{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:7788","slug":"opencode-7788","gitlabProjectId":7788,"name":"Workshop Green LLM Usage","pathWithNamespace":"uba-ki-lab/workshop-green-llm-usage","description":"Green AI Workshop zu Energiemessung von LLM-Nutzung; Keywords: uba, umweltbundesamt, ki-lab, LLM, Energiemessung","webUrl":"https://gitlab.opencode.de/uba-ki-lab/workshop-green-llm-usage","commitSha":"d72ec94b58729e8b5e32caa9484867ec13add189","commitUrl":"https://gitlab.opencode.de/uba-ki-lab/workshop-green-llm-usage/-/commit/d72ec94b58729e8b5e32caa9484867ec13add189","lastActivityAt":"2025-11-10T11:11:40.478Z","headCommittedAt":"2025-11-10T11:11:34.000Z","tree":{"complete":true,"entryCount":8,"truncated":false},"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"bf2ad06a6324960d4a6a7a91340009e907848d0a","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/workshop-green-llm-usage/-/blob/d72ec94b58729e8b5e32caa9484867ec13add189/uv.lock","commitSha":"d72ec94b58729e8b5e32caa9484867ec13add189","contentSha256":"61957e618f66a37d9e215e1c3f28156669993991782385cff9bcc34a70d841ce","byteCount":156416,"state":"parsed","componentCount":78}],"resolvedComponentCount":78,"artifactResolvedComponentCount":78,"exactManifestPinCount":0,"packageCount":78,"ecosystems":["pypi"],"aiPackageCount":2,"licenseExpressionCount":14,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-248v-346w-9cwc","GHSA-2c2j-9gv5-cj73","GHSA-2xpw-w6gg-jr37","GHSA-33p9-3p43-82vq","GHSA-38jv-5279-wg99","GHSA-3x9g-8vmp-wqvf","GHSA-48p4-8xcf-vxj5","GHSA-5239-wwwm-4pmq","GHSA-537c-gmf6-5ccf","GHSA-65pc-fj4g-8rjx","GHSA-78cv-mqj4-43f7","GHSA-79v4-65xg-pq4g","GHSA-7cx3-6m66-7c5m","GHSA-7f5h-v6xp-fcq8","GHSA-82w8-qh3p-5jfq","GHSA-86qp-5c8j-p5mr","GHSA-9hjg-9r4m-mvj7","GHSA-9wx4-h78v-vm56","GHSA-cx3h-4qpv-8hc9","GHSA-f96h-pmfr-66vw","GHSA-fjrm-76x2-c4q4","GHSA-g7vv-2v7x-gj9p","GHSA-gc5v-m9x4-r6x2","GHSA-gm62-xv2j-4w53","GHSA-h4gh-qq45-vh27","GHSA-jp82-jpqv-5vv3","GHSA-m959-cc7f-wv43","GHSA-mf9v-mfxr-j63j","GHSA-mgf9-4vpg-hj56","GHSA-p423-j2cm-9vmq","GHSA-pq67-6m6q-mj2v","GHSA-pw6j-qg29-8w7f","GHSA-qccp-gfcp-xxvc","GHSA-qjxf-f2mg-c6mc","GHSA-r6ph-v2qm-q3c2","GHSA-vqfr-h8mv-ghfj","GHSA-wqp7-x3pw-xc5r","GHSA-x746-7m8f-x49c","PYSEC-2025-265","PYSEC-2025-266","PYSEC-2025-267","PYSEC-2026-2132"],"advisoryCount":42,"providers":[]},"evidence":{"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"bf2ad06a6324960d4a6a7a91340009e907848d0a","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/workshop-green-llm-usage/-/blob/d72ec94b58729e8b5e32caa9484867ec13add189/uv.lock","commitSha":"d72ec94b58729e8b5e32caa9484867ec13add189","contentSha256":"61957e618f66a37d9e215e1c3f28156669993991782385cff9bcc34a70d841ce","byteCount":156416,"state":"parsed","componentCount":78}],"occurrenceCount":78},"related":{"packages":[{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.7.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:codecarbon","slug":"codecarbon-ee26b31e","identity":"pypi:codecarbon","label":"CodeCarbon","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.0.8"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tornado","slug":"tornado-ab0f364e","identity":"pypi:tornado","label":"tornado","aiRelevant":false,"provider":null,"advisoryCount":10,"licenseExpressions":["Apache-2.0"],"versions":["6.5.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:starlette","slug":"starlette-beb9e527","identity":"pypi:starlette","label":"starlette","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["BSD-3-Clause"],"versions":["0.49.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urllib3","slug":"urllib3-fa68f32c","identity":"pypi:urllib3","label":"urllib3","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["2.5.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cryptography","slug":"cryptography-de36c9c8","identity":"pypi:cryptography","label":"cryptography","aiRelevant":false,"provider":null,"advisoryCount":6,"licenseExpressions":["Apache-2.0 OR BSD-3-Clause"],"versions":["46.0.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests","slug":"requests-53653f76","identity":"pypi:requests","label":"requests","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["Apache-2.0"],"versions":["2.32.5"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:certifi","slug":"certifi-d4f0c37e","identity":"pypi:certifi","label":"certifi","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MPL-2.0"],"versions":["2025.10.5"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click","slug":"click-ef97f731","identity":"pypi:click","label":"click","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["8.3.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:h11","slug":"h11-48165ab1","identity":"pypi:h11","label":"h11","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.11"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-core","slug":"jupyter-core-44178c79","identity":"pypi:jupyter-core","label":"jupyter-core","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["5.9.