{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-10-01T06:23:02.848Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-10-01T06:19:50.815Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.29.0","releaseDate":"2026-09-16T00:00:00Z"}},"coverage":{"repositoryCount":44,"completeTreeCount":43,"incompleteTreeCount":1,"lockfileRepositoryCount":24,"sbomRepositoryCount":4,"artifactRepositoryCount":27,"resolvedRepositoryCount":41,"resolvedArtifactRepositoryCount":27,"dependencyFileCount":39,"parsedFileCount":38,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4135,"metadataResolvedCount":4124,"metadataNotFoundCount":11,"osvEvaluatedVersionCount":4135,"codeRadarRepositoryCount":44},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":8000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":44,"packageCount":2467,"aiPackageCount":50,"resolvedComponentCount":7265,"resolvedVersionCount":4135,"providerExposureRepositoryCount":9,"licenseExpressionCount":55,"knownLicensePackageCount":2433,"unknownLicensePackageCount":34,"advisoryCount":852,"matchedAdvisoryRepositoryCount":38,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":24,"repositoryShare":0.5454545454545454}},"kind":"repository","entity":{"id":"opencode:9852","slug":"opencode-9852","gitlabProjectId":9852,"name":"Datastore","pathWithNamespace":"f13/microservices/datastore","description":"Mandantenfähiger Datenspeicher für individuelle und gruppenbezogene Wissensdatenbanken für F13.","webUrl":"https://gitlab.opencode.de/f13/microservices/datastore","commitSha":"d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb","commitUrl":"https://gitlab.opencode.de/f13/microservices/datastore/-/commit/d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb","lastActivityAt":"2026-09-30T12:22:10.914Z","headCommittedAt":"2026-09-30T12:59:03.000Z","tree":{"complete":true,"entryCount":372,"truncated":false},"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"e0610ba7ea5ec17b3a76a73214cd40b77714c857","sourceUrl":"https://gitlab.opencode.de/f13/microservices/datastore/-/blob/d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb/uv.lock","commitSha":"d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb","contentSha256":"6595b6f54571e9af6cc1d55f3a760e5ca4e6191eb5043f8cea081d53d833f9e6","byteCount":432979,"state":"parsed","componentCount":117}],"resolvedComponentCount":119,"artifactResolvedComponentCount":117,"exactManifestPinCount":2,"packageCount":117,"ecosystems":["pypi"],"aiPackageCount":1,"licenseExpressionCount":16,"unknownLicensePackageCount":1,"advisoryIds":["GHSA-248v-346w-9cwc","GHSA-2c2j-9gv5-cj73","GHSA-2fqr-mr3j-6wp8","GHSA-2gx3-rcp4-g85q","GHSA-2vrm-gr82-f7m5","GHSA-2xpw-w6gg-jr37","GHSA-38jv-5279-wg99","GHSA-3wq7-rqq7-wx6j","GHSA-42vr-xj54-vc7v","GHSA-48p4-8xcf-vxj5","GHSA-4fvr-rgm6-gqmc","GHSA-4m7w-qmgq-4wj5","GHSA-4xgf-cpjx-pc3j","GHSA-5239-wwwm-4pmq","GHSA-537c-gmf6-5ccf","GHSA-54jq-c3m8-4m76","GHSA-597g-3phw-6986","GHSA-59g5-xgcq-4qw3","GHSA-5p39-cfhj-2xmp","GHSA-5rvq-cxj2-64vf","GHSA-63hf-3vf5-4wqf","GHSA-63hw-fmq6-xxg2","GHSA-65pc-fj4g-8rjx","GHSA-69f9-5gxw-wvc2","GHSA-6jhg-hg63-jvvf","GHSA-6jv3-5f52-599m","GHSA-6mq8-rvhq-8wgg","GHSA-6w46-j5rx-g56g","GHSA-752w-5fwx-jx9f","GHSA-79v4-65xg-pq4g","GHSA-7f5h-v6xp-fcq8","GHSA-7gcm-g887-7qv7","GHSA-82r6-8w77-94w6","GHSA-82w8-qh3p-5jfq","GHSA-86qp-5c8j-p5mr","GHSA-8988-9cw3-xx77","GHSA-8qvm-5x2c-j2w7","GHSA-8wjv-2p76-3863","GHSA-94p9-xgh2-xp45","GHSA-9548-qrrj-x5pj","GHSA-966j-vmvw-g2g9","GHSA-993g-76c3-p5m4","GHSA-9h52-p55h-vw2f","GHSA-9h9j-4vrj-gf7g","GHSA-9hjg-9r4m-mvj7","GHSA-9j54-fg26-wv3r","GHSA-9v7f-9g4p-ffgj","GHSA-9wx4-h78v-vm56","GHSA-9x8q-7h8h-wcw9","GHSA-c427-h43c-vf67","GHSA-cpwx-vrp4-4pq7","GHSA-cq5v-8q36-5273","GHSA-f96h-pmfr-66vw","GHSA-ffc3-869f-jxw9","GHSA-fh55-r93g-j68g","GHSA-fhv5-28vv-h8m8","GHSA-g3cq-j2xw-wf74","GHSA-g6cj-pr64-35w5","GHSA-g7vv-2v7x-gj9p","GHSA-g84x-mcqj-x9qq","GHSA-gc5v-m9x4-r6x2","GHSA-gh4c-6fx4-qh6g","GHSA-gm62-xv2j-4w53","GHSA-gmj6-6f8f-6699","GHSA-gvp8-978c-rx2q","GHSA-h4gh-qq45-vh27","GHSA-h75v-3vvj-5mfj","GHSA-hcc4-c3v8-rx92","GHSA-hg6j-4rv6-33pg","GHSA-hpj7-wq8m-9hgp","GHSA-hxm8-2xgr-2p9m","GHSA-jg22-mg44-37j8","GHSA-jj3x-wxrx-4x23","GHSA-jp82-jpqv-5vv3","GHSA-jpw9-pfvf-9f58","GHSA-jq35-7prp-9v3f","GHSA-jwrc-g2q2-pq5p","GHSA-jwv3-5hgf-82ww","GHSA-m2h6-j472-rp4c","GHSA-m5qp-6w8w-w647","GHSA-m6qw-4cw2-hm4m","GHSA-m959-cc7f-wv43","GHSA-mf9v-mfxr-j63j","GHSA-mf9w-mj56-hr94","GHSA-mfx4-hv73-q22v","GHSA-mj87-hwqh-73pj","GHSA-mq44-7p77-q5h7","GHSA-mqqc-3gqh-h2x8","GHSA-mwh4-6h8g-pg8w","GHSA-p423-j2cm-9vmq","GHSA-p4g4-x82p-q773","GHSA-p998-jp59-783m","GHSA-pp6c-gr5w-3c5g","GHSA-pq67-6m6q-mj2v","GHSA-q2x7-8rv6-6q7h","GHSA-qccp-gfcp-xxvc","GHSA-qmgc-5h2g-mvrw","GHSA-r6ph-v2qm-q3c2","GHSA-r6x4-923q-g947","GHSA-v9pg-7xvm-68hf","GHSA-vffw-93wf-4j4q","GHSA-vj7q-gjh5-988w","GHSA-vqfr-h8mv-ghfj","GHSA-vxq7-64xx-v4gw","GHSA-w2cx-738m-mc7w","GHSA-w2fm-2cpv-w7v5","GHSA-w6j9-cwv2-h6wq","GHSA-w7vc-732c-9m39","GHSA-w853-jp5j-5j7f","GHSA-wp53-j4wj-2cfg","GHSA-wqp7-x3pw-xc5r","GHSA-x746-7m8f-x49c","GHSA-xcgm-r5h9-7989","GHSA-xgmm-8j9v-c9wx","PYSEC-2025-183","PYSEC-2026-2132","PYSEC-2026-4013","PYSEC-2026-4014"],"advisoryCount":118,"providers":[]},"evidence":{"files":[{"path":"requirements-dev.txt","kind":"exact-manifest-pin","sourceUrl":"https://gitlab.opencode.de/f13/microservices/datastore/-/blob/d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb/requirements-dev.txt","commitSha":"d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb","blobSha":"700e298eb4ae818f9d220157c3b33e0240fab289","state":"parsed","componentCount":1},{"path":"requirements.txt","kind":"exact-manifest-pin","sourceUrl":"https://gitlab.opencode.de/f13/microservices/datastore/-/blob/d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb/requirements.txt","commitSha":"d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb","blobSha":"ad3c5204a854c4f69e0d5d638f0d031882cbc968","state":"parsed","componentCount":1},{"path":"uv.lock","kind":"uv-lock","blobSha":"e0610ba7ea5ec17b3a76a73214cd40b77714c857","sourceUrl":"https://gitlab.opencode.de/f13/microservices/datastore/-/blob/d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb/uv.lock","commitSha":"d69c3e5b02c3ba9b93fd65ac8b7efb2ca0c715bb","contentSha256":"6595b6f54571e9af6cc1d55f3a760e5ca4e6191eb5043f8cea081d53d833f9e6","byteCount":432979,"state":"parsed","componentCount":117}],"occurrenceCount":119},"related":{"packages":[{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.45.0"],"dossier":true,"occurrenceCount":3,"directOccurrenceCount":0,"evidenceFiles":["requirements-dev.txt","requirements.txt","uv.lock"]},{"id":"package:pypi:aiohttp","slug":"aiohttp-5a806a63","identity":"pypi:aiohttp","label":"aiohttp","aiRelevant":false,"provider":null,"advisoryCount":33,"licenseExpressions":["Apache-2.0","Apache-2.0 AND MIT"],"versions":["3.14.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyjwt","slug":"pyjwt-b1ea166e","identity":"pypi:pyjwt","label":"pyjwt","aiRelevant":false,"provider":null,"advisoryCount":20,"licenseExpressions":["MIT"],"versions":["2.15.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:urllib3","slug":"urllib3-fa68f32c","identity":"pypi:urllib3","label":"urllib3","aiRelevant":false,"provider":null,"advisoryCount":10,"licenseExpressions":["MIT"],"versions":["2.7.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cryptography","slug":"cryptography-de36c9c8","identity":"pypi:cryptography","label":"cryptography","aiRelevant":false,"provider":null,"advisoryCount":9,"licenseExpressions":["Apache-2.0 OR BSD-3-Clause"],"versions":["50.0.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-multipart","slug":"python-multipart-7d2a810e","identity":"pypi:python-multipart","label":"python-multipart","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["Apache-2.0"],"versions":["0.0.32"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:starlette","slug":"starlette-beb9e527","identity":"pypi:starlette","label":"starlette","aiRelevant":false,"provider":null,"advisoryCount":8,"licenseExpressions":["BSD-3-Clause"],"versions":["1.3.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:virtualenv","slug":"virtualenv-aeb2a546","identity":"pypi:virtualenv","label":"virtualenv","aiRelevant":false,"provider":null,"advisoryCount":5,"licenseExpressions":["MIT"],"versions":["21.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jinja2","slug":"jinja2-f7d34747","identity":"pypi:jinja2","label":"jinja2","aiRelevant":false,"provider":null,"advisoryCount":4,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mcp","slug":"mcp-ef053766","identity":"pypi:mcp","label":"mcp","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["1.29.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:requests","slug":"requests-53653f76","identity":"pypi:requests","label":"requests","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["Apache-2.0"],"versions":["2.34.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:anyio","slug":"anyio-399e5280","identity":"pypi:anyio","label":"anyio","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["4.14.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:filelock","slug":"filelock-b1c63968","identity":"pypi:filelock","label":"filelock","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT","Unlicense"],"versions":["3.32.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:protobuf","slug":"protobuf-6e30009a","identity":"pypi:protobuf","label":"protobuf","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["BSD-3-Clause"],"versions":["7.35.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:certifi","slug":"certifi-d4f0c37e","identity":"pypi:certifi","label":"certifi","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MPL-2.0"],"versions":["2026.6.17"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click","slug":"click-ef97f731","identity":"pypi:click","label":"click","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["8.4.