{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:8742","slug":"opencode-8742","gitlabProjectId":8742,"name":"ai-websearch-benchmark","pathWithNamespace":"datenlabor-bmz/ai-websearch-benchmark","description":"Small vibecoded benchmark meant as a smoke test for search API results.","webUrl":"https://gitlab.opencode.de/datenlabor-bmz/ai-websearch-benchmark","commitSha":"cd6b854b1b400d7e45796aaa22bded8183642916","commitUrl":"https://gitlab.opencode.de/datenlabor-bmz/ai-websearch-benchmark/-/commit/cd6b854b1b400d7e45796aaa22bded8183642916","lastActivityAt":"2026-05-07T14:25:51.430Z","headCommittedAt":"2026-02-17T14:55:53.000Z","tree":{"complete":true,"entryCount":248,"truncated":false},"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"4f7b4e2e096e186e4408b529568676aa8c71ba55","sourceUrl":"https://gitlab.opencode.de/datenlabor-bmz/ai-websearch-benchmark/-/blob/cd6b854b1b400d7e45796aaa22bded8183642916/uv.lock","commitSha":"cd6b854b1b400d7e45796aaa22bded8183642916","contentSha256":"b8f9651f03205e9719be196d83af006415043f761f2f02bcde0cac7b36f8dca7","byteCount":305255,"state":"parsed","componentCount":65}],"resolvedComponentCount":65,"artifactResolvedComponentCount":65,"exactManifestPinCount":0,"packageCount":65,"ecosystems":["pypi"],"aiPackageCount":9,"licenseExpressionCount":15,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-248v-346w-9cwc","GHSA-2fqr-mr3j-6wp8","GHSA-2g6r-c272-w58r","GHSA-2vrm-gr82-f7m5","GHSA-2xpw-w6gg-jr37","GHSA-3644-q5cj-c5c7","GHSA-38jv-5279-wg99","GHSA-3wq7-rqq7-wx6j","GHSA-428g-f7cq-pgp5","GHSA-45pg-36p6-83v9","GHSA-48p4-8xcf-vxj5","GHSA-4fvr-rgm6-gqmc","GHSA-4m7w-qmgq-4wj5","GHSA-4xgf-cpjx-pc3j","GHSA-54jq-c3m8-4m76","GHSA-5chr-fjjv-38qv","GHSA-63hf-3vf5-4wqf","GHSA-63hw-fmq6-xxg2","GHSA-65pc-fj4g-8rjx","GHSA-69f9-5gxw-wvc2","GHSA-6jhg-hg63-jvvf","GHSA-6mq8-rvhq-8wgg","GHSA-6qv9-48xg-fc7f","GHSA-926x-3r5x-gfhw","GHSA-9548-qrrj-x5pj","GHSA-966j-vmvw-g2g9","GHSA-9hjg-9r4m-mvj7","GHSA-9wx4-h78v-vm56","GHSA-9x8q-7h8h-wcw9","GHSA-c427-h43c-vf67","GHSA-c67j-w6g6-q2cm","GHSA-f4xh-w4cj-qxq8","GHSA-fh55-r93g-j68g","GHSA-fjqc-hq36-qh5p","GHSA-fv5p-p927-qmxr","GHSA-g3cq-j2xw-wf74","GHSA-g48c-2wqr-h844","GHSA-g7vv-2v7x-gj9p","GHSA-g84x-mcqj-x9qq","GHSA-gc5v-m9x4-r6x2","GHSA-gm62-xv2j-4w53","GHSA-gr75-jv2w-4656","GHSA-hcc4-c3v8-rx92","GHSA-hg6j-4rv6-33pg","GHSA-hpj7-wq8m-9hgp","GHSA-hx9q-6w63-j58v","GHSA-jg22-mg44-37j8","GHSA-jj3x-wxrx-4x23","GHSA-m5qp-6w8w-w647","GHSA-m6qw-4cw2-hm4m","GHSA-mf9v-mfxr-j63j","GHSA-mf9w-mj56-hr94","GHSA-mqqc-3gqh-h2x8","GHSA-mwh4-6h8g-pg8w","GHSA-p998-jp59-783m","GHSA-pc6w-59fv-rh23","GHSA-pjwx-r37v-7724","GHSA-pq67-6m6q-mj2v","GHSA-q25c-c977-4cmh","GHSA-qccp-gfcp-xxvc","GHSA-qh6h-p6c9-ff54","GHSA-r7w7-9xr2-qq2r","GHSA-rr7j-v2q5-chgv","GHSA-vqfr-h8mv-ghfj","GHSA-w2fm-2cpv-w7v5","GHSA-w39p-vh2g-g8g5","GHSA-xcgm-r5h9-7989","PYSEC-2024-115","PYSEC-2024-323"],"advisoryCount":69,"providers":[]},"evidence":{"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"4f7b4e2e096e186e4408b529568676aa8c71ba55","sourceUrl":"https://gitlab.opencode.de/datenlabor-bmz/ai-websearch-benchmark/-/blob/cd6b854b1b400d7e45796aaa22bded8183642916/uv.lock","commitSha":"cd6b854b1b400d7e45796aaa22bded8183642916","contentSha256":"b8f9651f03205e9719be196d83af006415043f761f2f02bcde0cac7b36f8dca7","byteCount":305255,"state":"parsed","componentCount":65}],"occurrenceCount":65},"related":{"packages":[{"id":"package:pypi:langchain-core","slug":"langchain-core-82117efb","identity":"pypi:langchain-core","label":"LangChain Core","aiRelevant":true,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["1.2.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-community","slug":"langchain-community-b296254c","identity":"pypi:langchain-community","label":"LangChain Community","aiRelevant":true,"provider":null,"advisoryCount":4,"licenseExpressions":["MIT"],"versions":["0.4.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain","slug":"langchain-2b3b6a0b","identity":"pypi:langchain","label":"LangChain","aiRelevant":true,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["1.2.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph","slug":"langgraph-6c1c645e","identity":"pypi:langgraph","label":"LangGraph","aiRelevant":true,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["1.0.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-openai","slug":"langchain-openai-4985188e","identity":"pypi:langchain-openai","label":"LangChain OpenAI","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.1.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.15.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-linkup","slug":"langchain-linkup-d50e0d4b","identity":"pypi:langchain-linkup","label":"LangChain · Linkup","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-tavily","slug":"langchain-tavily-432e1c93","identity":"pypi:langchain-tavily","label":"LangChain · Tavily","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.17"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tiktoken","slug":"tiktoken-06b251a3","identity":"pypi:tiktoken","label":"tiktoken","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.12.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohttp","slug":"aiohttp-5a806a63","identity":"pypi:aiohttp","label":"aiohttp","aiRelevant":false,"provider":null,"advisoryCount":30,"licenseExpressions":["Apache-2.0","Apache-2.0 AND MIT"],"versions":["3.13.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urllib3","slug":"urllib3-fa68f32c","identity":"pypi:urllib3","label":"urllib3","aiRelevant":false,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["2.6.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langsmith","slug":"langsmith-a7ab7b96","identity":"pypi:langsmith","label":"langsmith","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["0.6.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests","slug":"requests-53653f76","identity":"pypi:requests","label":"requests","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["Apache-2.0"],"versions":["2.32.5"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:certifi","slug":"certifi-d4f0c37e","identity":"pypi:certifi","label":"certifi","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MPL-2.0"],"versions":["2026.1.4"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:h11","slug":"h11-48165ab1","identity":"pypi:h11","label":"h11","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.11"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-classic","slug":"langchain-classic-ee5360ab","identity":"pypi:langchain-classic","label":"langchain-classic","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.0.