","GHSA-9q39-rmj3-p4r2","GHSA-9wx4-h78v-vm56","GHSA-cfh3-3jmp-rvhc","GHSA-cpwx-vrp4-4pq7","GHSA-cx3h-4qpv-8hc9","GHSA-cx63-2mw6-8hw5","GHSA-f9vj-2wh5-fj8j","GHSA-fcw5-x6j4-ccmp","GHSA-gc5v-m9x4-r6x2","GHSA-gf7q-q4j7-hp7c","GHSA-gj48-438w-jh9v","GHSA-gm62-xv2j-4w53","GHSA-gmj6-6f8f-6699","GHSA-h4gh-qq45-vh27","GHSA-h75v-3vvj-5mfj","GHSA-hgf8-39gv-g3f2","GHSA-jhhc-3hcp-qhm5","GHSA-jp4c-xjxw-mgf9","GHSA-m959-cc7f-wv43","GHSA-mf9v-mfxr-j63j","GHSA-mgf9-4vpg-hj56","GHSA-mq26-g339-26xf","GHSA-mqcg-5x36-vfcg","GHSA-p423-j2cm-9vmq","GHSA-pq67-6m6q-mj2v","GHSA-pw6j-qg29-8w7f","GHSA-pwv6-vv43-88gr","GHSA-q2x7-8rv6-6q7h","GHSA-q34m-jh98-gwm2","GHSA-qccp-gfcp-xxvc","GHSA-qcq2-496w-v96p","GHSA-qh7q-6qm3-653w","GHSA-qjxf-f2mg-c6mc","GHSA-qmgc-5h2g-mvrw","GHSA-r6ph-v2qm-q3c2","GHSA-r73j-pqj5-w3x7","GHSA-rch3-82jr-f9w9","GHSA-rgxp-2hwp-jwgg","GHSA-v42x-x7jp-845h","GHSA-v87v-83h2-53w7","GHSA-vfmq-68hx-4jfw","GHSA-vmhf-c436-hxj4","GHSA-vqfr-h8mv-ghfj","GHSA-vvfj-2jqx-52jm","GHSA-w853-jp5j-5j7f","GHSA-wf93-45jw-7689","GHSA-whj4-6x5x-4v2j","GHSA-wjx4-4jcj-g98j","GHSA-xg8h-j46f-w952","GHSA-xm59-rqc7-hhvf","GHSA-xrvj-v92f-53gj","PYSEC-2025-265","PYSEC-2025-266","PYSEC-2025-267","PYSEC-2026-2132","PYSEC-2026-2208","PYSEC-2026-2209","PYSEC-2026-2210","PYSEC-2026-2211","PYSEC-2026-2212","PYSEC-2026-2213","PYSEC-2026-2214","PYSEC-2026-2215","PYSEC-2026-2216","PYSEC-2026-2217","PYSEC-2026-2218","PYSEC-2026-2253","PYSEC-2026-2254","PYSEC-2026-2255","PYSEC-2026-2256","PYSEC-2026-2257","PYSEC-2026-3447","PYSEC-2026-3451","PYSEC-2026-3452","PYSEC-2026-3453"],"advisoryCount":120,"providers":[]},"evidence":{"files":[{"path":"poetry.lock","kind":"poetry-lock","blobSha":"681193f56a8b37b97336b2682fc1147ac3bdab1f","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/strahlenexposition/-/blob/1dd9cd8ca823a7998b729adce6957848cf241d54/poetry.lock","commitSha":"1dd9cd8ca823a7998b729adce6957848cf241d54","contentSha256":"c489b7b61f52a098139ff30c50edcca0e32753b4b014f22e0b51d2e97c950433","byteCount":258698,"state":"parsed","componentCount":102},{"path":"sbom.json","kind":"sbom-json","blobSha":"bce3149701e5462f1af80e9221c0e2967402d606","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/strahlenexposition/-/blob/1dd9cd8ca823a7998b729adce6957848cf241d54/sbom.json","commitSha":"1dd9cd8ca823a7998b729adce6957848cf241d54","contentSha256":"4352d1512c073ad9072f4876774e7e60b4d7287e992b698284e6e3054e972883","byteCount":531903,"state":"parsed","componentCount":222}],"occurrenceCount":324},"related":{"packages":[{"id":"package:pypi:scikit-learn","slug":"scikit-learn-ab0941d9","identity":"pypi:scikit-learn","label":"scikit-learn","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["1.6.1"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:mistune","slug":"mistune-883ae9a9","identity":"pypi:mistune","label":"mistune","aiRelevant":false,"provider":null,"advisoryCount":16,"licenseExpressions":["BSD-3-Clause"],"versions":["3.1.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pillow","slug":"pillow-834347dd","identity":"pypi:pillow","label":"pillow","aiRelevant":false,"provider":null,"advisoryCount":15,"licenseExpressions":["HPND","MIT-CMU"],"versions":["11.2.1"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:tornado","slug":"tornado-ab0f364e","identity":"pypi:tornado","label":"tornado","aiRelevant":false,"provider":null,"advisoryCount":10,"licenseExpressions":["Apache-2.0"],"versions":["6.4.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-server","slug":"jupyter-server-bda3ce93","identity":"pypi:jupyter-server","label":"jupyter-server","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["non-standard"],"versions":["2.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:urllib3","slug":"urllib3-fa68f32c","identity":"pypi:urllib3","label":"urllib3","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["2.4.0"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:cryptography","slug":"cryptography-de36c9c8","identity":"pypi:cryptography","label":"cryptography","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["Apache-2.0 OR BSD-3-Clause"],"versions":["44.0.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pip","slug":"pip-2911c768","identity":"pypi:pip","label":"pip","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["MIT"],"versions":["22.0.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:werkzeug","slug":"werkzeug-b18d5b02","identity":"pypi:werkzeug","label":"werkzeug","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.6"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:jupyterlab","slug":"jupyterlab-da634f79","identity":"pypi:jupyterlab","label":"jupyterlab","aiRelevant":false,"provider":null,"advisoryCount":5,"licenseExpressions":["non-standard"],"versions":["4.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jinja2","slug":"jinja2-f7d34747","identity":"pypi:jinja2","label":"jinja2","aiRelevant":false,"provider":null,"advisoryCount":4,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.6"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:nbconvert","slug":"nbconvert-a72151db","identity":"pypi:nbconvert","label":"nbconvert","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["non-standard"],"versions":["7.16.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:notebook","slug":"notebook-9683036a","identity":"pypi:notebook","label":"notebook","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["non-standard"],"versions":["7.0.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:requests","slug":"requests-53653f76","identity":"pypi:requests","label":"requests","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["Apache-2.0"],"versions":["2.32.3"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:setuptools","slug":"setuptools-fe37c31a","identity":"pypi:setuptools","label":"setuptools","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["80.0.1"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:bleach","slug":"bleach-b1747264","identity":"pypi:bleach","label":"bleach","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["non-standard"],"versions":["6.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:dulwich","slug":"dulwich-a07208e4","identity":"pypi:dulwich","label":"dulwich","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["non-standard"],"versions":["0.22.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:filelock","slug":"filelock-b1c63968","identity":"pypi:filelock","label":"filelock","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT","Unlicense"],"versions":["3.18.0"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:poetry","slug":"poetry-b3f02d83","identity":"pypi:poetry","label":"poetry","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["2.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:soupsieve","slug":"soupsieve-91552d8b","identity":"pypi:soupsieve","label":"soupsieve","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["2.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:weasyprint","slug":"weasyprint-637c63f5","identity":"pypi:weasyprint","label":"weasyprint","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["non-standard"],"versions":["64.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:brotli","slug":"brotli-9f215eb0","identity":"pypi:brotli","label":"brotli","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:certifi","slug":"certifi-d4f0c37e","identity":"pypi:certifi","label":"certifi","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MPL-2.0"],"versions":["2025.4.26"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:click","slug":"click-ef97f731","identity":"pypi:click","label":"click","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["8.1.8"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:flask","slug":"flask-734a8b3c","identity":"pypi:flask","label":"flask","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.3"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:fonttools","slug":"fonttools-d2488ea8","identity":"pypi:fonttools","label":"fonttools","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["4.57.0"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:h11","slug":"h11-48165ab1","identity":"pypi:h11","label":"h11","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.14.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.10"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:jaraco-context","slug":"jaraco-context-99c022f5","identity":"pypi:jaraco-context","label":"jaraco-context","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["6.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-core","slug":"jupyter-core-44178c79","identity":"pypi:jupyter-core","label":"jupyter-core","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["5.7.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:lxml","slug":"lxml-53ddfa54","identity":"pypi:lxml","label":"lxml","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["5.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:markdown","slug":"markdown-80f66882","identity":"pypi:markdown","label":"markdown","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["3.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:msgpack","slug":"msgpack-007a8d3b","identity":"pypi:msgpack","label":"msgpack","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pyarrow","slug":"pyarrow-facb8516","identity":"pypi:pyarrow","label":"pyarrow","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["20.0.0"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pygments","slug":"pygments-ad71bc11","identity":"pypi:pygments","label":"pygments","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-2-Clause"],"versions":["2.19.1"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pytest","slug":"pytest-07c6f86c","identity":"pypi:pytest","label":"pytest","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["7.4.4"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:virtualenv","slug":"virtualenv-aeb2a546","identity":"pypi:virtualenv","label":"virtualenv","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["20.30.0"],"dossier":true,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:accessible-pygments","slug":"accessible-pygments-9487de96","identity":"pypi:accessible-pygments","label":"accessible-pygments","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.0.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:adjusttext","slug":"adjusttext-93463b56","identity":"pypi:adjusttext","label":"adjusttext","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:alabaster","slug":"alabaster-b25f55b1","identity":"pypi:alabaster","label":"alabaster","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:anyio","slug":"anyio-399e5280","identity":"pypi:anyio","label":"anyio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:argon2-cffi","slug":"argon2-cffi-0666afdc","identity":"pypi:argon2-cffi","label":"argon2-cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["23.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:argon2-cffi-bindings","slug":"argon2-cffi-bindings-8c6d8583","identity":"pypi:argon2-cffi-bindings","label":"argon2-cffi-bindings","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["21.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:arrow","slug":"arrow-d0e153a5","identity":"pypi:arrow","label":"arrow","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:asttokens","slug":"asttokens-c349c5f9","identity":"pypi:asttokens","label":"asttokens","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["3.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:async-lru","slug":"async-lru-57db467a","identity":"pypi:async-lru","label":"async-lru","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:attrs","slug":"attrs-2e7954ac","identity":"pypi:attrs","label":"attrs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:babel","slug":"babel-c668b0a9","identity":"pypi:babel","label":"babel","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.17.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:backports-tarfile","slug":"backports-tarfile-4764d5a8","identity":"pypi:backports-tarfile","label":"backports-tarfile","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:beautifulsoup4","slug":"beautifulsoup4-eddf0c04","identity":"pypi:beautifulsoup4","label":"beautifulsoup4","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.13.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:blinker","slug":"blinker-409e1445","identity":"pypi:blinker","label":"blinker","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:boolean-py","slug":"boolean-py-d2700117","identity":"pypi:boolean-py","label":"boolean-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:brotlicffi","slug":"brotlicffi-2b85a746","identity":"pypi:brotlicffi","label":"brotlicffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock"]},{"id":"package:pypi:build","slug":"build-a517ae38","identity":"pypi:build","label":"build","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.2.post1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:cachecontrol","slug":"cachecontrol-f48df14f","identity":"pypi:cachecontrol","label":"cachecontrol","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.14.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:cffi","slug":"cffi-38e65d3e","identity":"pypi:cffi","label":"cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:cfgv","slug":"cfgv-4583061f","identity":"pypi:cfgv","label":"cfgv","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:chardet","slug":"chardet-69451fbd","identity":"pypi:chardet","label":"chardet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD","non-standard"],"versions":["5.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:charset-normalizer","slug":"charset-normalizer-74ccb20a","identity":"pypi:charset-normalizer","label":"charset-normalizer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:cleo","slug":"cleo-5786f647","identity":"pypi:cleo","label":"cleo","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock"]},{"id":"package:pypi:comm","slug":"comm-0720ed7b","identity":"pypi:comm","label":"comm","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:contourpy","slug":"contourpy-f86f9e10","identity":"pypi:contourpy","label":"contourpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.3.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:coverage","slug":"coverage-7ba89558","identity":"pypi:coverage","label":"coverage","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["7.8.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:crashtest","slug":"crashtest-ae75ce65","identity":"pypi:crashtest","label":"crashtest","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:cssselect2","slug":"cssselect2-87d00b2b","identity":"pypi:cssselect2","label":"cssselect2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.8.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:cycler","slug":"cycler-3e14883d","identity":"pypi:cycler","label":"cycler","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.12.