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jwcrypto","slug":"jwcrypto-5c3130dd","identity":"pypi:jwcrypto","label":"jwcrypto","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["non-standard"],"versions":["1.5.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pygments","slug":"pygments-ad71bc11","identity":"pypi:pygments","label":"pygments","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-2-Clause"],"versions":["2.19.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tqdm","slug":"tqdm-04b01f90","identity":"pypi:tqdm","label":"tqdm","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT AND MPL-2.0"],"versions":["4.67.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-doc","slug":"annotated-doc-9568e1af","identity":"pypi:annotated-doc","label":"annotated-doc","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-types","slug":"annotated-types-2304c38b","identity":"pypi:annotated-types","label":"annotated-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:anyio","slug":"anyio-399e5280","identity":"pypi:anyio","label":"anyio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:appnope","slug":"appnope-1881f8cd","identity":"pypi:appnope","label":"appnope","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:arrow","slug":"arrow-d0e153a5","identity":"pypi:arrow","label":"arrow","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:asttokens","slug":"asttokens-c349c5f9","identity":"pypi:asttokens","label":"asttokens","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["3.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cffi","slug":"cffi-38e65d3e","identity":"pypi:cffi","label":"cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:charset-normalizer","slug":"charset-normalizer-74ccb20a","identity":"pypi:charset-normalizer","label":"charset-normalizer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:comm","slug":"comm-0720ed7b","identity":"pypi:comm","label":"comm","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:debugpy","slug":"debugpy-71725cbb","identity":"pypi:debugpy","label":"debugpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.8.17"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:decorator","slug":"decorator-500c1fb8","identity":"pypi:decorator","label":"decorator","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause","non-standard"],"versions":["5.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distro","slug":"distro-36b318e9","identity":"pypi:distro","label":"distro","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:executing","slug":"executing-36845a5b","identity":"pypi:executing","label":"executing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi","slug":"fastapi-e52fd482","identity":"pypi:fastapi","label":"fastapi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.121.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fief-client","slug":"fief-client-da5c3c7d","identity":"pypi:fief-client","label":"fief-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.20.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpcore","slug":"httpcore-ba6ae671","identity":"pypi:httpcore","label":"httpcore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.0.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx","slug":"httpx-a512a166","identity":"pypi:httpx","label":"httpx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.27.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipykernel","slug":"ipykernel-37162218","identity":"pypi:ipykernel","label":"ipykernel","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["7.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipython","slug":"ipython-7a140323","identity":"pypi:ipython","label":"ipython","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["9.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ipython-pygments-lexers","slug":"ipython-pygments-lexers-6216051e","identity":"pypi:ipython-pygments-lexers","label":"ipython-pygments-lexers","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jedi","slug":"jedi-9eb0c211","identity":"pypi:jedi","label":"jedi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.19.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jiter","slug":"jiter-d62b34e9","identity":"pypi:jiter","label":"jiter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jupyter-client","slug":"jupyter-client-3b4db88c","identity":"pypi:jupyter-client","label":"jupyter-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["8.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markdown-it-py","slug":"markdown-it-py-27073f5e","identity":"pypi:markdown-it-py","label":"markdown-it-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:matplotlib-inline","slug":"matplotlib-inline-50f95e0d","identity":"pypi:matplotlib-inline","label":"matplotlib-inline","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.2.