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langchain-text-splitters","slug":"langchain-text-splitters-0c057788","identity":"pypi:langchain-text-splitters","label":"langchain-text-splitters","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph-checkpoint","slug":"langgraph-checkpoint-b3039a64","identity":"pypi:langgraph-checkpoint","label":"langgraph-checkpoint","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["4.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph-sdk","slug":"langgraph-sdk-7670dc92","identity":"pypi:langgraph-sdk","label":"langgraph-sdk","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.3.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:marshmallow","slug":"marshmallow-abf69093","identity":"pypi:marshmallow","label":"marshmallow","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["3.26.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:orjson","slug":"orjson-0293c856","identity":"pypi:orjson","label":"orjson","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["Apache-2.0 OR MIT","MPL-2.0 AND (Apache-2.0 OR MIT)"],"versions":["3.11.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-settings","slug":"pydantic-settings-d677745f","identity":"pypi:pydantic-settings","label":"pydantic-settings","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["2.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dotenv","slug":"python-dotenv-27b12285","identity":"pypi:python-dotenv","label":"python-dotenv","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["1.2.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tqdm","slug":"tqdm-04b01f90","identity":"pypi:tqdm","label":"tqdm","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT AND MPL-2.0"],"versions":["4.67.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohappyeyeballs","slug":"aiohappyeyeballs-ea4657b8","identity":"pypi:aiohappyeyeballs","label":"aiohappyeyeballs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["2.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiosignal","slug":"aiosignal-b6794e75","identity":"pypi:aiosignal","label":"aiosignal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-types","slug":"annotated-types-2304c38b","identity":"pypi:annotated-types","label":"annotated-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:anyio","slug":"anyio-399e5280","identity":"pypi:anyio","label":"anyio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.12.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:attrs","slug":"attrs-2e7954ac","identity":"pypi:attrs","label":"attrs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:charset-normalizer","slug":"charset-normalizer-74ccb20a","identity":"pypi:charset-normalizer","label":"charset-normalizer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:dataclasses-json","slug":"dataclasses-json-54bdba52","identity":"pypi:dataclasses-json","label":"dataclasses-json","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.7"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distro","slug":"distro-36b318e9","identity":"pypi:distro","label":"distro","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:frozenlist","slug":"frozenlist-110237da","identity":"pypi:frozenlist","label":"frozenlist","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:greenlet","slug":"greenlet-cd6f7934","identity":"pypi:greenlet","label":"greenlet","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","MIT AND PSF-2.0","MIT AND Python-2.0"],"versions":["3.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpcore","slug":"httpcore-ba6ae671","identity":"pypi:httpcore","label":"httpcore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.0.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx","slug":"httpx-a512a166","identity":"pypi:httpx","label":"httpx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx-sse","slug":"httpx-sse-0029fe64","identity":"pypi:httpx-sse","label":"httpx-sse","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jiter","slug":"jiter-d62b34e9","identity":"pypi:jiter","label":"jiter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonpatch","slug":"jsonpatch-ce7aa354","identity":"pypi:jsonpatch","label":"jsonpatch","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.33"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonpointer","slug":"jsonpointer-a61b5f8f","identity":"pypi:jsonpointer","label":"jsonpointer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:langgraph-prebuilt","slug":"langgraph-prebuilt-84c4e144","identity":"pypi:langgraph-prebuilt","label":"langgraph-prebuilt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.0.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:linkup-sdk","slug":"linkup-sdk-d56065ac","identity":"pypi:linkup-sdk","label":"linkup-sdk","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.12.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:multidict","slug":"multidict-b407a4ac","identity":"pypi:multidict","label":"multidict","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mypy-extensions","slug":"mypy-extensions-702f6cf3","identity":"pypi:mypy-extensions","label":"mypy-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:numpy","slug":"numpy-ba79b98d","identity":"pypi:numpy","label":"numpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib","non-standard"],"versions":["2.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ormsgpack","slug":"ormsgpack-56a067ff","identity":"pypi:ormsgpack","label":"ormsgpack","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.12.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:propcache","slug":"propcache-1fcd6be4","identity":"pypi:propcache","label":"propcache","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic","slug":"pydantic-4ac148ca","identity":"pypi:pydantic","label":"pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.12.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-core","slug":"pydantic-core-f9814ebc","identity":"pypi:pydantic-core","label":"pydantic-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.41.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyyaml","slug":"pyyaml-16000901","identity":"pypi:pyyaml","label":"pyyaml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:regex","slug":"regex-5e8be65e","identity":"pypi:regex","label":"regex","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 AND CNRI-Python","non-standard"],"versions":["2026.1.15"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests-toolbelt","slug":"requests-toolbelt-bb89e811","identity":"pypi:requests-toolbelt","label":"requests-toolbelt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sniffio","slug":"sniffio-83f32c9d","identity":"pypi:sniffio","label":"sniffio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sqlalchemy","slug":"sqlalchemy-5de7c53b","identity":"pypi:sqlalchemy","label":"sqlalchemy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.0.46"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tenacity","slug":"tenacity-415454f8","identity":"pypi:tenacity","label":"tenacity","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["9.