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:cyclonedx-bom","slug":"cyclonedx-bom-120c32c1","identity":"pypi:cyclonedx-bom","label":"cyclonedx-bom","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:cyclonedx-python-lib","slug":"cyclonedx-python-lib-af6d232b","identity":"pypi:cyclonedx-python-lib","label":"cyclonedx-python-lib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["10.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:dash","slug":"dash-e3e5697e","identity":"pypi:dash","label":"dash","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.18.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:dash-ag-grid","slug":"dash-ag-grid-743015a6","identity":"pypi:dash-ag-grid","label":"dash-ag-grid","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["31.3.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:dash-bootstrap-components","slug":"dash-bootstrap-components-88bc9fcb","identity":"pypi:dash-bootstrap-components","label":"dash-bootstrap-components","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.7.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:dash-core-components","slug":"dash-core-components-b991ac64","identity":"pypi:dash-core-components","label":"dash-core-components","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:dash-html-components","slug":"dash-html-components-e57cf97c","identity":"pypi:dash-html-components","label":"dash-html-components","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:dash-table","slug":"dash-table-7ee8ce01","identity":"pypi:dash-table","label":"dash-table","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["5.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:debugpy","slug":"debugpy-71725cbb","identity":"pypi:debugpy","label":"debugpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.8.13"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:decorator","slug":"decorator-500c1fb8","identity":"pypi:decorator","label":"decorator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["5.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:defusedxml","slug":"defusedxml-fab5db42","identity":"pypi:defusedxml","label":"defusedxml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:distlib","slug":"distlib-d66be865","identity":"pypi:distlib","label":"distlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["0.3.9"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:docutils","slug":"docutils-cc2f8622","identity":"pypi:docutils","label":"docutils","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.21.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:exceptiongroup","slug":"exceptiongroup-316db5d9","identity":"pypi:exceptiongroup","label":"exceptiongroup","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:executing","slug":"executing-36845a5b","identity":"pypi:executing","label":"executing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:fastexcel","slug":"fastexcel-597156fa","identity":"pypi:fastexcel","label":"fastexcel","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.12.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:fastjsonschema","slug":"fastjsonschema-8288c29a","identity":"pypi:fastjsonschema","label":"fastjsonschema","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.21.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:fpdf","slug":"fpdf-f7cb5b3b","identity":"pypi:fpdf","label":"fpdf","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.7.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:fqdn","slug":"fqdn-2616214a","identity":"pypi:fqdn","label":"fqdn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:ghp-import","slug":"ghp-import-17055206","identity":"pypi:ghp-import","label":"ghp-import","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:httpcore","slug":"httpcore-ba6ae671","identity":"pypi:httpcore","label":"httpcore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.0.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:httpx","slug":"httpx-a512a166","identity":"pypi:httpx","label":"httpx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:identify","slug":"identify-bd45ae56","identity":"pypi:identify","label":"identify","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.6.10"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:imagesize","slug":"imagesize-6607709a","identity":"pypi:imagesize","label":"imagesize","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.4.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:importlib-metadata","slug":"importlib-metadata-a3dfda3c","identity":"pypi:importlib-metadata","label":"importlib-metadata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["8.7.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:iniconfig","slug":"iniconfig-1f66e358","identity":"pypi:iniconfig","label":"iniconfig","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:installer","slug":"installer-b3de742e","identity":"pypi:installer","label":"installer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:ipykernel","slug":"ipykernel-37162218","identity":"pypi:ipykernel","label":"ipykernel","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["6.29.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:ipython","slug":"ipython-7a140323","identity":"pypi:ipython","label":"ipython","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["8.34.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:ipywidgets","slug":"ipywidgets-5079daea","identity":"pypi:ipywidgets","label":"ipywidgets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["8.1.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:isoduration","slug":"isoduration-e8f86ac8","identity":"pypi:isoduration","label":"isoduration","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["20.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:itsdangerous","slug":"itsdangerous-4af70837","identity":"pypi:itsdangerous","label":"itsdangerous","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2.2.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:jaraco-classes","slug":"jaraco-classes-f6f93091","identity":"pypi:jaraco-classes","label":"jaraco-classes","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jaraco-functools","slug":"jaraco-functools-96278cbc","identity":"pypi:jaraco-functools","label":"jaraco-functools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jedi","slug":"jedi-9eb0c211","identity":"pypi:jedi","label":"jedi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.19.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jeepney","slug":"jeepney-898410ff","identity":"pypi:jeepney","label":"jeepney","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:joblib","slug":"joblib-8cbb7872","identity":"pypi:joblib","label":"joblib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.4.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:json5","slug":"json5-79be3697","identity":"pypi:json5","label":"json5","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jsonpointer","slug":"jsonpointer-a61b5f8f","identity":"pypi:jsonpointer","label":"jsonpointer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jsonschema","slug":"jsonschema-df23f5cd","identity":"pypi:jsonschema","label":"jsonschema","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.23.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jsonschema-specifications","slug":"jsonschema-specifications-5d87863a","identity":"pypi:jsonschema-specifications","label":"jsonschema-specifications","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter","slug":"jupyter-cfc2388a","identity":"pypi:jupyter","label":"jupyter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-client","slug":"jupyter-client-3b4db88c","identity":"pypi:jupyter-client","label":"jupyter-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["8.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-console","slug":"jupyter-console-fe43250b","identity":"pypi:jupyter-console","label":"jupyter-console","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["6.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-events","slug":"jupyter-events-f8263fc3","identity":"pypi:jupyter-events","label":"jupyter-events","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-lsp","slug":"jupyter-lsp-e5008e78","identity":"pypi:jupyter-lsp","label":"jupyter-lsp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.2.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyter-server-terminals","slug":"jupyter-server-terminals-908697b8","identity":"pypi:jupyter-server-terminals","label":"jupyter-server-terminals","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.5.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyterlab-pygments","slug":"jupyterlab-pygments-f3159f9e","identity":"pypi:jupyterlab-pygments","label":"jupyterlab-pygments","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyterlab-server","slug":"jupyterlab-server-87bbeff5","identity":"pypi:jupyterlab-server","label":"jupyterlab-server","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.27.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:jupyterlab-widgets","slug":"jupyterlab-widgets-e76ed5e8","identity":"pypi:jupyterlab-widgets","label":"jupyterlab-widgets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.13"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:kaleido","slug":"kaleido-d94ddeb6","identity":"pypi:kaleido","label":"kaleido","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.0.post1","0.2.1"],"dossier":false,"occurrenceCount":3,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:keyring","slug":"keyring-1f591b74","identity":"pypi:keyring","label":"keyring","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:kiwisolver","slug":"kiwisolver-41b47c33","identity":"pypi:kiwisolver","label":"kiwisolver","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.4.8"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:license-expression","slug":"license-expression-66cbb677","identity":"pypi:license-expression","label":"license-expression","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["30.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:markdown-it-py","slug":"markdown-it-py-27073f5e","identity":"pypi:markdown-it-py","label":"markdown-it-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:markupsafe","slug":"markupsafe-1bdd4c7f","identity":"pypi:markupsafe","label":"markupsafe","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:matplotlib","slug":"matplotlib-9dc72309","identity":"pypi:matplotlib","label":"matplotlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.10.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:matplotlib-inline","slug":"matplotlib-inline-50f95e0d","identity":"pypi:matplotlib-inline","label":"matplotlib-inline","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.1.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:mdit-py-plugins","slug":"mdit-py-plugins-79000951","identity":"pypi:mdit-py-plugins","label":"mdit-py-plugins","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:mdurl","slug":"mdurl-e6f5f075","identity":"pypi:mdurl","label":"mdurl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:mergedeep","slug":"mergedeep-77a23f49","identity":"pypi:mergedeep","label":"mergedeep","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:mkdocs","slug":"mkdocs-a74efb5d","identity":"pypi:mkdocs","label":"mkdocs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["1.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:mkdocs-get-deps","slug":"mkdocs-get-deps-504099a6","identity":"pypi:mkdocs-get-deps","label":"mkdocs-get-deps","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:more-itertools","slug":"more-itertools-fa46f32b","identity":"pypi:more-itertools","label":"more-itertools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["10.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:myst-parser","slug":"myst-parser-af46368e","identity":"pypi:myst-parser","label":"myst-parser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.0.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:narwhals","slug":"narwhals-24e2f721","identity":"pypi:narwhals","label":"narwhals","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","non-standard"],"versions":["1.37.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:nbclient","slug":"nbclient-e201d8f1","identity":"pypi:nbclient","label":"nbclient","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.10.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:nbformat","slug":"nbformat-2d86904f","identity":"pypi:nbformat","label":"nbformat","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.10.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:nest-asyncio","slug":"nest-asyncio-f76531b1","identity":"pypi:nest-asyncio","label":"nest-asyncio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.6.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:nodeenv","slug":"nodeenv-71203cea","identity":"pypi:nodeenv","label":"nodeenv","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.9.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:notebook-shim","slug":"notebook-shim-6d442652","identity":"pypi:notebook-shim","label":"notebook-shim","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:numpy","slug":"numpy-ba79b98d","identity":"pypi:numpy","label":"numpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib","non-standard"],"versions":["2.2.5"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:overrides","slug":"overrides-be2d7343","identity":"pypi:overrides","label":"overrides","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["7.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:packageurl-python","slug":"packageurl-python-dc3afccd","identity":"pypi:packageurl-python","label":"packageurl-python","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["25.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pandas","slug":"pandas-e8d52445","identity":"pypi:pandas","label":"pandas","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.2.3"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pandocfilters","slug":"pandocfilters-f452098e","identity":"pypi:pandocfilters","label":"pandocfilters","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:parso","slug":"parso-fa59fdde","identity":"pypi:parso","label":"parso","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pathspec","slug":"pathspec-01378677","identity":"pypi:pathspec","label":"pathspec","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MPL-2.0"],"versions":["0.12.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pexpect","slug":"pexpect-9ad65a0c","identity":"pypi:pexpect","label":"pexpect","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pip-requirements-parser","slug":"pip-requirements-parser-3a4c3c44","identity":"pypi:pip-requirements-parser","label":"pip-requirements-parser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["32.