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mdurl","slug":"mdurl-e6f5f075","identity":"pypi:mdurl","label":"mdurl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nest-asyncio","slug":"nest-asyncio-f76531b1","identity":"pypi:nest-asyncio","label":"nest-asyncio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:numpy","slug":"numpy-ba79b98d","identity":"pypi:numpy","label":"numpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib","non-standard"],"versions":["2.3.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-ml-py","slug":"nvidia-ml-py-c07b1551","identity":"pypi:nvidia-ml-py","label":"nvidia-ml-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["13.580.82"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pandas","slug":"pandas-e8d52445","identity":"pypi:pandas","label":"pandas","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.3.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:parso","slug":"parso-fa59fdde","identity":"pypi:parso","label":"parso","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pexpect","slug":"pexpect-9ad65a0c","identity":"pypi:pexpect","label":"pexpect","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:platformdirs","slug":"platformdirs-e64002f0","identity":"pypi:platformdirs","label":"platformdirs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prometheus-client","slug":"prometheus-client-7bd206b5","identity":"pypi:prometheus-client","label":"prometheus-client","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","Apache-2.0 AND BSD-2-Clause"],"versions":["0.23.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prompt-toolkit","slug":"prompt-toolkit-e6f4118a","identity":"pypi:prompt-toolkit","label":"prompt-toolkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.52"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:psutil","slug":"psutil-840b9a74","identity":"pypi:psutil","label":"psutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["7.1.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ptyprocess","slug":"ptyprocess-ec2650c7","identity":"pypi:ptyprocess","label":"ptyprocess","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["ISC"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pure-eval","slug":"pure-eval-24d2bc1c","identity":"pypi:pure-eval","label":"pure-eval","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:py-cpuinfo","slug":"py-cpuinfo-5ef63954","identity":"pypi:py-cpuinfo","label":"py-cpuinfo","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["9.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pycparser","slug":"pycparser-102d9d3e","identity":"pypi:pycparser","label":"pycparser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["2.23"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic","slug":"pydantic-4ac148ca","identity":"pypi:pydantic","label":"pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.12.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-core","slug":"pydantic-core-f9814ebc","identity":"pypi:pydantic-core","label":"pydantic-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.41.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dateutil","slug":"python-dateutil-8eac96b7","identity":"pypi:python-dateutil","label":"python-dateutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.9.0.post0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytz","slug":"pytz-cbf1d95c","identity":"pypi:pytz","label":"pytz","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyzmq","slug":"pyzmq-30b92392","identity":"pypi:pyzmq","label":"pyzmq","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["27.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:questionary","slug":"questionary-3aceb11d","identity":"pypi:questionary","label":"questionary","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rapidfuzz","slug":"rapidfuzz-3beab87b","identity":"pypi:rapidfuzz","label":"rapidfuzz","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.14.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rich","slug":"rich-23b343f7","identity":"pypi:rich","label":"rich","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["14.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:shellingham","slug":"shellingham-fceabe5b","identity":"pypi:shellingham","label":"shellingham","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:six","slug":"six-3c3888bd","identity":"pypi:six","label":"six","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sniffio","slug":"sniffio-83f32c9d","identity":"pypi:sniffio","label":"sniffio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:stack-data","slug":"stack-data-d640fe0e","identity":"pypi:stack-data","label":"stack-data","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:termcolor","slug":"termcolor-7ed3cb9a","identity":"pypi:termcolor","label":"termcolor","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:traitlets","slug":"traitlets-52bd6ddb","identity":"pypi:traitlets","label":"traitlets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.14.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typer","slug":"typer-b291ff1c","identity":"pypi:typer","label":"typer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.20.