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspect","slug":"typing-inspect-bffee874","identity":"pypi:typing-inspect","label":"typing-inspect","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspection","slug":"typing-inspection-0abeb500","identity":"pypi:typing-inspection","label":"typing-inspection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uuid-utils","slug":"uuid-utils-c3d356a2","identity":"pypi:uuid-utils","label":"uuid-utils","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["0.14.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:xxhash","slug":"xxhash-908d556a","identity":"pypi:xxhash","label":"xxhash","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["3.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:yarl","slug":"yarl-05cd1b35","identity":"pypi:yarl","label":"yarl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.22.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:zstandard","slug":"zstandard-8fab007a","identity":"pypi:zstandard","label":"zstandard","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]}],"vulnerabilities":[{"id":"GHSA-248v-346w-9cwc","slug":"ghsa-248v-346w-9cwc-8a7dbdf1","dossier":false,"summary":"Certifi removes GLOBALTRUST root certificate","aliases":["CVE-2024-39689","PYSEC-2024-230"],"sourceIds":["GHSA-248v-346w-9cwc","PYSEC-2024-230"],"published":"2024-07-05T19:15:10Z","modified":"2026-06-10T17:14:18.786020835Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39689"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463"},{"type":"PACKAGE","url":"https://github.com/certifi/python-certifi"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2024-230.yaml"},{"type":"ARTICLE","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241206-0001"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241206-0001/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248v-346w-9cwc"}],"versionKeys":["pypi:certifi@2024.6.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2fqr-mr3j-6wp8","slug":"ghsa-2fqr-mr3j-6wp8-5ee7c60f","dossier":false,"summary":"aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence","aliases":["CVE-2026-54279","PYSEC-2026-2112"],"sourceIds":["GHSA-2fqr-mr3j-6wp8","PYSEC-2026-2112"],"published":"2026-06-15T20:08:51Z","modified":"2026-07-13T07:26:35.059071977Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2g6r-c272-w58r","slug":"ghsa-2g6r-c272-w58r-4bbbcb01","dossier":false,"summary":"LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages","aliases":["CVE-2026-26013","PYSEC-2026-2562"],"sourceIds":["GHSA-2g6r-c272-w58r","PYSEC-2026-2562"],"published":"2026-02-11T14:23:13Z","modified":"2026-07-13T16:43:30.756724986Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-2g6r-c272-w58r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26013"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/2b4b1dc29a833d4053deba4c2b77a3848c834565"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.11"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2g6r-c272-w58r"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-2vrm-gr82-f7m5","slug":"ghsa-2vrm-gr82-f7m5-5092ea0c","dossier":false,"summary":"AIOHTTP has CRLF injection through multipart part content type header construction","aliases":["CVE-2026-34514","PYSEC-2026-2096"],"sourceIds":["GHSA-2vrm-gr82-f7m5","PYSEC-2026-2096"],"published":"2026-04-01T21:16:59.417Z","modified":"2026-07-13T07:26:28.471600737Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2vrm-gr82-f7m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34514"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2xpw-w6gg-jr37","slug":"ghsa-2xpw-w6gg-jr37-91cead57","dossier":true,"summary":"urllib3 streaming API improperly handles highly compressed data","aliases":["CVE-2025-66471","PYSEC-2026-1994"],"sourceIds":["GHSA-2xpw-w6gg-jr37","PYSEC-2026-1994"],"published":"2025-12-05T18:15:54Z","modified":"2026-07-07T17:56:33.872074196Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-3644-q5cj-c5c7","slug":"ghsa-3644-q5cj-c5c7-4c578cf2","dossier":false,"summary":"LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","aliases":["CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"sourceIds":["GHSA-3644-q5cj-c5c7","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"published":"2026-05-13T15:29:30Z","modified":"2026-07-13T16:43:39.736848907Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45134"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3644-q5cj-c5c7"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-classic"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"}],"versionKeys":["pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4"],"packageCount":3,"repositoryCount":3},{"id":"GHSA-38jv-5279-wg99","slug":"ghsa-38jv-5279-wg99-c9df8f7b","dossier":true,"summary":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)","aliases":["CVE-2026-21441","PYSEC-2026-1996"],"sourceIds":["GHSA-38jv-5279-wg99","PYSEC-2026-1996"],"published":"2026-01-07T19:18:14Z","modified":"2026-07-07T17:56:31.346111893Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38jv-5279-wg99"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-3wq7-rqq7-wx6j","slug":"ghsa-3wq7-rqq7-wx6j-29b8d785","dossier":false,"summary":"AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS","aliases":["CVE-2026-34517","PYSEC-2026-2099"],"sourceIds":["GHSA-3wq7-rqq7-wx6j","PYSEC-2026-2099"],"published":"2026-04-01T21:16:59.870Z","modified":"2026-07-13T07:26:13.561233517Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-3wq7-rqq7-wx6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34517"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/cbb774f38330563422ca0c413a71021d7b944145"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-428g-f7cq-pgp5","slug":"ghsa-428g-f7cq-pgp5-bfab95ee","dossier":false,"summary":"Marshmallow has DoS in Schema.load(many)","aliases":["CVE-2025-68480","PYSEC-2026-1605"],"sourceIds":["GHSA-428g-f7cq-pgp5","PYSEC-2026-1605"],"published":"2025-12-22T20:20:07Z","modified":"2026-07-07T17:56:15.810789183Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68480"},{"type":"WEB","url":"https://github.com/marshmallow-code/marshmallow/commit/d24a0c9df061c4daa92f71cf85aca25b83eee508"},{"type":"PACKAGE","url":"https://github.com/marshmallow-code/marshmallow"},{"type":"PACKAGE","url":"https://pypi.org/project/marshmallow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-428g-f7cq-pgp5"}],"versionKeys":["pypi:marshmallow@3.24.2","pypi:marshmallow@3.26.1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-45pg-36p6-83v9","slug":"ghsa-45pg-36p6-83v9-9505da12","dossier":false,"summary":"Langchain SQL Injection vulnerability","aliases":["CVE-2024-8309","PYSEC-2024-115","PYSEC-2026-1507"],"sourceIds":["GHSA-45pg-36p6-83v9"],"published":"2024-10-29T15:32:05Z","modified":"2026-07-07T17:57:12.591755527Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8309"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/64c317eba05fbac0c6a6fc5aa192bc0d7130972e"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-115.