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:h11","slug":"h11-48165ab1","identity":"pypi:h11","label":"h11","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.18"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-settings","slug":"pydantic-settings-d677745f","identity":"pypi:pydantic-settings","label":"pydantic-settings","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["2.14.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pygments","slug":"pygments-ad71bc11","identity":"pypi:pygments","label":"pygments","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-2-Clause"],"versions":["2.20.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest","slug":"pytest-07c6f86c","identity":"pypi:pytest","label":"pytest","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["9.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dotenv","slug":"python-dotenv-27b12285","identity":"pypi:python-dotenv","label":"python-dotenv","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause"],"versions":["1.2.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tqdm","slug":"tqdm-04b01f90","identity":"pypi:tqdm","label":"tqdm","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT AND MPL-2.0"],"versions":["4.68.4"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohappyeyeballs","slug":"aiohappyeyeballs-ea4657b8","identity":"pypi:aiohappyeyeballs","label":"aiohappyeyeballs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["2.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiosignal","slug":"aiosignal-b6794e75","identity":"pypi:aiosignal","label":"aiosignal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:amqp","slug":"amqp-b7c07d93","identity":"pypi:amqp","label":"amqp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-doc","slug":"annotated-doc-9568e1af","identity":"pypi:annotated-doc","label":"annotated-doc","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-types","slug":"annotated-types-2304c38b","identity":"pypi:annotated-types","label":"annotated-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ast-serialize","slug":"ast-serialize-4fe42cf9","identity":"pypi:ast-serialize","label":"ast-serialize","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:attrs","slug":"attrs-2e7954ac","identity":"pypi:attrs","label":"attrs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["26.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:billiard","slug":"billiard-87cdf8d8","identity":"pypi:billiard","label":"billiard","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["4.2.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:boolean-py","slug":"boolean-py-d2700117","identity":"pypi:boolean-py","label":"boolean-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-2-Clause"],"versions":["5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:boto3","slug":"boto3-91d723f0","identity":"pypi:boto3","label":"boto3","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.43.46"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:botocore","slug":"botocore-cd11abb8","identity":"pypi:botocore","label":"botocore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.43.46"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:celery","slug":"celery-b40d49f4","identity":"pypi:celery","label":"celery","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["5.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:celery-types","slug":"celery-types-9f28e176","identity":"pypi:celery-types","label":"celery-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.26.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cffi","slug":"cffi-38e65d3e","identity":"pypi:cffi","label":"cffi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT","MIT-0"],"versions":["2.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cfgv","slug":"cfgv-4583061f","identity":"pypi:cfgv","label":"cfgv","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:charset-normalizer","slug":"charset-normalizer-74ccb20a","identity":"pypi:charset-normalizer","label":"charset-normalizer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.4.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click-didyoumean","slug":"click-didyoumean-4dbcd2d4","identity":"pypi:click-didyoumean","label":"click-didyoumean","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click-plugins","slug":"click-plugins-b43a6bb3","identity":"pypi:click-plugins","label":"click-plugins","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.1.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:click-repl","slug":"click-repl-3c545c47","identity":"pypi:click-repl","label":"click-repl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:coverage","slug":"coverage-7ba89558","identity":"pypi:coverage","label":"coverage","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["7.15.