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspection","slug":"typing-inspection-0abeb500","identity":"pypi:typing-inspection","label":"typing-inspection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tzdata","slug":"tzdata-f80b3bb7","identity":"pypi:tzdata","label":"tzdata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2025.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uvicorn","slug":"uvicorn-07c7a595","identity":"pypi:uvicorn","label":"uvicorn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.38.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wcwidth","slug":"wcwidth-038a8957","identity":"pypi:wcwidth","label":"wcwidth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.14"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:yaspin","slug":"yaspin-3abe0201","identity":"pypi:yaspin","label":"yaspin","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]}],"vulnerabilities":[{"id":"GHSA-248v-346w-9cwc","slug":"ghsa-248v-346w-9cwc-8a7dbdf1","dossier":false,"summary":"Certifi removes GLOBALTRUST root certificate","aliases":["CVE-2024-39689","PYSEC-2024-230"],"sourceIds":["GHSA-248v-346w-9cwc","PYSEC-2024-230"],"published":"2024-07-05T19:15:10Z","modified":"2026-06-10T17:14:18.786020835Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39689"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463"},{"type":"PACKAGE","url":"https://github.com/certifi/python-certifi"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2024-230.yaml"},{"type":"ARTICLE","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241206-0001"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241206-0001/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248v-346w-9cwc"}],"versionKeys":["pypi:certifi@2024.6.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2c2j-9gv5-cj73","slug":"ghsa-2c2j-9gv5-cj73-60bc1f35","dossier":false,"summary":"Starlette has possible denial-of-service vector when parsing large files in multipart forms","aliases":["CVE-2025-54121","PYSEC-2026-1941"],"sourceIds":["GHSA-2c2j-9gv5-cj73","PYSEC-2026-1941"],"published":"2025-07-21T19:34:23Z","modified":"2026-07-07T17:57:05.760766451Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54121"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"WEB","url":"https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14"},{"type":"WEB","url":"https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2c2j-9gv5-cj73"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-2xpw-w6gg-jr37","slug":"ghsa-2xpw-w6gg-jr37-91cead57","dossier":true,"summary":"urllib3 streaming API improperly handles highly compressed data","aliases":["CVE-2025-66471","PYSEC-2026-1994"],"sourceIds":["GHSA-2xpw-w6gg-jr37","PYSEC-2026-1994"],"published":"2025-12-05T18:15:54Z","modified":"2026-07-07T17:56:33.872074196Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-33p9-3p43-82vq","slug":"ghsa-33p9-3p43-82vq-f6a57ddd","dossier":false,"summary":"Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability","aliases":["CVE-2025-30167","PYSEC-2026-1477"],"sourceIds":["GHSA-33p9-3p43-82vq","PYSEC-2026-1477"],"published":"2025-06-04T21:00:23Z","modified":"2026-07-07T17:57:34.145908633Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/security/advisories/GHSA-33p9-3p43-82vq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30167"},{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/commit/5e8965600adda6b416692ce7e85ecb2bd814bd52"},{"type":"PACKAGE","url":"https://github.com/jupyter/jupyter_core"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-33p9-3p43-82vq"}],"versionKeys":["pypi:jupyter-core@5.7.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-38jv-5279-wg99","slug":"ghsa-38jv-5279-wg99-c9df8f7b","dossier":true,"summary":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)","aliases":["CVE-2026-21441","PYSEC-2026-1996"],"sourceIds":["GHSA-38jv-5279-wg99","PYSEC-2026-1996"],"published":"2026-01-07T19:18:14Z","modified":"2026-07-07T17:56:31.346111893Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38jv-5279-wg99"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-3x9g-8vmp-wqvf","slug":"ghsa-3x9g-8vmp-wqvf-6d03bf5f","dossier":false,"summary":"Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient","aliases":["CVE-2026-49853","PYSEC-2026-3387"],"sourceIds":["GHSA-3x9g-8vmp-wqvf","PYSEC-2026-3387"],"published":"2026-06-15T20:20:00Z","modified":"2026-07-13T16:42:55.378655356Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3x9g-8vmp-wqvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49853"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-48p4-8xcf-vxj5","slug":"ghsa-48p4-8xcf-vxj5-13f12656","dossier":false,"summary":"urllib3 does not control redirects in browsers and