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-48p4-8xcf-vxj5","slug":"ghsa-48p4-8xcf-vxj5-13f12656","dossier":false,"summary":"urllib3 does not control redirects in browsers and Node.js","aliases":["CVE-2025-50182","PYSEC-2026-1997"],"sourceIds":["GHSA-48p4-8xcf-vxj5","PYSEC-2026-1997"],"published":"2025-06-18T17:50:11Z","modified":"2026-07-07T17:57:08.881416805Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-4fvr-rgm6-gqmc","slug":"ghsa-4fvr-rgm6-gqmc-c8b35c87","dossier":false,"summary":"aiohttp: HTTP/1 Pipelined Requests Queue Without Limit","aliases":["CVE-2026-54273","PYSEC-2026-2107"],"sourceIds":["GHSA-4fvr-rgm6-gqmc","PYSEC-2026-2107"],"published":"2026-06-15T20:10:32Z","modified":"2026-07-13T07:26:17.316378610Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4m7w-qmgq-4wj5","slug":"ghsa-4m7w-qmgq-4wj5-f98433d3","dossier":false,"summary":"aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections","aliases":["CVE-2026-54275","PYSEC-2026-237"],"sourceIds":["GHSA-4m7w-qmgq-4wj5","PYSEC-2026-237"],"published":"2026-06-15T20:11:13Z","modified":"2026-06-27T11:26:29.646102490Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4m7w-qmgq-4wj5"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4xgf-cpjx-pc3j","slug":"ghsa-4xgf-cpjx-pc3j-c1284f87","dossier":false,"summary":"pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size","aliases":["CVE-2026-58203"],"sourceIds":["GHSA-4xgf-cpjx-pc3j"],"published":"2026-06-19T22:10:42Z","modified":"2026-07-08T08:12:48.604645024Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j"},{"type":"PACKAGE","url":"https://github.com/pydantic/pydantic-settings"}],"versionKeys":["pypi:pydantic-settings@2.12.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-54jq-c3m8-4m76","slug":"ghsa-54jq-c3m8-4m76-bba4b2d3","dossier":false,"summary":"AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components","aliases":["CVE-2025-69226","PYSEC-2026-1097"],"sourceIds":["GHSA-54jq-c3m8-4m76","PYSEC-2026-1097"],"published":"2026-01-05T23:09:51Z","modified":"2026-07-07T17:57:12.462419549Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-54jq-c3m8-4m76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69226"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f2a86fd5ac0383000d1715afddfa704413f0711e"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-54jq-c3m8-4m76"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-5chr-fjjv-38qv","slug":"ghsa-5chr-fjjv-38qv-5f3dd755","dossier":false,"summary":"langchain-core allows unauthorized users to read arbitrary files from the host file system","aliases":["CVE-2024-10940","PYSEC-2026-1517"],"sourceIds":["GHSA-5chr-fjjv-38qv","PYSEC-2026-1517"],"published":"2025-03-20T12:32:41Z","modified":"2026-07-07T17:56:35.905913395Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10940"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/7d481f10102f43559cc57bcad7eba291067939ee"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c1e742347f9701aadba8920e4d1f79a636e50b68"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/e711034713259ae448981bc0fd1d7a5671499c31"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://huntr.com/bounties/be1ee1cb-2147-4ff4-a57b-b6045271cf27"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5chr-fjjv-38qv"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-63hf-3vf5-4wqf","slug":"ghsa-63hf-3vf5-4wqf-aadd9f0f","dossier":false,"summary":"AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass","aliases":["CVE-2026-34520","PYSEC-2026-2102"],"sourceIds":["GHSA-63hf-3vf5-4wqf","PYSEC-2026-2102"],"published":"2026-04-01T21:17:00.333Z","modified":"2026-07-15T22:00:51.319409225Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hf-3vf5-4wqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34520"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2026-2102.yaml"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-63hw-fmq6-xxg2","slug":"ghsa-63hw-fmq6-xxg2-00aac622","dossier":false,"summary":"aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines","aliases":["CVE-2026-54277","PYSEC-2026-2110"],"sourceIds":["GHSA-63hw-fmq6-xxg2","PYSEC-2026-2110"],"published":"2026-06-15T20:09:16Z","modified":"2026-07-13T07:26:29.010491244Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hw-fmq6-xxg2"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5ab61bb4cd88f19b712f12c7c9295fe262bf804d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-07-08T17:45:15.021597323Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7"],"packageCount":1,"repositoryCount":17},{"id":"GHSA-69f9-5gxw-wvc2","slug":"ghsa-69f9-5gxw-wvc2-eec14573","dossier":false,"summary":"AIOHTTP's unicode processing of header values could cause parsing discrepancies","aliases":["CVE-2025-69224","PYSEC-2026-1099"],"sourceIds":["GHSA-69f9-5gxw-wvc2","PYSEC-2026-1099"],"published":"2026-01-05T22:58:57Z","modified":"2026-07-07T17:56:40.774148412Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-69f9-5gxw-wvc2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69224"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/32677f2adfd907420c078dda6b79225c6f4ebce0"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69f9-5gxw-wvc2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6jhg-hg63-jvvf","slug":"ghsa-6jhg-hg63-jvvf-74cd77d8","dossier":false,"summary":"AIOHTTP vulnerable to  denial of service through large payloads","aliases":["CVE-2025-69228","PYSEC-2026-1100"],"sourceIds":["GHSA-6jhg-hg63-jvvf","PYSEC-2026-1100"],"published":"2026-01-05T23:13:14Z","modified":"2026-07-07T17:57:35.249454020Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69228"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jhg-hg63-jvvf"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6mq8-rvhq-8wgg","slug":"ghsa-6mq8-rvhq-8wgg-d94d738f","dossier":false,"summary":"AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb","aliases":["CVE-2025-69223","PYSEC-2026-1101"],"sourceIds":["GHSA-6mq8-rvhq-8wgg","PYSEC-2026-1101"],"published":"2026-01-05T22:58:41Z","modified":"2026-07-07T17:56:11.402262091Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69223"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6mq8-rvhq-8wgg"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6qv9-48xg-fc7f","slug":"ghsa-6qv9-48xg-fc7f-6f0bc426","dossier":false,"summary":"LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates","aliases":["CVE-2025-65106","PYSEC-2026-1518"],"sourceIds":["GHSA-6qv9-48xg-fc7f","PYSEC-2026-1518"],"published":"2025-11-20T17:42:12Z","modified":"2026-07-07T17:57:16.939269197Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-6qv9-48xg-fc7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65106"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c4b6ba254e1a49ed91f2e268e6484011c540542a"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/fa7789d6c21222b85211755d822ef698d3b34e00"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6qv9-48xg-fc7f"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-926x-3r5x-gfhw","slug":"ghsa-926x-3r5x-gfhw-b7d12e65","dossier":false,"summary":"LangChain