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pkginfo","slug":"pkginfo-6db98855","identity":"pypi:pkginfo","label":"pkginfo","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:platformdirs","slug":"platformdirs-e64002f0","identity":"pypi:platformdirs","label":"platformdirs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.3.7"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:plotly","slug":"plotly-036ddabb","identity":"pypi:plotly","label":"plotly","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["6.0.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pluggy","slug":"pluggy-24479aaf","identity":"pypi:pluggy","label":"pluggy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.5.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:poetry-core","slug":"poetry-core-100baf72","identity":"pypi:poetry-core","label":"poetry-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:polars","slug":"polars-f649ebed","identity":"pypi:polars","label":"polars","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","non-standard"],"versions":["1.28.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pre-commit","slug":"pre-commit-6a196b54","identity":"pypi:pre-commit","label":"pre-commit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.2.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:prometheus-client","slug":"prometheus-client-7bd206b5","identity":"pypi:prometheus-client","label":"prometheus-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","Apache-2.0 AND BSD-2-Clause"],"versions":["0.21.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:prompt-toolkit","slug":"prompt-toolkit-e6f4118a","identity":"pypi:prompt-toolkit","label":"prompt-toolkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.50"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:psutil","slug":"psutil-840b9a74","identity":"pypi:psutil","label":"psutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["7.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:ptyprocess","slug":"ptyprocess-ec2650c7","identity":"pypi:ptyprocess","label":"ptyprocess","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pure-eval","slug":"pure-eval-24d2bc1c","identity":"pypi:pure-eval","label":"pure-eval","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:py-serializable","slug":"py-serializable-cebfca90","identity":"pypi:py-serializable","label":"py-serializable","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pycparser","slug":"pycparser-102d9d3e","identity":"pypi:pycparser","label":"pycparser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.22"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pydata-sphinx-theme","slug":"pydata-sphinx-theme-e95d5df9","identity":"pypi:pydata-sphinx-theme","label":"pydata-sphinx-theme","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.15.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pydyf","slug":"pydyf-60de6213","identity":"pypi:pydyf","label":"pydyf","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.11.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pyparsing","slug":"pyparsing-a28b9b62","identity":"pypi:pyparsing","label":"pyparsing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.2.3"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pyphen","slug":"pyphen-9e168dac","identity":"pypi:pyphen","label":"pyphen","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["GPL-2.0-or-later","LGPL-2.0-or-later","MPL-1.1"],"versions":["0.17.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pyproject-hooks","slug":"pyproject-hooks-360ad2ce","identity":"pypi:pyproject-hooks","label":"pyproject-hooks","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pytest-cov","slug":"pytest-cov-1f608c88","identity":"pypi:pytest-cov","label":"pytest-cov","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.1.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:python-dateutil","slug":"python-dateutil-8eac96b7","identity":"pypi:python-dateutil","label":"python-dateutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.9.0.post0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:python-json-logger","slug":"python-json-logger-f4803e0b","identity":"pypi:python-json-logger","label":"python-json-logger","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pytz","slug":"pytz-cbf1d95c","identity":"pypi:pytz","label":"pytz","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pyyaml","slug":"pyyaml-16000901","identity":"pypi:pyyaml","label":"pyyaml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.0.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:pyyaml-env-tag","slug":"pyyaml-env-tag-7c09b2b4","identity":"pypi:pyyaml-env-tag","label":"pyyaml-env-tag","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:pyzmq","slug":"pyzmq-30b92392","identity":"pypi:pyzmq","label":"pyzmq","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["26.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:rapidfuzz","slug":"rapidfuzz-3beab87b","identity":"pypi:rapidfuzz","label":"rapidfuzz","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:referencing","slug":"referencing-b8d98ce1","identity":"pypi:referencing","label":"referencing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.36.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:requests-toolbelt","slug":"requests-toolbelt-bb89e811","identity":"pypi:requests-toolbelt","label":"requests-toolbelt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:retrying","slug":"retrying-82bfb1ea","identity":"pypi:retrying","label":"retrying","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.3.4"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:rfc3339-validator","slug":"rfc3339-validator-433f6951","identity":"pypi:rfc3339-validator","label":"rfc3339-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:rfc3986-validator","slug":"rfc3986-validator-723c00af","identity":"pypi:rfc3986-validator","label":"rfc3986-validator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:rfc3987","slug":"rfc3987-a4373505","identity":"pypi:rfc3987","label":"rfc3987","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.3.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:rpds-py","slug":"rpds-py-67c64be8","identity":"pypi:rpds-py","label":"rpds-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.24.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:rstcheck","slug":"rstcheck-fd345cb4","identity":"pypi:rstcheck","label":"rstcheck","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.5.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:ruff","slug":"ruff-d5943bdf","identity":"pypi:ruff","label":"ruff","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.9.10"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:scipy","slug":"scipy-215f884d","identity":"pypi:scipy","label":"scipy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.15.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:secretstorage","slug":"secretstorage-0ea3bee5","identity":"pypi:secretstorage","label":"secretstorage","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.3.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:send2trash","slug":"send2trash-9494ed34","identity":"pypi:send2trash","label":"send2trash","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.8.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:shellingham","slug":"shellingham-fceabe5b","identity":"pypi:shellingham","label":"shellingham","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:six","slug":"six-3c3888bd","identity":"pypi:six","label":"six","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sniffio","slug":"sniffio-83f32c9d","identity":"pypi:sniffio","label":"sniffio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:snowballstemmer","slug":"snowballstemmer-1fdc23ac","identity":"pypi:snowballstemmer","label":"snowballstemmer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.2.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sortedcontainers","slug":"sortedcontainers-9601b229","identity":"pypi:sortedcontainers","label":"sortedcontainers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:sphinx","slug":"sphinx-e280a19f","identity":"pypi:sphinx","label":"sphinx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["8.1.3"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinx-book-theme","slug":"sphinx-book-theme-9ff8a638","identity":"pypi:sphinx-book-theme","label":"sphinx-book-theme","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:sphinx-rtd-theme","slug":"sphinx-rtd-theme-faf08ada","identity":"pypi:sphinx-rtd-theme","label":"sphinx-rtd-theme","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.0.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-applehelp","slug":"sphinxcontrib-applehelp-9e21d5db","identity":"pypi:sphinxcontrib-applehelp","label":"sphinxcontrib-applehelp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-devhelp","slug":"sphinxcontrib-devhelp-9744cd2e","identity":"pypi:sphinxcontrib-devhelp","label":"sphinxcontrib-devhelp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-htmlhelp","slug":"sphinxcontrib-htmlhelp-07a94a0d","identity":"pypi:sphinxcontrib-htmlhelp","label":"sphinxcontrib-htmlhelp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-jquery","slug":"sphinxcontrib-jquery-10d1d7dd","identity":"pypi:sphinxcontrib-jquery","label":"sphinxcontrib-jquery","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-jsmath","slug":"sphinxcontrib-jsmath-c5efc784","identity":"pypi:sphinxcontrib-jsmath","label":"sphinxcontrib-jsmath","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.0.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-qthelp","slug":"sphinxcontrib-qthelp-dfa89853","identity":"pypi:sphinxcontrib-qthelp","label":"sphinxcontrib-qthelp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:sphinxcontrib-serializinghtml","slug":"sphinxcontrib-serializinghtml-ef6417f3","identity":"pypi:sphinxcontrib-serializinghtml","label":"sphinxcontrib-serializinghtml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:stack-data","slug":"stack-data-d640fe0e","identity":"pypi:stack-data","label":"stack-data","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:terminado","slug":"terminado-9ae7e4c0","identity":"pypi:terminado","label":"terminado","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.18.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:threadpoolctl","slug":"threadpoolctl-e94f6300","identity":"pypi:threadpoolctl","label":"threadpoolctl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.6.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:tinycss2","slug":"tinycss2-301fccf6","identity":"pypi:tinycss2","label":"tinycss2","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:tinyhtml5","slug":"tinyhtml5-2f138940","identity":"pypi:tinyhtml5","label":"tinyhtml5","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:tomli","slug":"tomli-e09082bd","identity":"pypi:tomli","label":"tomli","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.2.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:tomlkit","slug":"tomlkit-d5fa3fad","identity":"pypi:tomlkit","label":"tomlkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.13.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:traitlets","slug":"traitlets-52bd6ddb","identity":"pypi:traitlets","label":"traitlets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.14.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:trove-classifiers","slug":"trove-classifiers-da03c18d","identity":"pypi:trove-classifiers","label":"trove-classifiers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2025.1.15.22"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:types-python-dateutil","slug":"types-python-dateutil-7c72d321","identity":"pypi:types-python-dateutil","label":"types-python-dateutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.9.0.20241206"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.13.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:tzdata","slug":"tzdata-f80b3bb7","identity":"pypi:tzdata","label":"tzdata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2025.2"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:uri-template","slug":"uri-template-04c43560","identity":"pypi:uri-template","label":"uri-template","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:watchdog","slug":"watchdog-55ddb444","identity":"pypi:watchdog","label":"watchdog","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:wcwidth","slug":"wcwidth-038a8957","identity":"pypi:wcwidth","label":"wcwidth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.13"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:webcolors","slug":"webcolors-380e4f6b","identity":"pypi:webcolors","label":"webcolors","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["24.11.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:webencodings","slug":"webencodings-04815c4d","identity":"pypi:webencodings","label":"webencodings","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.5.1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:websocket-client","slug":"websocket-client-af182b1a","identity":"pypi:websocket-client","label":"websocket-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:widgetsnbextension","slug":"widgetsnbextension-8ee19027","identity":"pypi:widgetsnbextension","label":"widgetsnbextension","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["4.0.13"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["sbom.json"]},{"id":"package:pypi:xlsxwriter","slug":"xlsxwriter-fab6ebdd","identity":"pypi:xlsxwriter","label":"xlsxwriter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["3.2.3"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:zipp","slug":"zipp-75ac1ddb","identity":"pypi:zipp","label":"zipp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.21.0"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]},{"id":"package:pypi:zopfli","slug":"zopfli-5e2184a1","identity":"pypi:zopfli","label":"zopfli","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.3.post1"],"dossier":false,"occurrenceCount":2,"directOccurrenceCount":0,"evidenceFiles":["poetry.lock","sbom.json"]}],"vulnerabilities":[{"id":"GHSA-248v-346w-9cwc","slug":"ghsa-248v-346w-9cwc-8a7dbdf1","dossier":false,"summary":"Certifi removes GLOBALTRUST root certificate","aliases":["CVE-2024-39689","PYSEC-2024-230"],"sourceIds":["GHSA-248v-346w-9cwc","PYSEC-2024-230"],"published":"2024-07-05T19:15:10Z","modified":"2026-06-10T17:14:18.786020835Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39689"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463"},{"type":"PACKAGE","url":"https://github.com/certifi/python-certifi"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2024-230.yaml"},{"type":"ARTICLE","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241206-0001"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241206-0001/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248v-346w-9cwc"}],"versionKeys":["pypi:certifi@2024.6.