Node.js","aliases":["CVE-2025-50182","PYSEC-2026-1997"],"sourceIds":["GHSA-48p4-8xcf-vxj5","PYSEC-2026-1997"],"published":"2025-06-18T17:50:11Z","modified":"2026-07-07T17:57:08.881416805Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-5239-wwwm-4pmq","slug":"ghsa-5239-wwwm-4pmq-228840e4","dossier":true,"summary":"Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching","aliases":["CVE-2026-4539","PYSEC-2026-2987"],"sourceIds":["GHSA-5239-wwwm-4pmq","PYSEC-2026-2987"],"published":"2026-03-22T06:30:15Z","modified":"2026-07-13T16:42:36.989801915Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4539"},{"type":"WEB","url":"https://github.com/pygments/pygments/issues/3058"},{"type":"WEB","url":"https://github.com/pygments/pygments/pull/3064"},{"type":"WEB","url":"https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc"},{"type":"PACKAGE","url":"https://github.com/pygments/pygments"},{"type":"WEB","url":"https://github.com/pygments/pygments/releases/tag/2.20.0"},{"type":"WEB","url":"https://vuldb.com/?ctiid.352327"},{"type":"WEB","url":"https://vuldb.com/?id.352327"},{"type":"WEB","url":"https://vuldb.com/?submit.774685"},{"type":"PACKAGE","url":"https://pypi.org/project/pygments"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5239-wwwm-4pmq"}],"versionKeys":["pypi:pygments@2.19.1","pypi:pygments@2.19.2"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-537c-gmf6-5ccf","slug":"ghsa-537c-gmf6-5ccf-23a24e16","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-537c-gmf6-5ccf"],"published":"2026-06-15T20:12:27Z","modified":"2026-06-16T19:59:26.897634900Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260609.txt"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-07-08T17:45:15.021597323Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7"],"packageCount":1,"repositoryCount":17},{"id":"GHSA-78cv-mqj4-43f7","slug":"ghsa-78cv-mqj4-43f7-2021f695","dossier":false,"summary":"Tornado has incomplete validation of cookie attributes","aliases":["CVE-2026-35536","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287"],"sourceIds":["GHSA-78cv-mqj4-43f7","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287"],"published":"2026-03-11T22:17:00Z","modified":"2026-07-13T16:45:06.531920939Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35536"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fqwm-6jpj-5wxc"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-79v4-65xg-pq4g","slug":"ghsa-79v4-65xg-pq4g-b911b371","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":["CVE-2024-12797","PYSEC-2026-1284"],"sourceIds":["GHSA-79v4-65xg-pq4g","PYSEC-2026-1284"],"published":"2025-02-11T18:06:42Z","modified":"2026-07-07T17:57:01.916729628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12797"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20250211.txt"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-79v4-65xg-pq4g"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7cx3-6m66-7c5m","slug":"ghsa-7cx3-6m66-7c5m-cde5125c","dossier":false,"summary":"Tornado vulnerable to excessive logging caused by malformed multipart form data","aliases":["CVE-2025-47287","PYSEC-2026-1974"],"sourceIds":["GHSA-7cx3-6m66-7c5m","PYSEC-2026-1974"],"published":"2025-05-16T14:12:40Z","modified":"2026-07-07T17:56:45.268719923Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47287"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7cx3-6m66-7c5m"}],"versionKeys":["pypi:tornado@6.4.2"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-7f5h-v6xp-fcq8","slug":"ghsa-7f5h-v6xp-fcq8-9393173e","dossier":false,"summary":"Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``","aliases":["CVE-2025-62727","PYSEC-2026-1942"],"sourceIds":["GHSA-7f5h-v6xp-fcq8","PYSEC-2026-1942"],"published":"2025-10-28T20:38:01Z","modified":"2026-07-07T17:56:07.620081354Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-7f5h-v6xp-fcq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62727"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/4ea6e22b489ec388d6004cfbca52dd5b147127c5"},{"type":"INTRODUCED","url":"https://github.com/Kludex/starlette/commit/69ed26a85956ef4bd0161807eb27abf49be7cd3c"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/Kludex/starlette/releases/tag/0.49.1"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7f5h-v6xp-fcq8"}],"versionKeys":["pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-82w8-qh3p-5jfq","slug":"ghsa-82w8-qh3p-5jfq-a05ef51e","dossier":false,"summary":"Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS","aliases":["CVE-2026-54283","PYSEC-2026-249"],"sourceIds":["GHSA-82w8-qh3p-5jfq","PYSEC-2026-249"],"published":"2026-06-15T20:39:53Z","modified":"2026-06-27T11:26:15.727496147Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-86qp-5c8j-p5mr","slug":"ghsa-86qp-5c8j-p5mr-13e563cb","dossier":false,"summary":"Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks","aliases":["CVE-2026-48710","PYSEC-2026-161","X41-2026-002"],"sourceIds":["GHSA-86qp-5c8j-p5mr","PYSEC-2026-161"],"published":"2026-05-22T13:10:03Z","modified":"2026-07-10T12:45:24.283227548Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48710"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