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distlib","slug":"distlib-d66be865","identity":"pypi:distlib","label":"distlib","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["0.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:distro","slug":"distro-36b318e9","identity":"pypi:distro","label":"distro","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:events","slug":"events-aef5a02a","identity":"pypi:events","label":"events","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi","slug":"fastapi-e52fd482","identity":"pypi:fastapi","label":"fastapi","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.139.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fastapi-mcp","slug":"fastapi-mcp-3648cecb","identity":"pypi:fastapi-mcp","label":"fastapi-mcp","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:frozenlist","slug":"frozenlist-110237da","identity":"pypi:frozenlist","label":"frozenlist","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:grpcio","slug":"grpcio-40fa763c","identity":"pypi:grpcio","label":"grpcio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.82.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpcore","slug":"httpcore-ba6ae671","identity":"pypi:httpcore","label":"httpcore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["1.0.9"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httptools","slug":"httptools-b6cca685","identity":"pypi:httptools","label":"httptools","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx","slug":"httpx-a512a166","identity":"pypi:httpx","label":"httpx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.28.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:httpx-sse","slug":"httpx-sse-0029fe64","identity":"pypi:httpx-sse","label":"httpx-sse","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:identify","slug":"identify-bd45ae56","identity":"pypi:identify","label":"identify","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.6.19"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:iniconfig","slug":"iniconfig-1f66e358","identity":"pypi:iniconfig","label":"iniconfig","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jiter","slug":"jiter-d62b34e9","identity":"pypi:jiter","label":"jiter","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.16.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jmespath","slug":"jmespath-ffa3386c","identity":"pypi:jmespath","label":"jmespath","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema","slug":"jsonschema-df23f5cd","identity":"pypi:jsonschema","label":"jsonschema","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.26.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jsonschema-specifications","slug":"jsonschema-specifications-5d87863a","identity":"pypi:jsonschema-specifications","label":"jsonschema-specifications","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2025.9.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:kombu","slug":"kombu-4085784d","identity":"pypi:kombu","label":"kombu","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["5.6.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:librt","slug":"librt-be98c166","identity":"pypi:librt","label":"librt","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.13.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:license-expression","slug":"license-expression-66cbb677","identity":"pypi:license-expression","label":"license-expression","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["30.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markdown-it-py","slug":"markdown-it-py-27073f5e","identity":"pypi:markdown-it-py","label":"markdown-it-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markupsafe","slug":"markupsafe-1bdd4c7f","identity":"pypi:markupsafe","label":"markupsafe","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mdurl","slug":"mdurl-e6f5f075","identity":"pypi:mdurl","label":"mdurl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:multidict","slug":"multidict-b407a4ac","identity":"pypi:multidict","label":"multidict","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mypy","slug":"mypy-2008b5d3","identity":"pypi:mypy","label":"mypy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mypy-extensions","slug":"mypy-extensions-702f6cf3","identity":"pypi:mypy-extensions","label":"mypy-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nodeenv","slug":"nodeenv-71203cea","identity":"pypi:nodeenv","label":"nodeenv","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.10.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opensearch-protobufs","slug":"opensearch-protobufs-c5ca7ed7","identity":"pypi:opensearch-protobufs","label":"opensearch-protobufs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opensearch-py","slug":"opensearch-py-f82a19ee","identity":"pypi:opensearch-py","label":"opensearch-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["3.