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-24qx-w28j-9m6p","slug":"ghsa-24qx-w28j-9m6p-97a1f20a","dossier":false,"summary":"Jupyter Server has a  CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)","aliases":["CVE-2026-40110","PYSEC-2026-2187"],"sourceIds":["GHSA-24qx-w28j-9m6p","PYSEC-2026-2187"],"published":"2026-05-05T16:54:31Z","modified":"2026-07-13T07:26:55.845862407Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40110"},{"type":"REPORT","url":"https://github.com/jupyter-server/jupyter_server/pull/603"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40110"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40110.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466912"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2599-h6xx-hpxp","slug":"ghsa-2599-h6xx-hpxp-c679fd6d","dossier":false,"summary":"Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write","aliases":["CVE-2026-34591","PYSEC-2026-2260"],"sourceIds":["GHSA-2599-h6xx-hpxp","PYSEC-2026-2260"],"published":"2026-04-01T22:17:36Z","modified":"2026-07-13T07:26:50.150184420Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/python-poetry/poetry/security/advisories/GHSA-2599-h6xx-hpxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34591"},{"type":"FIX","url":"https://github.com/python-poetry/poetry/pull/10792"},{"type":"PACKAGE","url":"https://github.com/python-poetry/poetry"},{"type":"ADVISORY","url":"https://github.com/python-poetry/poetry/releases/tag/2.3.3"}],"versionKeys":["pypi:poetry@2.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-29vq-49wr-vm6x","slug":"ghsa-29vq-49wr-vm6x-7d88633b","dossier":false,"summary":"Werkzeug safe_join() allows Windows special device names","aliases":["CVE-2026-27199","PYSEC-2026-2320"],"sourceIds":["GHSA-29vq-49wr-vm6x","PYSEC-2026-2320"],"published":"2026-02-19T20:32:45Z","modified":"2026-07-13T07:26:55.904978535Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-29vq-49wr-vm6x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27199"},{"type":"FIX","url":"https://github.com/pallets/werkzeug/commit/f407712fdc60a09c2b3f4fe7db557703e5d9338d"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"ADVISORY","url":"https://github.com/pallets/werkzeug/releases/tag/3.1.6"}],"versionKeys":["pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3","pypi:werkzeug@3.1.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-2g68-c3qc-8985","slug":"ghsa-2g68-c3qc-8985-d6075eca","dossier":false,"summary":"Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain","aliases":["CVE-2024-34069","PYSEC-2026-2043"],"sourceIds":["GHSA-2g68-c3qc-8985","PYSEC-2026-2043"],"published":"2024-05-06T14:21:27Z","modified":"2026-07-07T17:56:15.006571356Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-2g68-c3qc-8985"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34069"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/3386395b24c7371db11a5b8eaac0c91da5362692"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/02/msg00026.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4SH32AM3CTPMAAEOIDAN7VU565LO4IR"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HFERFN7PINV4MOGMGA3DPIXJPDCYOEJZ"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240614-0004"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2g68-c3qc-8985"}],"versionKeys":["pypi:werkzeug@3.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2qfp-q593-8484","slug":"ghsa-2qfp-q593-8484-b683fc2e","dossier":false,"summary":"Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation","aliases":["CVE-2025-6176","PYSEC-2026-1906","PYSEC-2026-2401"],"sourceIds":["GHSA-2qfp-q593-8484","PYSEC-2026-2401"],"published":"2025-10-31T00:30:35Z","modified":"2026-07-13T16:43:00.989110436Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6176"},{"type":"WEB","url":"https://github.com/google/brotli/issues/1327"},{"type":"WEB","url":"https://github.com/google/brotli/issues/1375"},{"type":"WEB","url":"https://github.com/google/brotli/pull/1234"},{"type":"WEB","url":"https://github.com/scrapy/scrapy/pull/7134"},{"type":"WEB","url":"https://github.com/google/brotli/commit/67d78bc41db1a0d03f2e763497748f2f69946627"},{"type":"WEB","url":"https://github.com/scrapy/scrapy/commit/14737e91edc513967f516fc839cc9c8a4f8d91da"},{"type":"PACKAGE","url":"https://github.com/google/brotli"},{"type":"WEB","url":"https://github.com/google/brotli/releases/tag/v1.2.0"},{"type":"WEB","url":"https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0"},{"type":"PACKAGE","url":"https://pypi.org/project/brotli"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2qfp-q593-8484"}],"versionKeys":["pypi:brotli@1.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2wc2-fm75-p42x","slug":"ghsa-2wc2-fm75-p42x-9941d681","dossier":false,"summary":"Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists","aliases":["CVE-2026-49476","PYSEC-2026-3071"],"sourceIds":["GHSA-2wc2-fm75-p42x","PYSEC-2026-3071"],"published":"2026-07-09T13:37:40Z","modified":"2026-07-13T16:43:32.898354818Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x"},{"type":"PACKAGE","url":"https://github.com/facelessuser/soupsieve"},{"type":"PACKAGE","url":"https://pypi.org/project/soupsieve"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2wc2-fm75-p42x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49476"}],"versionKeys":["pypi:soupsieve@2.6","pypi:soupsieve@2.7","pypi:soupsieve@2.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-2xpw-w6gg-jr37","slug":"ghsa-2xpw-w6gg-jr37-91cead57","dossier":true,"summary":"urllib3 streaming API improperly handles highly compressed data","aliases":["CVE-2025-66471","PYSEC-2026-1994"],"sourceIds":["GHSA-2xpw-w6gg-jr37","PYSEC-2026-1994"],"published":"2025-12-05T18:15:54Z","modified":"2026-07-07T17:56:33.872074196Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-33p9-3p43-82vq","slug":"ghsa-33p9-3p43-82vq-f6a57ddd","dossier":false,"summary":"Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability","aliases":["CVE-2025-30167","PYSEC-2026-1477"],"sourceIds":["GHSA-33p9-3p43-82vq","PYSEC-2026-1477"],"published":"2025-06-04T21:00:23Z","modified":"2026-07-07T17:57:34.145908633Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/security/advisories/GHSA-33p9-3p43-82vq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30167"},{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/commit/5e8965600adda6b416692ce7e85ecb2bd814bd52"},{"type":"PACKAGE","url":"https://github.com/jupyter/jupyter_core"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-33p9-3p43-82vq"}],"versionKeys":["pypi:jupyter-core@5.7.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-37w4-hwhx-4rc4","slug":"ghsa-37w4-hwhx-4rc4-705a8c0a","dossier":false,"summary":"JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request","aliases":["BIT-jupyterlab-2026-42266","CVE-2026-42266","PYSEC-2026-164"],"sourceIds":["GHSA-37w4-hwhx-4rc4","PYSEC-2026-164"],"published":"2026-05-05T20:53:18Z","modified":"2026-06-08T20:31:00.051032052Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42266"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"FIX","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyterlab/PYSEC-2026-164.yaml"},{"type":"WEB","url":"https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html"},{"type":"WEB","url":"https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations"}],"versionKeys":["pypi:jupyterlab@4.4.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-38jv-5279-wg99","slug":"ghsa-38jv-5279-wg99-c9df8f7b","dossier":true,"summary":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)","aliases":["CVE-2026-21441","PYSEC-2026-1996"],"sourceIds":["GHSA-38jv-5279-wg99","PYSEC-2026-1996"],"published":"2026-01-07T19:18:14Z","modified":"2026-07-07T17:56:31.346111893Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38jv-5279-wg99"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-3x9g-8vmp-wqvf","slug":"ghsa-3x9g-8vmp-wqvf-6d03bf5f","dossier":false,"summary":"Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient","aliases":["CVE-2026-49853","PYSEC-2026-3387"],"sourceIds":["GHSA-3x9g-8vmp-wqvf","PYSEC-2026-3387"],"published":"2026-06-15T20:20:00Z","modified":"2026-07-13T16:42:55.378655356Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3x9g-8vmp-wqvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49853"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-48p4-8xcf-vxj5","slug":"ghsa-48p4-8xcf-vxj5-13f12656","dossier":false,"summary":"urllib3 does not control redirects in browsers and Node.js","aliases":["CVE-2025-50182","PYSEC-2026-1997"],"sourceIds":["GHSA-48p4-8xcf-vxj5","PYSEC-2026-1997"],"published":"2025-06-18T17:50:11Z","modified":"2026-07-07T17:57:08.881416805Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-4c99-qj7h-p3vg","slug":"ghsa-4c99-qj7h-p3vg-9bb362f6","dossier":false,"summary":"nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames","aliases":["CVE-2026-39377","PYSEC-2026-2229"],"sourceIds":["GHSA-4c99-qj7h-p3vg","PYSEC-2026-2229"],"published":"2026-04-21T01:16:05.937Z","modified":"2026-07-13T07:26:39.970591013Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-4c99-qj7h-p3vg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39377"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.1"}],"versionKeys":["pypi:nbconvert@7.16.6"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4xh5-x5gv-qwph","slug":"ghsa-4xh5-x5gv-qwph-bdb101cb","dossier":false,"summary":"pip's fallback tar extraction doesn't check symbolic links point to extraction directory","aliases":["CVE-2025-8869","PYSEC-2026-1795"],"sourceIds":["GHSA-4xh5-x5gv-qwph","PYSEC-2026-1795"],"published":"2025-09-24T15:31:14Z","modified":"2026-07-07T17:57:29.434622137Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8869"},{"type":"WEB","url":"https://github.com/pypa/pip/pull/13550"},{"type":"FIX","url":"https://github.com/pypa/pip/commit/f2b92314da012b9fffa36b3f3e67748a37ef464a"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"},{"type":"WEB","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/IF5A3GCJY3VH7BVHJKOWOJFKTW7VFQEN"},{"type":"WEB","url":"https://pip.pypa.io/en/stable/news/#v25-2"},{"type":"PACKAGE","url":"https://pypi.org/project/pip"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4xh5-x5gv-qwph"}],"versionKeys":["pypi:pip@22.0.2","pypi:pip@25.1.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-5239-wwwm-4pmq","slug":"ghsa-5239-wwwm-4pmq-228840e4","dossier":true,"summary":"Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching","aliases":["CVE-2026-4539","PYSEC-2026-2987"],"sourceIds":["GHSA-5239-wwwm-4pmq","PYSEC-2026-2987"],"published":"2026-03-22T06:30:15Z","modified":"2026-07-13T16:42:36.989801915Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4539"},{"type":"WEB","url":"https://github.com/pygments/pygments/issues/3058"},{"type":"WEB","url":"https://github.com/pygments/pygments/pull/3064"},{"type":"WEB","url":"https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc"},{"type":"PACKAGE","url":"https://github.com/pygments/pygments"},{"type":"WEB","url":"https://github.com/pygments/pygments/releases/tag/2.20.0"},{"type":"WEB","url":"https://vuldb.com/?ctiid.352327"},{"type":"WEB","url":"https://vuldb.com/?id.352327"},{"type":"WEB","url":"https://vuldb.com/?submit.774685"},{"type":"PACKAGE","url":"https://pypi.org/project/pygments"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5239-wwwm-4pmq"}],"versionKeys":["pypi:pygments@2.19.1","pypi:pygments@2.19.2"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-537c-gmf6-5ccf","slug":"ghsa-537c-gmf6-5ccf-23a24e16","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-537c-gmf6-5ccf"],"published":"2026-06-15T20:12:27Z","modified":"2026-06-16T19:59:26.897634900Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260609.txt"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-5789-5fc7-67v3","slug":"ghsa-5789-5fc7-67v3-d09440f9","dossier":false,"summary":"Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories","aliases":["CVE-2026-35397","PYSEC-2026-68"],"sourceIds":["GHSA-5789-5fc7-67v3","PYSEC-2026-68"],"published":"2026-05-05T16:49:10Z","modified":"2026-06-06T00:30:08.780496042Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35397"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-68.yaml"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-58cw-g322-p94v","slug":"ghsa-58cw-g322-p94v-a1eee673","dossier":false,"summary":"Mistune has XSS via unescaped figclass/figwidth in Figure directive","aliases":["CVE-2026-44896","PYSEC-2026-168"],"sourceIds":["GHSA-58cw-g322-p94v","PYSEC-2026-168"],"published":"2026-05-08T23:43:12Z","modified":"2026-06-08T23:45:17.995583404Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/security/advisories/GHSA-58cw-g322-p94v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44896"},{"type":"WEB","url":"https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-168.yaml"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-58pv-8j8x-9vj2","slug":"ghsa-58pv-8j8x-9vj2-d16b4135","dossier":false,"summary":"jaraco.context Has a Path Traversal Vulnerability","aliases":["CVE-2026-23949","PYSEC-2026-1469"],"sourceIds":["GHSA-58pv-8j8x-9vj2","PYSEC-2026-1469"],"published":"2026-01-13T21:48:17Z","modified":"2026-07-07T17:57:36.346499117Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23949"},{"type":"WEB","url":"https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9"},{"type":"PACKAGE","url":"https://github.com/jaraco/jaraco.context"},{"type":"WEB","url":"https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91"},{"type":"WEB","url":"https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76"},{"type":"PACKAGE","url":"https://pypi.org/project/jaraco-context"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-58pv-8j8x-9vj2"}],"versionKeys":["pypi:jaraco-context@6.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-58qw-9mgm-455v","slug":"ghsa-58qw-9mgm-455v-d690efaf","dossier":false,"summary":"pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files","aliases":["CVE-2026-3219","PYSEC-2026-2875"],"sourceIds":["GHSA-58qw-9mgm-455v","PYSEC-2026-2875"],"published":"2026-04-20T18:31:48Z","modified":"2026-07-13T16:43:17.083270258Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3219"},{"type":"WEB","url":"https://github.com/pypa/pip/issues/13867"},{"type":"WEB","url":"https://github.com/pypa/pip/pull/13870"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"WEB","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ"},{"type":"PACKAGE","url":"https://pypi.org/project/pip"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-58qw-9mgm-455v"}],"versionKeys":["pypi:pip@22.0.2","pypi:pip@25.1.