6"},{"type":"WEB","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette"},{"type":"ARTICLE","url":"https://www.secwest.net/starlette"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-48710"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json"},{"type":"WEB","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481742"},{"type":"DETECTION","url":"https://badhost.org/"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48710"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34532"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:34526"},{"type":"ARTICLE","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/"},{"type":"ADVISORY","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette/"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-9hjg-9r4m-mvj7","slug":"ghsa-9hjg-9r4m-mvj7-32d7b63e","dossier":false,"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"sourceIds":["GHSA-9hjg-9r4m-mvj7","PYSEC-2026-1872"],"published":"2025-06-09T19:06:08Z","modified":"2026-07-07T17:56:56.234172558Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6965"},{"type":"FIX","url":"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2025/Jun/2"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-9wx4-h78v-vm56","slug":"ghsa-9wx4-h78v-vm56-6a334c57","dossier":false,"summary":"Requests `Session` object does not verify requests after making first request with verify=False","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"sourceIds":["GHSA-9wx4-h78v-vm56","PYSEC-2026-1873"],"published":"2024-05-20T20:15:00Z","modified":"2026-07-07T17:57:17.012984050Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6655"},{"type":"FIX","url":"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wx4-h78v-vm56"}],"versionKeys":["pypi:requests@2.31.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-cx3h-4qpv-8hc9","slug":"ghsa-cx3h-4qpv-8hc9-3078b6fa","dossier":false,"summary":"Tornado has out-of-bounds memory access via C extension","aliases":["CVE-2026-49854","PYSEC-2026-3388"],"sourceIds":["GHSA-cx3h-4qpv-8hc9","PYSEC-2026-3388"],"published":"2026-06-12T18:30:19Z","modified":"2026-07-13T16:43:34.663472817Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.6"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx3h-4qpv-8hc9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49854"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-f96h-pmfr-66vw","slug":"ghsa-f96h-pmfr-66vw-6763f20e","dossier":false,"summary":"Starlette Denial of service (DoS) via multipart/form-data","aliases":["CVE-2024-47874","PYSEC-2026-1943"],"sourceIds":["GHSA-f96h-pmfr-66vw","PYSEC-2026-1943"],"published":"2024-10-15T18:12:57Z","modified":"2026-07-07T17:57:05.823442628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47874"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/fd038f3070c302bff17ef7d173dbb0b007617733"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f96h-pmfr-66vw"}],"versionKeys":["pypi:starlette@0.37.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fjrm-76x2-c4q4","slug":"ghsa-fjrm-76x2-c4q4-c21dcb99","dossier":false,"summary":"JWCrypto: JWE ZIP decompression bomb","aliases":["CVE-2026-39373","PYSEC-2026-70"],"sourceIds":["GHSA-fjrm-76x2-c4q4","PYSEC-2026-70"],"published":"2026-04-07T20:16:32.133Z","modified":"2026-06-06T00:30:08.711138560Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"EVIDENCE","url":"https://github.com/latchset/jwcrypto/security/advisories/GHSA-fjrm-76x2-c4q4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39373"},{"type":"WEB","url":"https://github.com/latchset/jwcrypto/commit/25db861d8b29434838669a94a843af03d29ea6ed"},{"type":"PACKAGE","url":"https://github.com/latchset/jwcrypto"},{"type":"WEB","url":"https://github.com/latchset/jwcrypto/releases/tag/v1.5.7"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2026-70.yaml"}],"versionKeys":["pypi:jwcrypto@1.5.6"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-g7vv-2v7x-gj9p","slug":"ghsa-g7vv-2v7x-gj9p-5ef970c3","dossier":false,"summary":"tqdm CLI arguments injection attack","aliases":["CVE-2024-34062","PYSEC-2026-1976"],"sourceIds":["GHSA-g7vv-2v7x-gj9p","PYSEC-2026-1976"],"published":"2024-05-03T19:33:28Z","modified":"2026-07-07T17:56:20.187915678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"},{"type":"WEB","url":"https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316"},{"type":"PACKAGE","url":"https://github.com/tqdm/tqdm"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC"},{"type":"PACKAGE","url":"https://pypi.org/project/tqdm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7vv-2v7x-gj9p"}],"versionKeys":["pypi:tqdm@4.66.