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["26.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pathspec","slug":"pathspec-01378677","identity":"pypi:pathspec","label":"pathspec","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MPL-2.0"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:platformdirs","slug":"platformdirs-e64002f0","identity":"pypi:platformdirs","label":"platformdirs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.11.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pluggy","slug":"pluggy-24479aaf","identity":"pypi:pluggy","label":"pluggy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pre-commit","slug":"pre-commit-6a196b54","identity":"pypi:pre-commit","label":"pre-commit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["4.5.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:prompt-toolkit","slug":"prompt-toolkit-e6f4118a","identity":"pypi:prompt-toolkit","label":"prompt-toolkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.52"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:propcache","slug":"propcache-1fcd6be4","identity":"pypi:propcache","label":"propcache","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.5.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pycparser","slug":"pycparser-102d9d3e","identity":"pypi:pycparser","label":"pycparser","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic","slug":"pydantic-4ac148ca","identity":"pypi:pydantic","label":"pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.13.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-core","slug":"pydantic-core-f9814ebc","identity":"pypi:pydantic-core","label":"pydantic-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.46.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest-asyncio","slug":"pytest-asyncio-5e711c5a","identity":"pypi:pytest-asyncio","label":"pytest-asyncio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest-cov","slug":"pytest-cov-1f608c88","identity":"pypi:pytest-cov","label":"pytest-cov","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["7.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-dateutil","slug":"python-dateutil-8eac96b7","identity":"pypi:python-dateutil","label":"python-dateutil","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.9.0.post0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-debian","slug":"python-debian-dcb8fb7e","identity":"pypi:python-debian","label":"python-debian","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["GPL-2.0-or-later"],"versions":["1.1.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-discovery","slug":"python-discovery-6dfeea81","identity":"pypi:python-discovery","label":"python-discovery","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:python-magic","slug":"python-magic-28c4094a","identity":"pypi:python-magic","label":"python-magic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.27"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pywin32","slug":"pywin32-9a7c83ae","identity":"pypi:pywin32","label":"pywin32","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":[],"versions":["312"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyyaml","slug":"pyyaml-16000901","identity":"pypi:pyyaml","label":"pyyaml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:referencing","slug":"referencing-b8d98ce1","identity":"pypi:referencing","label":"referencing","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.37.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:respx","slug":"respx-6e4b8195","identity":"pypi:respx","label":"respx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.23.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:reuse","slug":"reuse-a5ec460b","identity":"pypi:reuse","label":"reuse","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 AND CC-BY-SA-4.0 AND CC0-1.0 AND GPL-3.0-or-later"],"versions":["6.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rich","slug":"rich-23b343f7","identity":"pypi:rich","label":"rich","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["15.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:rpds-py","slug":"rpds-py-67c64be8","identity":"pypi:rpds-py","label":"rpds-py","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2026.6.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ruff","slug":"ruff-d5943bdf","identity":"pypi:ruff","label":"ruff","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.15.21"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:s3transfer","slug":"s3transfer-34b3ad07","identity":"pypi:s3transfer","label":"s3transfer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.19.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:shellingham","slug":"shellingham-fceabe5b","identity":"pypi:shellingham","label":"shellingham","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.5.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:six","slug":"six-3c3888bd","identity":"pypi:six","label":"six","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.17.