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-597g-3phw-6986","slug":"ghsa-597g-3phw-6986-6d75801e","dossier":false,"summary":"virtualenv Has TOCTOU Vulnerabilities in Directory Creation","aliases":["BIT-virtualenv-2026-22702","CVE-2026-22702","PYSEC-2026-2009"],"sourceIds":["GHSA-597g-3phw-6986","PYSEC-2026-2009"],"published":"2026-01-13T18:45:57Z","modified":"2026-07-07T17:57:28.238961214Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-597g-3phw-6986"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22702"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3013"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/dec4cec5d16edaf83a00a658f32d1e032661cebc"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-597g-3phw-6986"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-5mrq-x3x5-8v8f","slug":"ghsa-5mrq-x3x5-8v8f-c6e2734e","dossier":false,"summary":"Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart","aliases":["CVE-2026-40934","PYSEC-2026-69"],"sourceIds":["GHSA-5mrq-x3x5-8v8f","PYSEC-2026-69"],"published":"2026-05-05T17:03:24Z","modified":"2026-06-06T00:45:47.735760264Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40934"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-69.yaml"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5rjg-fvgr-3xxf","slug":"ghsa-5rjg-fvgr-3xxf-79d39e6b","dossier":false,"summary":"setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write","aliases":["BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49"],"sourceIds":["GHSA-5rjg-fvgr-3xxf","PYSEC-2025-49"],"published":"2025-05-17T16:15:19Z","modified":"2026-05-11T00:26:34.671259971Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273"},{"type":"REPORT","url":"https://github.com/pypa/setuptools/issues/4946"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@75.8.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5wmx-573v-2qwq","slug":"ghsa-5wmx-573v-2qwq-3c948197","dossier":false,"summary":"Python-Markdown has an Uncaught Exception","aliases":["CVE-2025-69534","PYSEC-2026-89"],"sourceIds":["GHSA-5wmx-573v-2qwq","PYSEC-2026-89"],"published":"2026-03-05T15:16:11.243Z","modified":"2026-06-10T17:02:03.742572395Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534"},{"type":"REPORT","url":"https://github.com/Python-Markdown/markdown/issues/1534"},{"type":"WEB","url":"https://github.com/Python-Markdown/markdown/pull/1535"},{"type":"PACKAGE","url":"https://github.com/Python-Markdown/markdown"},{"type":"WEB","url":"https://github.com/Python-Markdown/markdown/actions/runs/15736122892"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/markdown/PYSEC-2026-89.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5wmx-573v-2qwq"}],"versionKeys":["pypi:markdown@3.8"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5xmw-vc9v-4wf2","slug":"ghsa-5xmw-vc9v-4wf2-86a8861a","dossier":false,"summary":"Pillow has a heap buffer overflow with nested list coordinates","aliases":["BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251"],"sourceIds":["GHSA-5xmw-vc9v-4wf2","PYSEC-2026-2251"],"published":"2026-05-04T20:18:27Z","modified":"2026-07-13T07:26:28.768890335Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5xmw-vc9v-4wf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42309"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-07-08T17:45:15.021597323Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7"],"packageCount":1,"repositoryCount":17},{"id":"GHSA-68rp-wp8r-4726","slug":"ghsa-68rp-wp8r-4726-c59718b4","dossier":false,"summary":"Flask session does not add `Vary: Cookie` header when accessed in some ways","aliases":["CVE-2026-27205","PYSEC-2026-2151"],"sourceIds":["GHSA-68rp-wp8r-4726","PYSEC-2026-2151"],"published":"2026-02-19T20:45:41Z","modified":"2026-07-13T07:26:21.445447696Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27205"},{"type":"FIX","url":"https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4"},{"type":"PACKAGE","url":"https://github.com/pallets/flask"},{"type":"ADVISORY","url":"https://github.com/pallets/flask/releases/tag/3.1.3"}],"versionKeys":["pypi:flask@3.0.2","pypi:flask@3.0.3","pypi:flask@3.1.1","pypi:flask@3.1.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-6v7p-g79w-8964","slug":"ghsa-6v7p-g79w-8964-7ab8b488","dossier":false,"summary":"MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error","aliases":["CVE-2026-57585"],"sourceIds":["GHSA-6v7p-g79w-8964"],"published":"2026-06-19T21:42:55Z","modified":"2026-07-08T08:26:50.587609817Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"},{"type":"WEB","url":"https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d"},{"type":"PACKAGE","url":"https://github.com/msgpack/msgpack-python"},{"type":"WEB","url":"https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1"}],"versionKeys":["pypi:msgpack@1.1.0","pypi:msgpack@1.1.1","pypi:msgpack@1.1.2"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-6vgw-5pg2-w6jp","slug":"ghsa-6vgw-5pg2-w6jp-57c7d3f5","dossier":false,"summary":"pip Path Traversal vulnerability","aliases":["CVE-2026-1703","PYSEC-2026-1796"],"sourceIds":["GHSA-6vgw-5pg2-w6jp","PYSEC-2026-1796"],"published":"2026-02-02T15:30:34Z","modified":"2026-07-07T17:56:16.480954738Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1703"},{"type":"WEB","url":"https://github.com/pypa/pip/pull/13777"},{"type":"WEB","url":"https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"WEB","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ"},{"type":"PACKAGE","url":"https://pypi.org/project/pip"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6vgw-5pg2-w6jp"}],"versionKeys":["pypi:pip@22.0.2","pypi:pip@25.1.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6w46-j5rx-g56g","slug":"ghsa-6w46-j5rx-g56g-5324d549","dossier":false,"summary":"pytest has vulnerable tmpdir handling","aliases":["CVE-2025-71176","PYSEC-2026-1845"],"sourceIds":["GHSA-6w46-j5rx-g56g","PYSEC-2026-1845"],"published":"2026-01-22T06:30:29Z","modified":"2026-07-07T17:56:26.471696626Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71176"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/issues/13669"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/pull/14343"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/commit/95d8423bd24992deea5b9df32555fa1741679e2c"},{"type":"PACKAGE","url":"https://github.com/pytest-dev/pytes"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/releases/tag/9.0.3"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/01/21/5"},{"type":"PACKAGE","url":"https://pypi.org/project/pytest"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6w46-j5rx-g56g"}],"versionKeys":["pypi:pytest@7.2.2","pypi:pytest@7.4.4","pypi:pytest@8.3.2","pypi:pytest@9.0.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-73h3-mf4w-8647","slug":"ghsa-73h3-mf4w-8647-540f9fd2","dossier":false,"summary":"Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4","aliases":["CVE-2026-41140","PYSEC-2026-2890"],"sourceIds":["GHSA-73h3-mf4w-8647","PYSEC-2026-2890"],"published":"2026-04-22T14:35:30Z","modified":"2026-07-13T16:42:25.945183494Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/python-poetry/poetry/security/advisories/GHSA-73h3-mf4w-8647"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41140"},{"type":"PACKAGE","url":"https://github.com/python-poetry/poetry"},{"type":"WEB","url":"https://github.com/python-poetry/poetry/releases/tag/2.3.4"},{"type":"PACKAGE","url":"https://pypi.org/project/poetry"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-73h3-mf4w-8647"}],"versionKeys":["pypi:poetry@2.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-768j-98cg-p3fv","slug":"ghsa-768j-98cg-p3fv-0815ff07","dossier":false,"summary":"fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib","aliases":["CVE-2025-66034","PYSEC-2026-1389"],"sourceIds":["GHSA-768j-98cg-p3fv","PYSEC-2026-1389"],"published":"2025-12-01T19:07:00Z","modified":"2026-07-07T17:57:24.966058048Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/fonttools/fonttools/security/advisories/GHSA-768j-98cg-p3fv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66034"},{"type":"WEB","url":"https://github.com/fonttools/fonttools/commit/a696d5ba93270d5954f98e7cab5ddca8a02c1e32"},{"type":"PACKAGE","url":"https://github.com/fonttools/fonttools"},{"type":"PACKAGE","url":"https://pypi.org/project/fonttools"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-768j-98cg-p3fv"}],"versionKeys":["pypi:fonttools@4.55.3","pypi:fonttools@4.57.0","pypi:fonttools@4.58.0","pypi:fonttools@4.58.5","pypi:fonttools@4.59.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-78cv-mqj4-43f7","slug":"ghsa-78cv-mqj4-43f7-2021f695","dossier":false,"summary":"Tornado has incomplete validation of cookie attributes","aliases":["CVE-2026-35536","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287"],"sourceIds":["GHSA-78cv-mqj4-43f7","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287"],"published":"2026-03-11T22:17:00Z","modified":"2026-07-13T16:45:06.531920939Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35536"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fqwm-6jpj-5wxc"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-79v4-65xg-pq4g","slug":"ghsa-79v4-65xg-pq4g-b911b371","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":["CVE-2024-12797","PYSEC-2026-1284"],"sourceIds":["GHSA-79v4-65xg-pq4g","PYSEC-2026-1284"],"published":"2025-02-11T18:06:42Z","modified":"2026-07-07T17:57:01.916729628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12797"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20250211.txt"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-79v4-65xg-pq4g"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7cx3-6m66-7c5m","slug":"ghsa-7cx3-6m66-7c5m-cde5125c","dossier":false,"summary":"Tornado vulnerable to excessive logging caused by malformed multipart form data","aliases":["CVE-2025-47287","PYSEC-2026-1974"],"sourceIds":["GHSA-7cx3-6m66-7c5m","PYSEC-2026-1974"],"published":"2025-05-16T14:12:40Z","modified":"2026-07-07T17:56:45.268719923Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47287"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7cx3-6m66-7c5m"}],"versionKeys":["pypi:tornado@6.4.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-7jqv-fw35-gmx9","slug":"ghsa-7jqv-fw35-gmx9-d6bf4abd","dossier":false,"summary":"nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding","aliases":["CVE-2026-39378","PYSEC-2026-2230"],"sourceIds":["GHSA-7jqv-fw35-gmx9","PYSEC-2026-2230"],"published":"2026-04-21T01:16:06.073Z","modified":"2026-07-13T07:26:18.607056830Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-7jqv-fw35-gmx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39378"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.1"}],"versionKeys":["pypi:nbconvert@7.16.6"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-836r-79rf-4m37","slug":"ghsa-836r-79rf-4m37-54a23e8e","dossier":false,"summary":"Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser","aliases":["CVE-2026-49477","PYSEC-2026-3072"],"sourceIds":["GHSA-836r-79rf-4m37","PYSEC-2026-3072"],"published":"2026-07-09T13:37:46Z","modified":"2026-07-13T16:42:45.934231028Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37"},{"type":"PACKAGE","url":"https://github.com/facelessuser/soupsieve"},{"type":"PACKAGE","url":"https://pypi.org/project/soupsieve"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-836r-79rf-4m37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49477"}],"versionKeys":["pypi:soupsieve@2.6","pypi:soupsieve@2.7","pypi:soupsieve@2.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-87hc-h4r5-73f7","slug":"ghsa-87hc-h4r5-73f7-c5117ca2","dossier":false,"summary":"Werkzeug safe_join() allows Windows special device names with compound extensions","aliases":["CVE-2026-21860","PYSEC-2026-2044"],"sourceIds":["GHSA-87hc-h4r5-73f7","PYSEC-2026-2044"],"published":"2026-01-08T19:51:21Z","modified":"2026-07-07T17:56:19.044748151Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-87hc-h4r5-73f7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21860"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/7ae1d254e04a0c33e241ac1cca4783ce6c875ca3"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-87hc-h4r5-73f7"}],"versionKeys":["pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-897w-fcg9-f6xj","slug":"ghsa-897w-fcg9-f6xj-5f2cb719","dossier":false,"summary":"Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows","aliases":["CVE-2026-42305","PYSEC-2026-2463"],"sourceIds":["GHSA-897w-fcg9-f6xj","PYSEC-2026-2463"],"published":"2026-05-28T22:28:06Z","modified":"2026-07-13T16:42:38.959600273Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-897w-fcg9-f6xj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42305"},{"type":"WEB","url":"https://github.com/jelmer/dulwich/commit/49eb56e51aad637fc23d54bf2a08cb42739b8290"},{"type":"WEB","url":"https://github.com/jelmer/dulwich/commit/57efc4aa1581e038915a0fd79365be53b150f4a9"},{"type":"PACKAGE","url":"https://github.com/jelmer/dulwich"},{"type":"WEB","url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.5"},{"type":"PACKAGE","url":"https://pypi.org/project/dulwich"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-897w-fcg9-f6xj"}],"versionKeys":["pypi:dulwich@0.22.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8g87-j6q8-g93x","slug":"ghsa-8g87-j6q8-g93x-2e837b39","dossier":false,"summary":"Mistune Math Plugin has an XSS Escape Bypass","aliases":["CVE-2026-44708","PYSEC-2026-2206"],"sourceIds":["GHSA-8g87-j6q8-g93x","PYSEC-2026-2206"],"published":"2026-05-08T23:40:04Z","modified":"2026-07-13T07:26:26.365066334Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8g87-j6q8-g93x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44708"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8mp2-v27r-99xp","slug":"ghsa-8mp2-v27r-99xp-3e3baa33","dossier":false,"summary":"Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input","aliases":["CVE-2026-33079","PYSEC-2026-2651"],"sourceIds":["GHSA-8mp2-v27r-99xp","PYSEC-2026-2651"],"published":"2026-05-06T16:52:43Z","modified":"2026-07-13T16:42:39.431792280Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8mp2-v27r-99xp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33079"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://github.com/lepture/mistune/blob/df23edd60b43b639d2e6760ef9dd3d618aa11c21/src/mistune/helpers.py#L20-L25"},{"type":"PACKAGE","url":"https://pypi.org/project/mistune"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8mp2-v27r-99xp"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-8rfp-98v4-mmr6","slug":"ghsa-8rfp-98v4-mmr6-7ea7e5dd","dossier":false,"summary":"Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output","aliases":[],"sourceIds":["GHSA-8rfp-98v4-mmr6"],"published":"2026-06-16T14:06:29Z","modified":"2026-06-18T13:29:27.505774604Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/mozilla/bleach/security/advisories/GHSA-8rfp-98v4-mmr6"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2023812"},{"type":"PACKAGE","url":"https://github.com/mozilla/bleach"}],"versionKeys":["pypi:bleach@6.