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gc5v-m9x4-r6x2","slug":"ghsa-gc5v-m9x4-r6x2-b9828ad8","dossier":true,"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"sourceIds":["GHSA-gc5v-m9x4-r6x2","PYSEC-2026-2275"],"published":"2026-03-25T16:56:28Z","modified":"2026-07-13T07:26:34.091663004Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645"},{"type":"FIX","url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"ADVISORY","url":"https://github.com/psf/requests/releases/tag/v2.33.0"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3","pypi:requests@2.32.4","pypi:requests@2.32.5"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-gm62-xv2j-4w53","slug":"ghsa-gm62-xv2j-4w53-5befa184","dossier":true,"summary":"urllib3 allows an unbounded number of links in the decompression chain","aliases":["CVE-2025-66418","PYSEC-2026-1998"],"sourceIds":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"published":"2025-12-05T18:15:19Z","modified":"2026-07-07T17:57:28.931610368Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm62-xv2j-4w53"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-h4gh-qq45-vh27","slug":"ghsa-h4gh-qq45-vh27-43490265","dossier":false,"summary":"pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-h4gh-qq45-vh27"],"published":"2024-09-03T21:59:48Z","modified":"2026-02-04T03:06:49.280647Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20240903.txt"}],"versionKeys":["pypi:cryptography@42.0.8"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jp82-jpqv-5vv3","slug":"ghsa-jp82-jpqv-5vv3-4d50530e","dossier":false,"summary":"Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname","aliases":["CVE-2026-54282","PYSEC-2026-248"],"sourceIds":["GHSA-jp82-jpqv-5vv3","PYSEC-2026-248"],"published":"2026-06-15T20:38:08Z","modified":"2026-07-15T22:30:44.498280076Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54282"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-248.yaml"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-m959-cc7f-wv43","slug":"ghsa-m959-cc7f-wv43-3b497c67","dossier":false,"summary":"cryptography has incomplete DNS name constraint enforcement on peer names","aliases":["CVE-2026-34073","PYSEC-2026-35"],"sourceIds":["GHSA-m959-cc7f-wv43","PYSEC-2026-35"],"published":"2026-03-27T19:56:21Z","modified":"2026-06-05T18:00:13.915417385Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34073"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-35.yaml"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mf9v-mfxr-j63j","slug":"ghsa-mf9v-mfxr-j63j-1a7db6d4","dossier":false,"summary":"urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API","aliases":["CVE-2026-44432","PYSEC-2026-142"],"sourceIds":["GHSA-mf9v-mfxr-j63j","PYSEC-2026-142"],"published":"2026-05-11T14:51:45Z","modified":"2026-06-08T20:00:12.284378628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mgf9-4vpg-hj56","slug":"ghsa-mgf9-4vpg-hj56-00729355","dossier":false,"summary":"tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)","aliases":["CVE-2026-49855","PYSEC-2026-3389"],"sourceIds":["GHSA-mgf9-4vpg-hj56","PYSEC-2026-3389"],"published":"2026-06-15T20:19:28Z","modified":"2026-07-13T16:43:27.241564365Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"PACKAGE","url":"https://pypi.org/project/tornado"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mgf9-4vpg-hj56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49855"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-p423-j2cm-9vmq","slug":"ghsa-p423-j2cm-9vmq-1455bc4c","dossier":false,"summary":"Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs","aliases":["CVE-2026-39892","PYSEC-2026-36"],"sourceIds":["GHSA-p423-j2cm-9vmq","PYSEC-2026-36"],"published":"2026-04-08T19:23:08Z","modified":"2026-06-05T18:00:15.295914184Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39892"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml"}],"versionKeys":["pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-pq67-6m6q-mj2v","slug":"ghsa-pq67-6m6q-mj2v-3522d1d4","dossier":false,"summary":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","aliases":["CVE-2025-50181","PYSEC-2026-1999"],"sourceIds":["GHSA-pq67-6m6q-mj2v","PYSEC-2026-1999"],"published":"2025-06-18T17:50:00Z","modified":"2026-07-07T17:56:41.872294653Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-pw6j-qg29-8w7f","slug":"ghsa-pw6j-qg29-8w7f-fb4d7ed6","dossier":false,"summary":"Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse","aliases":[],"sourceIds":["GHSA-pw6j-qg29-8w7f"],"published":"2026-06-15T20:37:24Z","modified":"2026-06-16T22:59:25.768721886Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-qccp-gfcp-xxvc","slug":"ghsa-qccp-gfcp-xxvc-0d988969","dossier":true,"summary":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects","aliases":["CVE-2026-44431","PYSEC-2026-141"],"sourceIds":["GHSA-qccp-gfcp-xxvc","PYSEC-2026-141"],"published":"2026-05-11T14:51:20Z","modified":"2026-05-20T09:19:20.983812Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-qjxf-f2mg-c6mc","slug":"ghsa-qjxf-f2mg-c6mc-58d52008","dossier":false,"summary":"Tornado is vulnerable to DoS due to too many multipart