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sniffio","slug":"sniffio-83f32c9d","identity":"pypi:sniffio","label":"sniffio","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR MIT"],"versions":["1.3.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sse-starlette","slug":"sse-starlette-94ef666b","identity":"pypi:sse-starlette","label":"sse-starlette","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["3.4.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tenacity","slug":"tenacity-415454f8","identity":"pypi:tenacity","label":"tenacity","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["9.1.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tomli","slug":"tomli-e09082bd","identity":"pypi:tomli","label":"tomli","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tomlkit","slug":"tomlkit-d5fa3fad","identity":"pypi:tomlkit","label":"tomlkit","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typer","slug":"typer-b291ff1c","identity":"pypi:typer","label":"typer","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.26.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.16.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspection","slug":"typing-inspection-0abeb500","identity":"pypi:typing-inspection","label":"typing-inspection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tzdata","slug":"tzdata-f80b3bb7","identity":"pypi:tzdata","label":"tzdata","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2026.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tzlocal","slug":"tzlocal-7dbb909c","identity":"pypi:tzlocal","label":"tzlocal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["5.4.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uvicorn","slug":"uvicorn-07c7a595","identity":"pypi:uvicorn","label":"uvicorn","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["0.51.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:uvloop","slug":"uvloop-7921eb0f","identity":"pypi:uvloop","label":"uvloop","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.22.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:vine","slug":"vine-fa93acc9","identity":"pypi:vine","label":"vine","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["5.1.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:watchfiles","slug":"watchfiles-d200b8ce","identity":"pypi:watchfiles","label":"watchfiles","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:wcwidth","slug":"wcwidth-038a8957","identity":"pypi:wcwidth","label":"wcwidth","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.8.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:websockets","slug":"websockets-047236a0","identity":"pypi:websockets","label":"websockets","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause"],"versions":["16.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:yarl","slug":"yarl-05cd1b35","identity":"pypi:yarl","label":"yarl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.24.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]}],"vulnerabilities":[{"id":"GHSA-248v-346w-9cwc","slug":"ghsa-248v-346w-9cwc-8a7dbdf1","dossier":false,"summary":"Certifi removes GLOBALTRUST root certificate","aliases":["CVE-2024-39689","PYSEC-2024-230"],"sourceIds":["GHSA-248v-346w-9cwc","PYSEC-2024-230"],"published":"2024-07-05T19:15:10Z","modified":"2026-09-10T03:50:15.994602411Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39689"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463"},{"type":"PACKAGE","url":"https://github.com/certifi/python-certifi"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2024-230.yaml"},{"type":"ARTICLE","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241206-0001"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241206-0001/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-248v-346w-9cwc"}],"versionKeys":["pypi:certifi@2024.6.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-2c2j-9gv5-cj73","slug":"ghsa-2c2j-9gv5-cj73-60bc1f35","dossier":false,"summary":"Starlette has possible denial-of-service vector when parsing large files in multipart forms","aliases":["CVE-2025-54121","PYSEC-2026-1941"],"sourceIds":["GHSA-2c2j-9gv5-cj73","PYSEC-2026-1941"],"published":"2025-07-21T19:34:23Z","modified":"2026-09-10T03:50:25.704876348Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54121"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"WEB","url":"https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14"},{"type":"WEB","url":"https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2c2j-9gv5-cj73"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-2fqr-mr3j-6wp8","slug":"ghsa-2fqr-mr3j-6wp8-5ee7c60f","dossier":false,"summary":"aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence","aliases":["CVE-2026-54279","PYSEC-2026-2112"],"sourceIds":["GHSA-2fqr-mr3j-6wp8","PYSEC-2026-2112"],"published":"2026-06-15T20:08:51Z","modified":"2026-09-10T03:51:07.471021274Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-2gx3-rcp4-g85q","slug":"ghsa-2gx3-rcp4-g85q-9272f372","dossier":false,"summary":"PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)","aliases":["CVE-2026-101917"],"sourceIds":["GHSA-2gx3-rcp4-g85q"],"published":"2026-09-29T23:11:51Z","modified":"2026-09-29T23:15:08.573706550Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101917"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-2vrm-gr82-f7m5","slug":"ghsa-2vrm-gr82-f7m5-5092ea0c","dossier":false,"summary":"AIOHTTP