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-983w-rhvv-gwmv","slug":"ghsa-983w-rhvv-gwmv-c6b60e52","dossier":false,"summary":"WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect","aliases":["CVE-2025-68616","PYSEC-2026-2034"],"sourceIds":["GHSA-983w-rhvv-gwmv","PYSEC-2026-2034"],"published":"2026-01-20T16:29:53Z","modified":"2026-07-07T17:57:32.367800639Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-983w-rhvv-gwmv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68616"},{"type":"WEB","url":"https://github.com/Kozea/WeasyPrint/commit/b6a14f0f3f4ce9c0c75c1a2d73cb1c5d43f0e565"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-68616"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2430858"},{"type":"PACKAGE","url":"https://github.com/Kozea/WeasyPrint"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68616.json"},{"type":"PACKAGE","url":"https://pypi.org/project/weasyprint"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-983w-rhvv-gwmv"}],"versionKeys":["pypi:weasyprint@64.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9hjg-9r4m-mvj7","slug":"ghsa-9hjg-9r4m-mvj7-32d7b63e","dossier":false,"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"sourceIds":["GHSA-9hjg-9r4m-mvj7","PYSEC-2026-1872"],"published":"2025-06-09T19:06:08Z","modified":"2026-07-07T17:56:56.234172558Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6965"},{"type":"FIX","url":"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2025/Jun/2"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-9q39-rmj3-p4r2","slug":"ghsa-9q39-rmj3-p4r2-67d5744e","dossier":false,"summary":"HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering","aliases":["BIT-jupyter-base-notebook-2024-43805","BIT-jupyter-notebook-2024-43805","BIT-jupyterlab-2024-43805","CVE-2024-43805","PYSEC-2026-1481","PYSEC-2026-2536"],"sourceIds":["GHSA-9q39-rmj3-p4r2","PYSEC-2026-1481"],"published":"2024-08-29T17:55:53Z","modified":"2026-07-13T16:43:05.974128183Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43805"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/06ad9de836f155add7d3d651ef936cc4c5ea8093"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/88e24baac551196f9cb3de16bd060a7ab1597674"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9q39-rmj3-p4r2"}],"versionKeys":["pypi:notebook@7.0.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9wx4-h78v-vm56","slug":"ghsa-9wx4-h78v-vm56-6a334c57","dossier":false,"summary":"Requests `Session` object does not verify requests after making first request with verify=False","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"sourceIds":["GHSA-9wx4-h78v-vm56","PYSEC-2026-1873"],"published":"2024-05-20T20:15:00Z","modified":"2026-07-07T17:57:17.012984050Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6655"},{"type":"FIX","url":"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wx4-h78v-vm56"}],"versionKeys":["pypi:requests@2.31.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-cfh3-3jmp-rvhc","slug":"ghsa-cfh3-3jmp-rvhc-4e95572c","dossier":false,"summary":"Pillow affected by out-of-bounds write when loading PSD images","aliases":["BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249"],"sourceIds":["GHSA-cfh3-3jmp-rvhc","PYSEC-2026-2249"],"published":"2026-02-11T14:22:50Z","modified":"2026-07-13T07:26:49.514806069Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25990"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9427"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-25990"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14873"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14874"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:28385"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4128"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4942"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-cpwx-vrp4-4pq7","slug":"ghsa-cpwx-vrp4-4pq7-799bdc98","dossier":false,"summary":"Jinja2 vulnerable to sandbox breakout through attr filter selecting format method","aliases":["CVE-2025-27516","PYSEC-2026-1471"],"sourceIds":["GHSA-cpwx-vrp4-4pq7","PYSEC-2026-1471"],"published":"2025-03-05T20:40:14Z","modified":"2026-07-07T17:56:16.836141266Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-cpwx-vrp4-4pq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27516"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/90457bbf33b8662926ae65cdde4c4c32e756e403"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00045.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cpwx-vrp4-4pq7"}],"versionKeys":["pypi:jinja2@3.1.3","pypi:jinja2@3.1.5"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cx3h-4qpv-8hc9","slug":"ghsa-cx3h-4qpv-8hc9-3078b6fa","dossier":false,"summary":"Tornado has out-of-bounds memory access via C extension","aliases":["CVE-2026-49854","PYSEC-2026-3388"],"sourceIds":["GHSA-cx3h-4qpv-8hc9","PYSEC-2026-3388"],"published":"2026-06-12T18:30:19Z","modified":"2026-07-13T16:43:34.663472817Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.6"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx3h-4qpv-8hc9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49854"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-cx63-2mw6-8hw5","slug":"ghsa-cx63-2mw6-8hw5-1754ad59","dossier":false,"summary":"setuptools vulnerable to Command Injection via package URL","aliases":["BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918"],"sourceIds":["GHSA-cx63-2mw6-8hw5","PYSEC-2026-1918"],"published":"2024-07-15T03:30:57Z","modified":"2026-07-07T17:57:13.326243614Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6345"},{"type":"WEB","url":"https://github.com/pypa/setuptools/pull/4332"},{"type":"WEB","url":"https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html"},{"type":"PACKAGE","url":"https://pypi.org/project/setuptools"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx63-2mw6-8hw5"}],"versionKeys":["pypi:setuptools@69.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f9vj-2wh5-fj8j","slug":"ghsa-f9vj-2wh5-fj8j-f0f29e2a","dossier":false,"summary":"Werkzeug safe_join not safe on Windows","aliases":["CVE-2024-49766","PYSEC-2026-2045"],"sourceIds":["GHSA-f9vj-2wh5-fj8j","PYSEC-2026-2045"],"published":"2024-10-25T19:43:41Z","modified":"2026-07-07T17:56:25.762524663Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-f9vj-2wh5-fj8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49766"},{"type":"FIX","url":"https://github.com/pallets/werkzeug/commit/2767bcb10a7dd1c297d812cc5e6d11a474c1f092"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.0.6"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250131-0005"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f9vj-2wh5-fj8j"}],"versionKeys":["pypi:werkzeug@3.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fcw5-x6j4-ccmp","slug":"ghsa-fcw5-x6j4-ccmp-6b9a05f5","dossier":false,"summary":"Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP","aliases":["CVE-2026-44727","PYSEC-2026-366"],"sourceIds":["GHSA-fcw5-x6j4-ccmp","PYSEC-2026-366"],"published":"2026-06-18T15:04:07Z","modified":"2026-07-18T17:30:29.202052826Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44727"},{"type":"WEB","url":"https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-44727"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491516"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fcw5-x6j4-ccmp"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-366.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-server"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44727.json"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gc5v-m9x4-r6x2","slug":"ghsa-gc5v-m9x4-r6x2-b9828ad8","dossier":true,"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"sourceIds":["GHSA-gc5v-m9x4-r6x2","PYSEC-2026-2275"],"published":"2026-03-25T16:56:28Z","modified":"2026-07-13T07:26:34.091663004Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645"},{"type":"FIX","url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"ADVISORY","url":"https://github.com/psf/requests/releases/tag/v2.33.0"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3","pypi:requests@2.32.4","pypi:requests@2.32.5"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-gf7q-q4j7-hp7c","slug":"ghsa-gf7q-q4j7-hp7c-0edc7a7a","dossier":false,"summary":"Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()","aliases":["CVE-2026-5422","PYSEC-2026-2532"],"sourceIds":["GHSA-gf7q-q4j7-hp7c","PYSEC-2026-2532"],"published":"2026-06-02T12:31:26Z","modified":"2026-07-13T16:43:48.932414937Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5422"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://huntr.com/bounties/24a36953-6490-466f-8cb2-a90d1ca56e0f"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-server"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gf7q-q4j7-hp7c"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gj48-438w-jh9v","slug":"ghsa-gj48-438w-jh9v-02216692","dossier":false,"summary":"Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes","aliases":[],"sourceIds":["GHSA-gj48-438w-jh9v"],"published":"2026-06-16T14:07:49Z","modified":"2026-06-18T18:29:26.517334064Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/mozilla/bleach/security/advisories/GHSA-gj48-438w-jh9v"},{"type":"PACKAGE","url":"https://github.com/mozilla/bleach"},{"type":"WEB","url":"https://github.com/mozilla/bleach/releases/tag/v6.4.0"}],"versionKeys":["pypi:bleach@6.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gm62-xv2j-4w53","slug":"ghsa-gm62-xv2j-4w53-5befa184","dossier":true,"summary":"urllib3 allows an unbounded number of links in the decompression chain","aliases":["CVE-2025-66418","PYSEC-2026-1998"],"sourceIds":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"published":"2025-12-05T18:15:19Z","modified":"2026-07-07T17:57:28.931610368Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm62-xv2j-4w53"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-gmj6-6f8f-6699","slug":"ghsa-gmj6-6f8f-6699-e3e02f35","dossier":false,"summary":"Jinja has a sandbox breakout through malicious filenames","aliases":["CVE-2024-56201","PYSEC-2026-1472"],"sourceIds":["GHSA-gmj6-6f8f-6699","PYSEC-2026-1472"],"published":"2024-12-23T17:54:12Z","modified":"2026-07-07T17:56:55.074166933Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-gmj6-6f8f-6699"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56201"},{"type":"WEB","url":"https://github.com/pallets/jinja/issues/1792"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/767b23617628419ae3709ccfb02f9602ae9fe51f"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gmj6-6f8f-6699"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h4gh-qq45-vh27","slug":"ghsa-h4gh-qq45-vh27-43490265","dossier":false,"summary":"pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-h4gh-qq45-vh27"],"published":"2024-09-03T21:59:48Z","modified":"2026-02-04T03:06:49.280647Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20240903.txt"}],"versionKeys":["pypi:cryptography@42.0.8"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h75v-3vvj-5mfj","slug":"ghsa-h75v-3vvj-5mfj-d8fc6bb7","dossier":false,"summary":"Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter","aliases":["CVE-2024-34064","PYSEC-2026-1474"],"sourceIds":["GHSA-h75v-3vvj-5mfj","PYSEC-2026-1474"],"published":"2024-05-06T14:20:59Z","modified":"2026-07-07T17:57:30.872296178Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34064"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h75v-3vvj-5mfj"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-hgf8-39gv-g3f2","slug":"ghsa-hgf8-39gv-g3f2-0469b394","dossier":false,"summary":"Werkzeug safe_join() allows Windows special device names","aliases":["CVE-2025-66221","PYSEC-2026-2046"],"sourceIds":["GHSA-hgf8-39gv-g3f2","PYSEC-2026-2046"],"published":"2025-12-02T00:27:38Z","modified":"2026-07-07T17:57:36.044527736Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-hgf8-39gv-g3f2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66221"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/4b833376a45c323a189cd11d2362bcffdb1c0c13"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.1.4"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hgf8-39gv-g3f2"}],"versionKeys":["pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-jhhc-3hcp-qhm5","slug":"ghsa-jhhc-3hcp-qhm5-310e06ea","dossier":false,"summary":"WeasyPrint has CSS Injection via Presentational Hints","aliases":["CVE-2026-49452","PYSEC-2026-3412"],"sourceIds":["GHSA-jhhc-3hcp-qhm5","PYSEC-2026-3412"],"published":"2026-07-06T17:29:53Z","modified":"2026-07-13T16:42:26.449768536Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jhhc-3hcp-qhm5"},{"type":"PACKAGE","url":"https://github.com/Kozea/WeasyPrint"},{"type":"PACKAGE","url":"https://pypi.org/project/weasyprint"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jhhc-3hcp-qhm5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49452"}],"versionKeys":["pypi:weasyprint@64.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jp4c-xjxw-mgf9","slug":"ghsa-jp4c-xjxw-mgf9-e780c8d6","dossier":false,"summary":"pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere","aliases":["CVE-2026-6357","PYSEC-2026-2876"],"sourceIds":["GHSA-jp4c-xjxw-mgf9","PYSEC-2026-2876"],"published":"2026-04-27T15:30:52Z","modified":"2026-07-13T16:43:01.316339792Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357"},{"type":"WEB","url":"https://github.com/pypa/pip/pull/13923"},{"type":"WEB","url":"https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"WEB","url":"https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes"},{"type":"PACKAGE","url":"https://pypi.org/project/pip"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jp4c-xjxw-mgf9"}],"versionKeys":["pypi:pip@22.0.2","pypi:pip@25.1.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-m959-cc7f-wv43","slug":"ghsa-m959-cc7f-wv43-3b497c67","dossier":false,"summary":"cryptography has incomplete DNS name constraint enforcement on peer names","aliases":["CVE-2026-34073","PYSEC-2026-35"],"sourceIds":["GHSA-m959-cc7f-wv43","PYSEC-2026-35"],"published":"2026-03-27T19:56:21Z","modified":"2026-06-05T18:00:13.915417385Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34073"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-35.yaml"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mf9v-mfxr-j63j","slug":"ghsa-mf9v-mfxr-j63j-1a7db6d4","dossier":false,"summary":"urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API","aliases":["CVE-2026-44432","PYSEC-2026-142"],"sourceIds":["GHSA-mf9v-mfxr-j63j","PYSEC-2026-142"],"published":"2026-05-11T14:51:45Z","modified":"2026-06-08T20:00:12.284378628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mgf9-4vpg-hj56","slug":"ghsa-mgf9-4vpg-hj56-00729355","dossier":false,"summary":"tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)","aliases":["CVE-2026-49855","PYSEC-2026-3389"],"sourceIds":["GHSA-mgf9-4vpg-hj56","PYSEC-2026-3389"],"published":"2026-06-15T20:19:28Z","modified":"2026-07-13T16:43:27.241564365Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mgf9-4vpg-hj56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49855"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-mq26-g339-26xf","slug":"ghsa-mq26-g339-26xf-ed024c7e","dossier":false,"summary":"Command Injection in pip when used with Mercurial","aliases":["CVE-2023-5752","PYSEC-2023-228"],"sourceIds":["GHSA-mq26-g339-26xf","PYSEC-2023-228"],"published":"2023-10-25T18:17:00Z","modified":"2026-06-10T17:01:27.606909654Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5752"},{"type":"FIX","url":"https://github.com/pypa/pip/pull/12306"},{"type":"WEB","url":"https://github.com/pypa/pip/commit/389cb799d0da9a840749fcd14878928467ed49b4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2023-228.