has incomplete f-string validation in prompt templates","aliases":["CVE-2026-40087","PYSEC-2026-2563"],"sourceIds":["GHSA-926x-3r5x-gfhw","PYSEC-2026-2563"],"published":"2026-04-08T21:51:32Z","modified":"2026-07-13T16:42:42.901211235Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-926x-3r5x-gfhw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40087"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36612"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36613"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/6bab0ba3c12328008ddca3e0d54ff5a6151cd27b"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/af2ed47c6f008cdd551f3c0d87db3774c8dfe258"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.84"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.28"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-926x-3r5x-gfhw"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-9548-qrrj-x5pj","slug":"ghsa-9548-qrrj-x5pj-6121f213","dossier":false,"summary":"AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections","aliases":["CVE-2025-53643","PYSEC-2026-1104"],"sourceIds":["GHSA-9548-qrrj-x5pj","PYSEC-2026-1104"],"published":"2025-07-14T19:33:31Z","modified":"2026-07-07T17:56:52.935544397Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9548-qrrj-x5pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53643"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9548-qrrj-x5pj"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-966j-vmvw-g2g9","slug":"ghsa-966j-vmvw-g2g9-dad9a989","dossier":false,"summary":"AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect","aliases":["CVE-2026-34518","PYSEC-2026-2100"],"sourceIds":["GHSA-966j-vmvw-g2g9","PYSEC-2026-2100"],"published":"2026-04-01T21:17:00.020Z","modified":"2026-07-13T07:26:39.502317923Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-966j-vmvw-g2g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34518"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-9hjg-9r4m-mvj7","slug":"ghsa-9hjg-9r4m-mvj7-32d7b63e","dossier":false,"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"sourceIds":["GHSA-9hjg-9r4m-mvj7","PYSEC-2026-1872"],"published":"2025-06-09T19:06:08Z","modified":"2026-07-07T17:56:56.234172558Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6965"},{"type":"FIX","url":"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2025/Jun/2"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-9wx4-h78v-vm56","slug":"ghsa-9wx4-h78v-vm56-6a334c57","dossier":false,"summary":"Requests `Session` object does not verify requests after making first request with verify=False","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"sourceIds":["GHSA-9wx4-h78v-vm56","PYSEC-2026-1873"],"published":"2024-05-20T20:15:00Z","modified":"2026-07-07T17:57:17.012984050Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6655"},{"type":"FIX","url":"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wx4-h78v-vm56"}],"versionKeys":["pypi:requests@2.31.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9x8q-7h8h-wcw9","slug":"ghsa-9x8q-7h8h-wcw9-af94166e","dossier":false,"summary":"aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect","aliases":["CVE-2026-54280","PYSEC-2026-2113"],"sourceIds":["GHSA-9x8q-7h8h-wcw9","PYSEC-2026-2113"],"published":"2026-06-15T20:10:44Z","modified":"2026-07-13T07:26:14.649569270Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9x8q-7h8h-wcw9"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c427-h43c-vf67","slug":"ghsa-c427-h43c-vf67-fa5b38aa","dossier":false,"summary":"AIOHTTP accepts duplicate Host headers","aliases":["CVE-2026-34525","PYSEC-2026-2103"],"sourceIds":["GHSA-c427-h43c-vf67","PYSEC-2026-2103"],"published":"2026-04-01T21:17:00.490Z","modified":"2026-07-13T07:26:42.158681139Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34525"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c67j-w6g6-q2cm","slug":"ghsa-c67j-w6g6-q2cm-a4c5c0cf","dossier":false,"summary":"LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs","aliases":["CVE-2025-68664","PYSEC-2026-373"],"sourceIds":["GHSA-c67j-w6g6-q2cm","PYSEC-2026-373"],"published":"2025-12-23T18:46:13Z","modified":"2026-07-02T13:00:05.018724776Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68664"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34455"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34458"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/d9ec4c5cc78960abd37da79b0250f5642e6f0ce6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.81"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.5"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c67j-w6g6-q2cm"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f4xh-w4cj-qxq8","slug":"ghsa-f4xh-w4cj-qxq8-981d76df","dossier":false,"summary":"LangSmith SDK TracingMiddleware: Arbitrary server-side file read","aliases":["CVE-2026-59152"],"sourceIds":["GHSA-f4xh-w4cj-qxq8"],"published":"2026-06-19T22:10:34Z","modified":"2026-07-08T08:26:43.324048749Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-f4xh-w4cj-qxq8"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"}],"versionKeys":["pypi:langsmith@0.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fh55-r93g-j68g","slug":"ghsa-fh55-r93g-j68g-a231bc8e","dossier":false,"summary":"AIOHTTP Vulnerable to Cookie Parser Warning Storm","aliases":["CVE-2025-69230","PYSEC-2026-1105"],"sourceIds":["GHSA-fh55-r93g-j68g","PYSEC-2026-1105"],"published":"2026-01-05T23:13:46Z","modified":"2026-07-07T17:56:34.702331996Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-fh55-r93g-j68g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69230"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/64629a0834f94e46d9881f4e99c41a137e1f3326"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh55-r93g-j68g"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-fjqc-hq36-qh5p","slug":"ghsa-fjqc-hq36-qh5p-fbc7458c","dossier":false,"summary":"LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading","aliases":["CVE-2026-48775","PYSEC-2026-2573"],"sourceIds":["GHSA-fjqc-hq36-qh5p","PYSEC-2026-2573"],"published":"2026-06-25T18:25:42Z","modified":"2026-07-13T16:42:57.455268050Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-fjqc-hq36-qh5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48775"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"PACKAGE","url":"https://pypi.org/project/langgraph-checkpoint"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fjqc-hq36-qh5p"}],"versionKeys":["pypi:langgraph-checkpoint@4.0.