parts","aliases":["CVE-2026-31958","PYSEC-2026-140"],"sourceIds":["GHSA-qjxf-f2mg-c6mc","PYSEC-2026-140"],"published":"2026-03-11T20:16:16.617Z","modified":"2026-06-08T20:00:14.385003861Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31958"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-r6ph-v2qm-q3c2","slug":"ghsa-r6ph-v2qm-q3c2-c75907df","dossier":false,"summary":"cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves","aliases":["CVE-2026-26007","PYSEC-2026-2141"],"sourceIds":["GHSA-r6ph-v2qm-q3c2","PYSEC-2026-2141"],"published":"2026-02-10T21:27:06Z","modified":"2026-07-13T07:26:47.289183808Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26007"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pyca/cryptography/releases/tag/46.0.5"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-26007"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:12176"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13553"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13672"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19355"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21517"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22330"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22993"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2694"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-vqfr-h8mv-ghfj","slug":"ghsa-vqfr-h8mv-ghfj-49515033","dossier":false,"summary":"h11 accepts some malformed Chunked-Encoding bodies","aliases":["CVE-2025-43859","PYSEC-2026-348"],"sourceIds":["GHSA-vqfr-h8mv-ghfj","PYSEC-2026-348"],"published":"2025-04-24T16:07:56Z","modified":"2026-07-01T20:22:54.082067Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43859"},{"type":"WEB","url":"https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h11"},{"type":"PACKAGE","url":"https://pypi.org/project/h11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqfr-h8mv-ghfj"}],"versionKeys":["pypi:h11@0.14.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-wqp7-x3pw-xc5r","slug":"ghsa-wqp7-x3pw-xc5r-4caabf81","dossier":false,"summary":"Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows","aliases":["CVE-2026-48818","PYSEC-2026-2281"],"sourceIds":["GHSA-wqp7-x3pw-xc5r","PYSEC-2026-2281"],"published":"2026-06-15T20:16:30Z","modified":"2026-07-13T07:26:44.976412482Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-wqp7-x3pw-xc5r"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48818"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48818.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30087"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490020"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/fd53168a7767b6b55ba5af787fd88f49e33cabc5"},{"type":"FIX","url":"https://github.com/Kludex/starlette/pull/3287"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-x746-7m8f-x49c","slug":"ghsa-x746-7m8f-x49c-c0349d3f","dossier":false,"summary":"Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`","aliases":["CVE-2026-48817","PYSEC-2026-2280"],"sourceIds":["GHSA-x746-7m8f-x49c","PYSEC-2026-2280"],"published":"2026-06-15T20:16:05Z","modified":"2026-07-13T07:26:54.069698774Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48817"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-265","slug":"pysec-2025-265-33beac08","dossier":false,"summary":null,"aliases":["CVE-2025-67724","GHSA-pr2v-jx2c-wg9f"],"sourceIds":["PYSEC-2025-265"],"published":"2025-12-12T06:15:41.213Z","modified":"2026-07-13T07:15:44.068555841Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pr2v-jx2c-wg9f"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/9c163aebeaad9e6e7d28bac1f33580eb00b0e421"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2025-266","slug":"pysec-2025-266-c9802ae6","dossier":false,"summary":null,"aliases":["CVE-2025-67725","GHSA-c98p-7wgm-6p64"],"sourceIds":["PYSEC-2025-266"],"published":"2025-12-12T06:15:41.380Z","modified":"2026-07-13T07:15:44.064352714Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2025-267","slug":"pysec-2025-267-ca9685ba","dossier":false,"summary":null,"aliases":["CVE-2025-67726","GHSA-jhmp-mqwm-3gq8"],"sourceIds":["PYSEC-2025-267"],"published":"2025-12-12T07:15:44.920Z","modified":"2026-07-13T07:15:45.375541292Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.3"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8"},{"type":"FIX","url":"https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd"}],"versionKeys":["pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2"],"packageCount":1,"repositoryCount":5},{"id":"PYSEC-2026-2132","slug":"pysec-2026-2132-627bf7c7","dossier":true,"summary":null,"aliases":["CVE-2026-7246","GHSA-47fr-3ffg-hgmw"],"sourceIds":["PYSEC-2026-2132"],"published":"2026-04-30T14:16:36.433Z","modified":"2026-07-13T07:15:21.899333658Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-7246"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464121"},{"type":"FIX","url":"https://github.com/pallets/click/releases/tag/8.3.3"},{"type":"EVIDENCE","url":"https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw"}],"versionKeys":["pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1"],"packageCount":1,"repositoryCount":14}]}}