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/622OZXWG72ISQPLM5Y57YCVIMWHD4C3U"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXUVMJM25PUAZRQZBF54OFVKTY3MINPW"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ"},{"type":"WEB","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL"},{"type":"ADVISORY","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mq26-g339-26xf"}],"versionKeys":["pypi:pip@22.0.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-mqcg-5x36-vfcg","slug":"ghsa-mqcg-5x36-vfcg-bd7ad531","dossier":false,"summary":"JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content","aliases":["BIT-jupyter-base-notebook-2026-42557","BIT-jupyter-notebook-2026-42557","BIT-jupyterlab-2026-42557","CVE-2026-42557","PYSEC-2026-2537","PYSEC-2026-2681"],"sourceIds":["GHSA-mqcg-5x36-vfcg","PYSEC-2026-2537","PYSEC-2026-2681"],"published":"2026-05-06T21:43:44Z","modified":"2026-07-13T16:43:04.081738235Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42557"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-files"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqcg-5x36-vfcg"},{"type":"PACKAGE","url":"https://pypi.org/project/notebook"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:notebook@7.0.7"],"packageCount":2,"repositoryCount":1},{"id":"GHSA-p423-j2cm-9vmq","slug":"ghsa-p423-j2cm-9vmq-1455bc4c","dossier":false,"summary":"Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs","aliases":["CVE-2026-39892","PYSEC-2026-36"],"sourceIds":["GHSA-p423-j2cm-9vmq","PYSEC-2026-36"],"published":"2026-04-08T19:23:08Z","modified":"2026-06-05T18:00:15.295914184Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39892"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml"}],"versionKeys":["pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-pq67-6m6q-mj2v","slug":"ghsa-pq67-6m6q-mj2v-3522d1d4","dossier":false,"summary":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","aliases":["CVE-2025-50181","PYSEC-2026-1999"],"sourceIds":["GHSA-pq67-6m6q-mj2v","PYSEC-2026-1999"],"published":"2025-06-18T17:50:00Z","modified":"2026-07-07T17:56:41.872294653Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-pw6j-qg29-8w7f","slug":"ghsa-pw6j-qg29-8w7f-fb4d7ed6","dossier":false,"summary":"Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse","aliases":[],"sourceIds":["GHSA-pw6j-qg29-8w7f"],"published":"2026-06-15T20:37:24Z","modified":"2026-06-16T22:59:25.768721886Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-pwv6-vv43-88gr","slug":"ghsa-pwv6-vv43-88gr-c5f811d0","dossier":true,"summary":"Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)","aliases":["BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252"],"sourceIds":["GHSA-pwv6-vv43-88gr","PYSEC-2026-2252"],"published":"2026-05-04T20:20:31Z","modified":"2026-07-13T07:26:52.198871129Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42311"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9520"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-q2x7-8rv6-6q7h","slug":"ghsa-q2x7-8rv6-6q7h-1113a288","dossier":false,"summary":"Jinja has a sandbox breakout through indirect reference to format method","aliases":["CVE-2024-56326","PYSEC-2026-1475"],"sourceIds":["GHSA-q2x7-8rv6-6q7h","PYSEC-2026-1475"],"published":"2024-12-23T17:56:08Z","modified":"2026-07-07T17:56:44.376174317Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56326"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2x7-8rv6-6q7h"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-q34m-jh98-gwm2","slug":"ghsa-q34m-jh98-gwm2-76f8ef0b","dossier":false,"summary":"Werkzeug possible resource exhaustion when parsing file data in forms","aliases":["CVE-2024-49767","PYSEC-2026-1860","PYSEC-2026-3417"],"sourceIds":["GHSA-q34m-jh98-gwm2","PYSEC-2026-3417"],"published":"2024-10-25T19:44:43Z","modified":"2026-07-13T16:43:34.482065524Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49767"},{"type":"WEB","url":"https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee"},{"type":"WEB","url":"https://github.com/pallets/quart/commit/abb04a512496206de279225340ed022852fbf51f"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/50cfeebcb0727e18cc52ffbeb125f4a66551179b"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/cbb446fdcada7685fce936ded01b76c08dbd6eb5"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.0.6"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250103-0007"},{"type":"PACKAGE","url":"https://pypi.org/project/werkzeug"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q34m-jh98-gwm2"}],"versionKeys":["pypi:werkzeug@3.0.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qccp-gfcp-xxvc","slug":"ghsa-qccp-gfcp-xxvc-0d988969","dossier":true,"summary":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects","aliases":["CVE-2026-44431","PYSEC-2026-141"],"sourceIds":["GHSA-qccp-gfcp-xxvc","PYSEC-2026-141"],"published":"2026-05-11T14:51:20Z","modified":"2026-05-20T09:19:20.983812Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-qcq2-496w-v96p","slug":"ghsa-qcq2-496w-v96p-f873dd58","dossier":false,"summary":"Mistune: Potential DoS via quadratic-time parsing in parse_link_text","aliases":["CVE-2026-49851","PYSEC-2026-2652"],"sourceIds":["GHSA-qcq2-496w-v96p","PYSEC-2026-2652"],"published":"2026-07-09T23:52:27Z","modified":"2026-07-13T16:42:54.588302008Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49851"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-49851"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492304"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49851.json"},{"type":"PACKAGE","url":"https://pypi.org/project/mistune"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qcq2-496w-v96p"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qh7q-6qm3-653w","slug":"ghsa-qh7q-6qm3-653w-ce7f1a0b","dossier":false,"summary":"Jupyter Server has an open redirection vulnerability in `next` query parameter","aliases":["CVE-2025-61669","PYSEC-2026-67"],"sourceIds":["GHSA-qh7q-6qm3-653w","PYSEC-2026-67"],"published":"2026-05-05T16:16:10.133Z","modified":"2026-06-05T18:00:15.359519984Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-qh7q-6qm3-653w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61669"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-67.yaml"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qjxf-f2mg-c6mc","slug":"ghsa-qjxf-f2mg-c6mc-58d52008","dossier":false,"summary":"Tornado is vulnerable to DoS due to too many multipart parts","aliases":["CVE-2026-31958","PYSEC-2026-140"],"sourceIds":["GHSA-qjxf-f2mg-c6mc","PYSEC-2026-140"],"published":"2026-03-11T20:16:16.617Z","modified":"2026-06-08T20:00:14.385003861Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31958"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-qmgc-5h2g-mvrw","slug":"ghsa-qmgc-5h2g-mvrw-199eacc8","dossier":false,"summary":"filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock","aliases":["CVE-2026-22701","PYSEC-2026-1374"],"sourceIds":["GHSA-qmgc-5h2g-mvrw","PYSEC-2026-1374"],"published":"2026-01-13T18:44:55Z","modified":"2026-07-07T17:56:19.485233787Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22701"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qmgc-5h2g-mvrw"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-r6ph-v2qm-q3c2","slug":"ghsa-r6ph-v2qm-q3c2-c75907df","dossier":false,"summary":"cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves","aliases":["CVE-2026-26007","PYSEC-2026-2141"],"sourceIds":["GHSA-r6ph-v2qm-q3c2","PYSEC-2026-2141"],"published":"2026-02-10T21:27:06Z","modified":"2026-07-13T07:26:47.289183808Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26007"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pyca/cryptography/releases/tag/46.0.5"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-26007"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:12176"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13553"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13672"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19355"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21517"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22330"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22993"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2694"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-r73j-pqj5-w3x7","slug":"ghsa-r73j-pqj5-w3x7-8d4d543f","dossier":true,"summary":"Pillow has a PDF Parsing Trailer Infinite Loop (DoS)","aliases":["BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874"],"sourceIds":["GHSA-r73j-pqj5-w3x7","PYSEC-2026-2874"],"published":"2026-05-04T20:19:30Z","modified":"2026-07-13T16:42:37.358429541Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-r73j-pqj5-w3x7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42310"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9519"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3bf614e4b8615d0ce1d5039efaf6db447fe7c468"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r73j-pqj5-w3x7"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-rch3-82jr-f9w9","slug":"ghsa-rch3-82jr-f9w9-c220441f","dossier":false,"summary":"Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS","aliases":["BIT-jupyter-base-notebook-2026-40171","BIT-jupyter-notebook-2026-40171","BIT-jupyterlab-2026-40171","CVE-2026-40171","PYSEC-2026-2538","PYSEC-2026-2682"],"sourceIds":["GHSA-rch3-82jr-f9w9","PYSEC-2026-2538","PYSEC-2026-2682"],"published":"2026-04-30T17:25:47Z","modified":"2026-07-13T16:42:47.886298772Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40171"},{"type":"PACKAGE","url":"https://github.com/jupyter/notebook"},{"type":"WEB","url":"https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rch3-82jr-f9w9"},{"type":"PACKAGE","url":"https://pypi.org/project/notebook"}],"versionKeys":["pypi:jupyterlab@4.4.0","pypi:notebook@7.0.7"],"packageCount":2,"repositoryCount":1},{"id":"GHSA-rgxp-2hwp-jwgg","slug":"ghsa-rgxp-2hwp-jwgg-76cdda06","dossier":false,"summary":"Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering","aliases":["CVE-2026-25087","PYSEC-2026-113"],"sourceIds":["GHSA-rgxp-2hwp-jwgg","PYSEC-2026-113"],"published":"2026-02-17T14:16:01.947Z","modified":"2026-06-12T10:29:15.451071539Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25087"},{"type":"FIX","url":"https://github.com/apache/arrow/pull/48925"},{"type":"PACKAGE","url":"https://github.com/apache/arrow"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyarrow/PYSEC-2026-113.yaml"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/mpm4ld1qony30tchfpjtk5b11tcyvmwh"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rgxp-2hwp-jwgg"}],"versionKeys":["pypi:pyarrow@18.1.0","pypi:pyarrow@20.0.0","pypi:pyarrow@21.0.0","pypi:pyarrow@22.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-v42x-x7jp-845h","slug":"ghsa-v42x-x7jp-845h-25baa2bb","dossier":false,"summary":"jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used","aliases":["CVE-2026-6657"],"sourceIds":["GHSA-v42x-x7jp-845h"],"published":"2026-06-03T18:33:10Z","modified":"2026-07-13T18:00:23.398020678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6657"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://huntr.com/bounties/18f642db-3569-43b3-b58d-ff97be4b09d7"}],"versionKeys":["pypi:jupyter-server@2.15.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-v87v-83h2-53w7","slug":"ghsa-v87v-83h2-53w7-36afb5ef","dossier":false,"summary":"Mistune Heading ID Attribute has Injection XSS","aliases":["CVE-2026-44897","PYSEC-2026-2207"],"sourceIds":["GHSA-v87v-83h2-53w7","PYSEC-2026-2207"],"published":"2026-05-09T00:13:12Z","modified":"2026-07-13T07:26:47.040339656Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-v87v-83h2-53w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44897"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vfmq-68hx-4jfw","slug":"ghsa-vfmq-68hx-4jfw-7287cb04","dossier":false,"summary":"lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files","aliases":["CVE-2026-41066","PYSEC-2026-87"],"sourceIds":["GHSA-vfmq-68hx-4jfw","PYSEC-2026-87"],"published":"2026-04-21T20:38:44Z","modified":"2026-06-06T01:15:07.932706387Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41066"},{"type":"REPORT","url":"https://bugs.launchpad.net/lxml/+bug/2146291"},{"type":"PACKAGE","url":"https://github.com/lxml/lxml"},{"type":"WEB","url":"https://github.com/lxml/lxml/releases/tag/lxml-6.1.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/lxml/PYSEC-2026-87.yaml"}],"versionKeys":["pypi:lxml@5.3.0","pypi:lxml@5.4.0","pypi:lxml@6.0.2"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-vmhf-c436-hxj4","slug":"ghsa-vmhf-c436-hxj4-2356488f","dossier":false,"summary":"JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol","aliases":[],"sourceIds":["GHSA-vmhf-c436-hxj4"],"published":"2026-06-19T15:11:17Z","modified":"2026-06-22T18:29:21.418806301Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.9"}],"versionKeys":["pypi:jupyterlab@4.4.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vqfr-h8mv-ghfj","slug":"ghsa-vqfr-h8mv-ghfj-49515033","dossier":false,"summary":"h11 accepts some malformed Chunked-Encoding bodies","aliases":["CVE-2025-43859","PYSEC-2026-348"],"sourceIds":["GHSA-vqfr-h8mv-ghfj","PYSEC-2026-348"],"published":"2025-04-24T16:07:56Z","modified":"2026-07-01T20:22:54.082067Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43859"},{"type":"WEB","url":"https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h11"},{"type":"PACKAGE","url":"https://pypi.org/project/h11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqfr-h8mv-ghfj"}],"versionKeys":["pypi:h11@0.14.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-vvfj-2jqx-52jm","slug":"ghsa-vvfj-2jqx-52jm-5fd8a3bd","dossier":false,"summary":"JupyterLab LaTeX typesetter links did not enforce `noopener` attribute","aliases":["BIT-jupyterlab-2025-59842","CVE-2025-59842","PYSEC-2026-1482"],"sourceIds":["GHSA-vvfj-2jqx-52jm","PYSEC-2026-1482"],"published":"2025-09-26T14:26:40Z","modified":"2026-07-07T17:57:38.072715082Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vvfj-2jqx-52jm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59842"},{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/commit/88ef373039a8cc09f27d3814382a512d9033675c"},{"type":"PACKAGE","url":"https://github.com/jupyterlab/jupyterlab"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyterlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vvfj-2jqx-52jm"}],"versionKeys":["pypi:jupyterlab@4.4.