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fv5p-p927-qmxr","slug":"ghsa-fv5p-p927-qmxr-2692dd04","dossier":false,"summary":"LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass","aliases":["CVE-2026-41481","PYSEC-2026-77"],"sourceIds":["GHSA-fv5p-p927-qmxr","PYSEC-2026-77"],"published":"2026-04-16T22:53:32Z","modified":"2026-06-06T01:15:07.890699366Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-fv5p-p927-qmxr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41481"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-text-splitters/PYSEC-2026-77.yaml"}],"versionKeys":["pypi:langchain-text-splitters@1.1.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g3cq-j2xw-wf74","slug":"ghsa-g3cq-j2xw-wf74-4475e17b","dossier":false,"summary":"aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup","aliases":["CVE-2026-54278","PYSEC-2026-2111"],"sourceIds":["GHSA-g3cq-j2xw-wf74","PYSEC-2026-2111"],"published":"2026-06-15T20:09:51Z","modified":"2026-07-13T07:26:25.190325605Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g3cq-j2xw-wf74"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-g48c-2wqr-h844","slug":"ghsa-g48c-2wqr-h844-48f35247","dossier":false,"summary":"LangGraph checkpoint loading has unsafe msgpack deserialization","aliases":["CVE-2026-28277","PYSEC-2026-83"],"sourceIds":["GHSA-g48c-2wqr-h844","PYSEC-2026-83"],"published":"2026-03-05T20:16:15.677Z","modified":"2026-06-06T01:00:08.116125988Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-g48c-2wqr-h844"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28277"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langgraph/PYSEC-2026-83.yaml"}],"versionKeys":["pypi:langgraph@0.1.1","pypi:langgraph@0.3.21","pypi:langgraph@1.0.6"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-g7vv-2v7x-gj9p","slug":"ghsa-g7vv-2v7x-gj9p-5ef970c3","dossier":false,"summary":"tqdm CLI arguments injection attack","aliases":["CVE-2024-34062","PYSEC-2026-1976"],"sourceIds":["GHSA-g7vv-2v7x-gj9p","PYSEC-2026-1976"],"published":"2024-05-03T19:33:28Z","modified":"2026-07-07T17:56:20.187915678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"},{"type":"WEB","url":"https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316"},{"type":"PACKAGE","url":"https://github.com/tqdm/tqdm"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC"},{"type":"PACKAGE","url":"https://pypi.org/project/tqdm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7vv-2v7x-gj9p"}],"versionKeys":["pypi:tqdm@4.66.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g84x-mcqj-x9qq","slug":"ghsa-g84x-mcqj-x9qq-fc677e5d","dossier":false,"summary":"AIOHTTP vulnerable to DoS through chunked messages","aliases":["CVE-2025-69229","PYSEC-2026-1106"],"sourceIds":["GHSA-g84x-mcqj-x9qq","PYSEC-2026-1106"],"published":"2026-01-05T23:13:29Z","modified":"2026-07-07T17:56:31.463290158Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g84x-mcqj-x9qq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g84x-mcqj-x9qq"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-gc5v-m9x4-r6x2","slug":"ghsa-gc5v-m9x4-r6x2-b9828ad8","dossier":true,"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"sourceIds":["GHSA-gc5v-m9x4-r6x2","PYSEC-2026-2275"],"published":"2026-03-25T16:56:28Z","modified":"2026-07-13T07:26:34.091663004Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645"},{"type":"FIX","url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"ADVISORY","url":"https://github.com/psf/requests/releases/tag/v2.33.0"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3","pypi:requests@2.32.4","pypi:requests@2.32.5"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-gm62-xv2j-4w53","slug":"ghsa-gm62-xv2j-4w53-5befa184","dossier":true,"summary":"urllib3 allows an unbounded number of links in the decompression chain","aliases":["CVE-2025-66418","PYSEC-2026-1998"],"sourceIds":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"published":"2025-12-05T18:15:19Z","modified":"2026-07-07T17:57:28.931610368Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm62-xv2j-4w53"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-gr75-jv2w-4656","slug":"ghsa-gr75-jv2w-4656-a5b8c61e","dossier":false,"summary":"LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","aliases":["CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556"],"sourceIds":["GHSA-gr75-jv2w-4656","PYSEC-2026-2192"],"published":"2026-06-16T15:03:14Z","modified":"2026-07-13T16:43:09.845932020Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-gr75-jv2w-4656"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55443"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"}],"versionKeys":["pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langchain@1.2.6","pypi:langchain@1.3.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-hcc4-c3v8-rx92","slug":"ghsa-hcc4-c3v8-rx92-ddf32b5c","dossier":false,"summary":"AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector","aliases":["CVE-2026-34513","PYSEC-2026-2095"],"sourceIds":["GHSA-hcc4-c3v8-rx92","PYSEC-2026-2095"],"published":"2026-04-01T21:16:59.267Z","modified":"2026-07-13T07:26:43.174352940Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hcc4-c3v8-rx92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34513"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hg6j-4rv6-33pg","slug":"ghsa-hg6j-4rv6-33pg-d0ac8db0","dossier":false,"summary":"AIOHTTP is vulnerable to cross-origin redirect with per-request cookies","aliases":["CVE-2026-47265","PYSEC-2026-2105"],"sourceIds":["GHSA-hg6j-4rv6-33pg","PYSEC-2026-2105"],"published":"2026-06-02T20:16:37.903Z","modified":"2026-07-13T07:26:51.969507320Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hg6j-4rv6-33pg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47265"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hpj7-wq8m-9hgp","slug":"ghsa-hpj7-wq8m-9hgp-fac25647","dossier":false,"summary":"aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges","aliases":["CVE-2026-54276","PYSEC-2026-2109"],"sourceIds":["GHSA-hpj7-wq8m-9hgp","PYSEC-2026-2109"],"published":"2026-06-15T20:09:06Z","modified":"2026-07-13T07:26:28.701980401Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hpj7-wq8m-9hgp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/38d16060037e1bfcd6d677abababa3c2a4bb58fa"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hx9q-6w63-j58v","slug":"ghsa-hx9q-6w63-j58v-8d6e2248","dossier":false,"summary":"orjson does not limit recursion for deeply nested JSON documents","aliases":["CVE-2025-67221","PYSEC-2026-107"],"sourceIds":["GHSA-hx9q-6w63-j58v","PYSEC-2026-107"],"published":"2026-01-22T17:16:01.433Z","modified":"2026-06-10T17:02:27.794281728Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67221"},{"type":"WEB","url":"https://github.com/ijl/orjson/issues/620"},{"type":"WEB","url":"https://github.com/kpatsakis/CVE-2025-67221/issues/1"},{"type":"WEB","url":"https://github.com/ijl/orjson/commit/62bb185b70785ded49c79c26f8c9781f1e6fe370"},{"type":"PACKAGE","url":"https://github.com/ijl/orjson"},{"type":"EVIDENCE","url":"https://github.com/kpatsakis/orjson_vulnerability"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/orjson/PYSEC-2026-107.