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-w853-jp5j-5j7f","slug":"ghsa-w853-jp5j-5j7f-2786386f","dossier":false,"summary":"filelock has a TOCTOU race condition which allows symlink attacks during lock file creation","aliases":["CVE-2025-68146","PYSEC-2026-1375"],"sourceIds":["GHSA-w853-jp5j-5j7f","PYSEC-2026-1375"],"published":"2025-12-16T20:52:55Z","modified":"2026-07-07T17:56:10.949145470Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/releases/tag/3.20.1"},{"type":"WEB","url":"https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants"},{"type":"WEB","url":"https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w853-jp5j-5j7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68146"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-wf93-45jw-7689","slug":"ghsa-wf93-45jw-7689-98dc514d","dossier":false,"summary":"pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory","aliases":["CVE-2026-8643","PYSEC-2026-196"],"sourceIds":["GHSA-wf93-45jw-7689","PYSEC-2026-196"],"published":"2026-06-01T17:17:35.770Z","modified":"2026-07-14T02:29:29.982772188Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643"},{"type":"FIX","url":"https://github.com/pypa/pip/pull/14000"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:33313"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34776"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34777"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34778"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34780"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34891"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36193"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36315"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37283"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-8643"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2460927"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"ADVISORY","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wf93-45jw-7689"}],"versionKeys":["pypi:pip@22.0.2","pypi:pip@25.1.1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-whj4-6x5x-4v2j","slug":"ghsa-whj4-6x5x-4v2j-eb5fc6a1","dossier":true,"summary":"FITS GZIP decompression bomb in Pillow","aliases":["BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250"],"sourceIds":["GHSA-whj4-6x5x-4v2j","PYSEC-2026-2250"],"published":"2026-04-13T19:22:35Z","modified":"2026-07-13T07:26:24.246094941Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40192"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9521"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40192"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16008"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16009"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17609"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17611"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19375"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21017"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22465"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22629"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22840"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-wjx4-4jcj-g98j","slug":"ghsa-wjx4-4jcj-g98j-e937161b","dossier":true,"summary":"Pillow has an integer overflow when processing fonts","aliases":["BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165"],"sourceIds":["GHSA-wjx4-4jcj-g98j","PYSEC-2026-165"],"published":"2026-05-04T20:18:45Z","modified":"2026-06-08T23:45:16.414580348Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42308"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-xg8h-j46f-w952","slug":"ghsa-xg8h-j46f-w952-da36a616","dossier":false,"summary":"Pillow vulnerability can cause write buffer overflow on BCn encoding","aliases":["BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61"],"sourceIds":["GHSA-xg8h-j46f-w952","PYSEC-2025-61"],"published":"2025-07-01T17:29:37Z","modified":"2026-02-04T03:49:31.268130Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48379"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9041"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2025-61.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/11.3.0"}],"versionKeys":["pypi:pillow@11.2.1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-xm59-rqc7-hhvf","slug":"ghsa-xm59-rqc7-hhvf-9413791b","dossier":false,"summary":"nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows","aliases":["CVE-2025-53000","PYSEC-2026-1691"],"sourceIds":["GHSA-xm59-rqc7-hhvf","PYSEC-2026-1691"],"published":"2025-12-18T22:03:08Z","modified":"2026-07-07T17:56:11.809154672Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-xm59-rqc7-hhvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53000"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/issues/2258"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/commit/c9ac1d1040459ed1ff9eb34e9918ce5a87cf9d71"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/blob/4f61702f5c7524d8a3c4ac0d5fc33a6ac2fa36a7/nbconvert/preprocessors/svg2pdf.py#L104"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.0"},{"type":"WEB","url":"https://www.imperva.com/blog/code-execution-in-jupyter-notebook-exports"},{"type":"PACKAGE","url":"https://pypi.org/project/nbconvert"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xm59-rqc7-hhvf"}],"versionKeys":["pypi:nbconvert@7.16.6"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-xrvj-v92f-53gj","slug":"ghsa-xrvj-v92f-53gj-f104bdc0","dossier":false,"summary":"Dulwich has unbounded memory allocation in receive-pack from crafted thin packs","aliases":["CVE-2026-47734","PYSEC-2026-2466"],"sourceIds":["GHSA-xrvj-v92f-53gj","PYSEC-2026-2466"],"published":"2026-06-08T23:43:42Z","modified":"2026-07-13T16:43:32.716665118Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-xrvj-v92f-53gj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47734"},{"type":"PACKAGE","url":"https://github.com/jelmer/dulwich"},{"type":"WEB","url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.5"},{"type":"PACKAGE","url":"https://pypi.org/project/dulwich"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xrvj-v92f-53gj"}],"versionKeys":["pypi:dulwich@0.22.7"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-265","slug":"pysec-2025-265-33beac08","dossier":false,"summary":null,"aliases":["CVE-2025-67724","GHSA-pr2v-jx2c-wg9f"],"sourceIds":["PYSEC-2025-265"],"published":"2025-12-12T06:15:41.213Z","modified":"2026-07-13T07:15:44.068555841Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pr2v-jx2c-wg9f"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/9c163aebeaad9e6e7d28bac1f33580eb00b0e421"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2025-266","slug":"pysec-2025-266-c9802ae6","dossier":false,"summary":null,"aliases":["CVE-2025-67725","GHSA-c98p-7wgm-6p64"],"sourceIds":["PYSEC-2025-266"],"published":"2025-12-12T06:15:41.380Z","modified":"2026-07-13T07:15:44.064352714Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2025-267","slug":"pysec-2025-267-ca9685ba","dossier":false,"summary":null,"aliases":["CVE-2025-67726","GHSA-jhmp-mqwm-3gq8"],"sourceIds":["PYSEC-2025-267"],"published":"2025-12-12T07:15:44.920Z","modified":"2026-07-13T07:15:45.375541292Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2026-2132","slug":"pysec-2026-2132-627bf7c7","dossier":true,"summary":null,"aliases":["CVE-2026-7246","GHSA-47fr-3ffg-hgmw"],"sourceIds":["PYSEC-2026-2132"],"published":"2026-04-30T14:16:36.433Z","modified":"2026-07-13T07:15:21.899333658Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-7246"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464121"},{"type":"FIX","url":"https://github.com/pallets/click/releases/tag/8.3.3"},{"type":"EVIDENCE","url":"https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw"}],"versionKeys":["pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1"],"packageCount":1,"repositoryCount":14},{"id":"PYSEC-2026-2208","slug":"pysec-2026-2208-4dad303d","dossier":false,"summary":null,"aliases":["CVE-2026-44898","GHSA-6269-cqxg-mhhv"],"sourceIds":["PYSEC-2026-2208"],"published":"2026-05-26T21:16:39.810Z","modified":"2026-07-13T07:15:28.986856174Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-6269-cqxg-mhhv"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2209","slug":"pysec-2026-2209-f89c37e9","dossier":false,"summary":null,"aliases":["CVE-2026-44899","GHSA-ccfx-mfmx-2fx9"],"sourceIds":["PYSEC-2026-2209"],"published":"2026-05-26T21:16:39.953Z","modified":"2026-07-13T07:15:29.089597285Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-ccfx-mfmx-2fx9"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2210","slug":"pysec-2026-2210-6825f77a","dossier":false,"summary":null,"aliases":["CVE-2026-59922","GHSA-c8j7-8cv4-2xmq"],"sourceIds":["PYSEC-2026-2210"],"published":"2026-07-08T17:17:27.770Z","modified":"2026-07-13T07:15:29.086264845Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2211","slug":"pysec-2026-2211-c0889fb5","dossier":false,"summary":null,"aliases":["CVE-2026-59923","GHSA-8c25-4j27-2rv3"],"sourceIds":["PYSEC-2026-2211"],"published":"2026-07-08T17:17:27.910Z","modified":"2026-07-13T07:15:29.095933312Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2212","slug":"pysec-2026-2212-142b9deb","dossier":false,"summary":null,"aliases":["CVE-2026-59924","GHSA-r4rv-85jg-w4mf"],"sourceIds":["PYSEC-2026-2212"],"published":"2026-07-08T17:17:28.050Z","modified":"2026-07-13T07:15:18.817309011Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2213","slug":"pysec-2026-2213-b8267230","dossier":false,"summary":null,"aliases":["CVE-2026-59925","GHSA-4j32-57v6-6g45"],"sourceIds":["PYSEC-2026-2213"],"published":"2026-07-08T17:17:28.183Z","modified":"2026-07-13T07:15:18.858108495Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2214","slug":"pysec-2026-2214-d409d0d3","dossier":false,"summary":null,"aliases":["CVE-2026-59926","GHSA-g97x-gvcm-x72h"],"sourceIds":["PYSEC-2026-2214"],"published":"2026-07-08T17:17:28.323Z","modified":"2026-07-13T07:15:18.821076445Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.2.1"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/security/advisories/GHSA-g97x-gvcm-x72h"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2215","slug":"pysec-2026-2215-23fde122","dossier":false,"summary":null,"aliases":["CVE-2026-59927","GHSA-8mpj-m6qm-5qr8"],"sourceIds":["PYSEC-2026-2215"],"published":"2026-07-08T17:17:28.450Z","modified":"2026-07-13T07:15:18.817354531Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2216","slug":"pysec-2026-2216-99d94312","dossier":false,"summary":null,"aliases":["CVE-2026-59928","GHSA-ffq3-xpv3-j92q"],"sourceIds":["PYSEC-2026-2216"],"published":"2026-07-08T17:17:28.600Z","modified":"2026-07-13T07:15:18.812243616Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2217","slug":"pysec-2026-2217-8c4b6b66","dossier":false,"summary":null,"aliases":["CVE-2026-59929","GHSA-qfrw-5rxm-mhh2"],"sourceIds":["PYSEC-2026-2217"],"published":"2026-07-08T17:17:28.737Z","modified":"2026-07-13T07:15:18.820531742Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-qfrw-5rxm-mhh2"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2218","slug":"pysec-2026-2218-9cd796f8","dossier":false,"summary":null,"aliases":["CVE-2026-59930","GHSA-2hm2-hc3v-44h9"],"sourceIds":["PYSEC-2026-2218"],"published":"2026-07-08T17:17:28.867Z","modified":"2026-07-13T07:15:18.864143856Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b"},{"type":"EVIDENCE","url":"https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9"}],"versionKeys":["pypi:mistune@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2026-2253","slug":"pysec-2026-2253-e1ccf3df","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-54059","CVE-2026-54059","GHSA-8v84-f9pq-wr9x"],"sourceIds":["PYSEC-2026-2253"],"published":"2026-07-06T19:17:08.127Z","modified":"2026-07-13T07:26:49.281845979Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2254","slug":"pysec-2026-2254-a1ed1fd2","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-54060","CVE-2026-54060","GHSA-5x94-69rx-g8h2"],"sourceIds":["PYSEC-2026-2254"],"published":"2026-07-06T19:17:08.270Z","modified":"2026-07-13T07:26:56.196935469Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2255","slug":"pysec-2026-2255-d0951b98","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55379","CVE-2026-55379","GHSA-45hq-cxwh-f6vc"],"sourceIds":["PYSEC-2026-2255"],"published":"2026-07-06T19:17:08.577Z","modified":"2026-07-13T07:26:26.726353373Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2256","slug":"pysec-2026-2256-0f333f0b","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55380","CVE-2026-55380","GHSA-phj9-mv4w-65pm"],"sourceIds":["PYSEC-2026-2256"],"published":"2026-07-06T19:17:08.703Z","modified":"2026-07-13T07:26:17.085341343Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2257","slug":"pysec-2026-2257-bcbe5d79","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55798","CVE-2026-55798","GHSA-4x4j-2g7c-83w6"],"sourceIds":["PYSEC-2026-2257"],"published":"2026-07-06T19:17:08.830Z","modified":"2026-07-13T07:26:48.229039344Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8a"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/88194166691b7b603529b8b036ab3ab9cedd2de4"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/b0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3447","slug":"pysec-2026-3447-df031425","dossier":true,"summary":null,"aliases":["BIT-setuptools-2026-59890","CVE-2026-59890","GHSA-h35f-9h28-mq5c"],"sourceIds":["PYSEC-2026-3447"],"published":"2026-07-08T17:17:27.020Z","modified":"2026-07-14T10:56:37.948360943Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/pypa/setuptools/releases/tag/v83.0.0"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f"},{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@75.8.0","pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@82.0.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3451","slug":"pysec-2026-3451-3e5eac34","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-59199","CVE-2026-59199","GHSA-6r8x-57c9-28j4"],"sourceIds":["PYSEC-2026-3451"],"published":"2026-07-14T16:17:01.937Z","modified":"2026-07-15T20:11:36.266805254Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9703"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3452","slug":"pysec-2026-3452-0999fd2a","dossier":false,"summary":null,"aliases":["BIT-pillow-2026-59203","CVE-2026-59203","GHSA-pg7v-jwj7-p798"],"sourceIds":["PYSEC-2026-3452"],"published":"2026-07-14T16:17:02.063Z","modified":"2026-07-15T20:11:27.953713427Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9708"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798"}],"versionKeys":["pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":4},{"id":"PYSEC-2026-3453","slug":"pysec-2026-3453-83974725","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-59205","CVE-2026-59205","GHSA-9hw9-ch79-4vh6"],"sourceIds":["PYSEC-2026-3453"],"published":"2026-07-14T16:17:02.370Z","modified":"2026-07-15T20:11:15.582336837Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9715"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13}]}}