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hx9q-6w63-j58v"}],"versionKeys":["pypi:orjson@3.10.14","pypi:orjson@3.10.15","pypi:orjson@3.11.4","pypi:orjson@3.11.5"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-jg22-mg44-37j8","slug":"ghsa-jg22-mg44-37j8-b8064c77","dossier":false,"summary":"AIOHTTP is Vulnerable to Deserialization of Untrusted Data","aliases":["CVE-2026-34993","PYSEC-2026-2104"],"sourceIds":["GHSA-jg22-mg44-37j8","PYSEC-2026-2104"],"published":"2026-06-02T20:16:34.857Z","modified":"2026-07-13T07:26:37.684367184Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-jj3x-wxrx-4x23","slug":"ghsa-jj3x-wxrx-4x23-407bafac","dossier":false,"summary":"AIOHTTP vulnerable to DoS when bypassing asserts","aliases":["CVE-2025-69227","PYSEC-2026-1107"],"sourceIds":["GHSA-jj3x-wxrx-4x23","PYSEC-2026-1107"],"published":"2026-01-05T23:10:15Z","modified":"2026-07-07T17:57:17.782415842Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jj3x-wxrx-4x23"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69227"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj3x-wxrx-4x23"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-m5qp-6w8w-w647","slug":"ghsa-m5qp-6w8w-w647-495897bd","dossier":false,"summary":"AIOHTTP has a Multipart Header Size Bypass","aliases":["CVE-2026-34516","PYSEC-2026-2098"],"sourceIds":["GHSA-m5qp-6w8w-w647","PYSEC-2026-2098"],"published":"2026-04-01T21:16:59.723Z","modified":"2026-07-13T07:26:19.821892403Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m5qp-6w8w-w647"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34516"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/8a74257b3804c9aac0bf644af93070f68f6c5a6f"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-m6qw-4cw2-hm4m","slug":"ghsa-m6qw-4cw2-hm4m-3f6d3ee7","dossier":false,"summary":"aiohttp: CRLF injection in multipart headers","aliases":["CVE-2026-50269","PYSEC-2026-2106"],"sourceIds":["GHSA-m6qw-4cw2-hm4m","PYSEC-2026-2106"],"published":"2026-06-15T20:07:26Z","modified":"2026-07-13T07:26:17.983947245Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-mf9v-mfxr-j63j","slug":"ghsa-mf9v-mfxr-j63j-1a7db6d4","dossier":false,"summary":"urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API","aliases":["CVE-2026-44432","PYSEC-2026-142"],"sourceIds":["GHSA-mf9v-mfxr-j63j","PYSEC-2026-142"],"published":"2026-05-11T14:51:45Z","modified":"2026-06-08T20:00:12.284378628Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mf9w-mj56-hr94","slug":"ghsa-mf9w-mj56-hr94-a492e0f4","dossier":false,"summary":"python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback","aliases":["CVE-2026-28684","PYSEC-2026-2270"],"sourceIds":["GHSA-mf9w-mj56-hr94","PYSEC-2026-2270"],"published":"2026-04-20T17:16:33.087Z","modified":"2026-07-13T07:26:26.604845458Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/security/advisories/GHSA-mf9w-mj56-hr94"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28684"},{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311"},{"type":"WEB","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311.patch"},{"type":"PACKAGE","url":"https://github.com/theskumar/python-dotenv"},{"type":"ADVISORY","url":"https://github.com/theskumar/python-dotenv/releases/tag/v1.2.2"}],"versionKeys":["pypi:python-dotenv@1.0.1","pypi:python-dotenv@1.1.0","pypi:python-dotenv@1.1.1","pypi:python-dotenv@1.2.1"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-mqqc-3gqh-h2x8","slug":"ghsa-mqqc-3gqh-h2x8-6d702daf","dossier":false,"summary":"AIOHTTP has unicode match groups in regexes for ASCII protocol elements","aliases":["CVE-2025-69225","PYSEC-2026-1109"],"sourceIds":["GHSA-mqqc-3gqh-h2x8","PYSEC-2026-1109"],"published":"2026-01-05T23:09:30Z","modified":"2026-07-07T17:56:18.569417663Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69225"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqqc-3gqh-h2x8"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mwh4-6h8g-pg8w","slug":"ghsa-mwh4-6h8g-pg8w-881420d8","dossier":false,"summary":"AIOHTTP has HTTP response splitting via \\r in reason phrase","aliases":["CVE-2026-34519","PYSEC-2026-2101"],"sourceIds":["GHSA-mwh4-6h8g-pg8w","PYSEC-2026-2101"],"published":"2026-04-01T21:17:00.170Z","modified":"2026-07-13T07:26:39.246105773Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mwh4-6h8g-pg8w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34519"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53b35a2f8869c37a133e60bf1a82a1c01642ba2b"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-p998-jp59-783m","slug":"ghsa-p998-jp59-783m-17c88f0d","dossier":false,"summary":"AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows","aliases":["CVE-2026-34515","PYSEC-2026-2097"],"sourceIds":["GHSA-p998-jp59-783m","PYSEC-2026-2097"],"published":"2026-04-01T21:16:59.570Z","modified":"2026-07-13T07:26:55.790859426Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34515"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-pc6w-59fv-rh23","slug":"ghsa-pc6w-59fv-rh23-cab9cb2f","dossier":false,"summary":"Langchain Community Vulnerable to XML External Entity (XXE) Attacks","aliases":["CVE-2025-6984","PYSEC-2026-1515"],"sourceIds":["GHSA-pc6w-59fv-rh23","PYSEC-2026-1515"],"published":"2025-09-04T12:30:42Z","modified":"2026-07-07T17:56:45.822570559Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6984"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain-community"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23"},{"type":"WEB","url":"https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pc6w-59fv-rh23"}],"versionKeys":["pypi:langchain-community@0.2.7","pypi:langchain-community@0.3.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pjwx-r37v-7724","slug":"ghsa-pjwx-r37v-7724-2297a72a","dossier":false,"summary":"LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists","aliases":["CVE-2026-44843","PYSEC-2026-2564"],"sourceIds":["GHSA-pjwx-r37v-7724","PYSEC-2026-2564"],"published":"2026-05-08T23:07:32Z","modified":"2026-07-13T16:42:39.210995356Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-pjwx-r37v-7724"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44843"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pjwx-r37v-7724"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pq67-6m6q-mj2v","slug":"ghsa-pq67-6m6q-mj2v-3522d1d4","dossier":false,"summary":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","aliases":["CVE-2025-50181","PYSEC-2026-1999"],"sourceIds":["GHSA-pq67-6m6q-mj2v","PYSEC-2026-1999"],"published":"2025-06-18T17:50:00Z","modified":"2026-07-07T17:56:41.872294653Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-q25c-c977-4cmh","slug":"ghsa-q25c-c977-4cmh-8e74e348","dossier":false,"summary":"Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever","aliases":["CVE-2024-3095","PYSEC-2026-1516"],"sourceIds":["GHSA-q25c-c977-4cmh","PYSEC-2026-1516"],"published":"2024-06-06T21:30:36Z","modified":"2026-07-07T17:57:27.127785500Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3095"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/24451"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-community%3D%3D0.2.9"},{"type":"WEB","url":"https://huntr.com/bounties/e62d4895-2901-405b-9559-38276b6a5273"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q25c-c977-4cmh"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qccp-gfcp-xxvc","slug":"ghsa-qccp-gfcp-xxvc-0d988969","dossier":true,"summary":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects","aliases":["CVE-2026-44431","PYSEC-2026-141"],"sourceIds":["GHSA-qccp-gfcp-xxvc","PYSEC-2026-141"],"published":"2026-05-11T14:51:20Z","modified":"2026-05-20T09:19:20.983812Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-qh6h-p6c9-ff54","slug":"ghsa-qh6h-p6c9-ff54-caf42ff5","dossier":false,"summary":"LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions","aliases":["CVE-2026-34070","PYSEC-2026-2193"],"sourceIds":["GHSA-qh6h-p6c9-ff54","PYSEC-2026-2193"],"published":"2026-03-27T19:45:00Z","modified":"2026-07-13T07:26:33.913236655Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-qh6h-p6c9-ff54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34070"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/27add913474e01e33bededf4096151130ba0d47c"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core==1.2.22"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34070"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34070.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24766"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453287"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-r7w7-9xr2-qq2r","slug":"ghsa-r7w7-9xr2-qq2r-7a3a0a91","dossier":false,"summary":"langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding","aliases":["CVE-2026-41488","PYSEC-2026-76"],"sourceIds":["GHSA-r7w7-9xr2-qq2r","PYSEC-2026-76"],"published":"2026-04-16T23:00:12Z","modified":"2026-06-06T01:15:07.912179267Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-r7w7-9xr2-qq2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41488"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-openai/PYSEC-2026-76.yaml"}],"versionKeys":["pypi:langchain-openai@0.2.8","pypi:langchain-openai@1.1.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-rr7j-v2q5-chgv","slug":"ghsa-rr7j-v2q5-chgv-a773969e","dossier":false,"summary":"LangSmith SDK: Streaming token events bypass output redaction","aliases":["CVE-2026-41182","PYSEC-2026-2583"],"sourceIds":["GHSA-rr7j-v2q5-chgv","PYSEC-2026-2583"],"published":"2026-04-16T01:20:37Z","modified":"2026-07-13T16:43:37.566182133Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-rr7j-v2q5-chgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41182"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rr7j-v2q5-chgv"}],"versionKeys":["pypi:langsmith@0.6.4"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vqfr-h8mv-ghfj","slug":"ghsa-vqfr-h8mv-ghfj-49515033","dossier":false,"summary":"h11 accepts some malformed Chunked-Encoding bodies","aliases":["CVE-2025-43859","PYSEC-2026-348"],"sourceIds":["GHSA-vqfr-h8mv-ghfj","PYSEC-2026-348"],"published":"2025-04-24T16:07:56Z","modified":"2026-07-01T20:22:54.082067Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43859"},{"type":"WEB","url":"https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h11"},{"type":"PACKAGE","url":"https://pypi.org/project/h11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqfr-h8mv-ghfj"}],"versionKeys":["pypi:h11@0.14.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-w2fm-2cpv-w7v5","slug":"ghsa-w2fm-2cpv-w7v5-c2f7701a","dossier":false,"summary":"aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage","aliases":["CVE-2026-22815","PYSEC-2026-2094"],"sourceIds":["GHSA-w2fm-2cpv-w7v5","PYSEC-2026-2094"],"published":"2026-04-01T19:45:17Z","modified":"2026-07-13T07:26:28.950069528Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-w2fm-2cpv-w7v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22815"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-w39p-vh2g-g8g5","slug":"ghsa-w39p-vh2g-g8g5-47880dfe","dossier":false,"summary":"LangGraph SDK has unsafe URL path construction","aliases":["CVE-2026-48776","PYSEC-2026-2194","PYSEC-2026-2575"],"sourceIds":["GHSA-w39p-vh2g-g8g5","PYSEC-2026-2194","PYSEC-2026-2575"],"published":"2026-06-17T10:55:15.113Z","modified":"2026-07-13T16:42:27.619863658Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-w39p-vh2g-g8g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48776"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/releases/tag/sdk%3D%3D0.3.15"},{"type":"PACKAGE","url":"https://pypi.org/project/langgraph-sdk"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w39p-vh2g-g8g5"}],"versionKeys":["pypi:langgraph-sdk@0.3.3","pypi:langgraph@0.1.1"],"packageCount":2,"repositoryCount":2},{"id":"GHSA-xcgm-r5h9-7989","slug":"ghsa-xcgm-r5h9-7989-77bcbc26","dossier":false,"summary":"aiohttp: Incomplete websocket frame payloads bypass memory limits","aliases":["CVE-2026-54274","PYSEC-2026-2108"],"sourceIds":["GHSA-xcgm-r5h9-7989","PYSEC-2026-2108"],"published":"2026-06-15T20:11:22Z","modified":"2026-07-13T07:26:54.330692251Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"PYSEC-2024-323","slug":"pysec-2024-323-1dd96856","dossier":false,"summary":null,"aliases":["CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514"],"sourceIds":["PYSEC-2024-323"],"published":"2024-09-17T12:15:02.977Z","modified":"2026-07-13T07:26:23.643495355Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"}],"versionKeys":["pypi:langchain@0.2.7"],"packageCount":1,"repositoryCount":1}]}}