has CRLF injection through multipart part content type header construction","aliases":["CVE-2026-34514","PYSEC-2026-2096"],"sourceIds":["GHSA-2vrm-gr82-f7m5","PYSEC-2026-2096"],"published":"2026-04-01T21:16:59.417Z","modified":"2026-09-10T03:50:42.288164171Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2vrm-gr82-f7m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34514"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-2xpw-w6gg-jr37","slug":"ghsa-2xpw-w6gg-jr37-91cead57","dossier":true,"summary":"urllib3 streaming API improperly handles highly compressed data","aliases":["CVE-2025-66471","PYSEC-2026-1994"],"sourceIds":["GHSA-2xpw-w6gg-jr37","PYSEC-2026-1994"],"published":"2025-12-05T18:15:54Z","modified":"2026-09-25T17:15:05.968189421Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commit/d0fde3672e4a4093f7587858dccfc298eb66e46c"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-1994.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":16},{"id":"GHSA-38jv-5279-wg99","slug":"ghsa-38jv-5279-wg99-c9df8f7b","dossier":false,"summary":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)","aliases":["CVE-2026-21441","PYSEC-2026-1996"],"sourceIds":["GHSA-38jv-5279-wg99","PYSEC-2026-1996"],"published":"2026-01-07T19:18:14Z","modified":"2026-09-10T03:50:32.562010895Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38jv-5279-wg99"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":16},{"id":"GHSA-3wq7-rqq7-wx6j","slug":"ghsa-3wq7-rqq7-wx6j-29b8d785","dossier":false,"summary":"AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS","aliases":["CVE-2026-34517","PYSEC-2026-2099"],"sourceIds":["GHSA-3wq7-rqq7-wx6j","PYSEC-2026-2099"],"published":"2026-04-01T21:16:59.870Z","modified":"2026-09-10T03:50:42.683852324Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-3wq7-rqq7-wx6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34517"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/cbb774f38330563422ca0c413a71021d7b944145"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-42vr-xj54-vc7v","slug":"ghsa-42vr-xj54-vc7v-bb2dfa49","dossier":false,"summary":"PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)","aliases":["CVE-2026-101918"],"sourceIds":["GHSA-42vr-xj54-vc7v"],"published":"2026-09-30T15:41:05Z","modified":"2026-09-30T16:00:09.812873551Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-42vr-xj54-vc7v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101918"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.15.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-48p4-8xcf-vxj5","slug":"ghsa-48p4-8xcf-vxj5-13f12656","dossier":false,"summary":"urllib3 does not control redirects in browsers and Node.js","aliases":["CVE-2025-50182","PYSEC-2026-1997"],"sourceIds":["GHSA-48p4-8xcf-vxj5","PYSEC-2026-1997"],"published":"2025-06-18T17:50:11Z","modified":"2026-09-10T03:50:24.821170285Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-4fvr-rgm6-gqmc","slug":"ghsa-4fvr-rgm6-gqmc-c8b35c87","dossier":false,"summary":"aiohttp: HTTP/1 Pipelined Requests Queue Without Limit","aliases":["CVE-2026-54273","PYSEC-2026-2107"],"sourceIds":["GHSA-4fvr-rgm6-gqmc","PYSEC-2026-2107"],"published":"2026-06-15T20:10:32Z","modified":"2026-09-10T03:51:07.881817751Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-4m7w-qmgq-4wj5","slug":"ghsa-4m7w-qmgq-4wj5-f98433d3","dossier":false,"summary":"aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections","aliases":["CVE-2026-54275","PYSEC-2026-237"],"sourceIds":["GHSA-4m7w-qmgq-4wj5","PYSEC-2026-237"],"published":"2026-06-15T20:11:13Z","modified":"2026-09-10T03:50:48.205198252Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4m7w-qmgq-4wj5"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-4xgf-cpjx-pc3j","slug":"ghsa-4xgf-cpjx-pc3j-c1284f87","dossier":false,"summary":"pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size","aliases":["CVE-2026-58203"],"sourceIds":["GHSA-4xgf-cpjx-pc3j"],"published":"2026-06-19T22:10:42Z","modified":"2026-09-10T03:50:48.282428168Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j"},{"type":"PACKAGE","url":"https://github.com/pydantic/pydantic-settings"}],"versionKeys":["pypi:pydantic-settings@2.12.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5239-wwwm-4pmq","slug":"ghsa-5239-wwwm-4pmq-228840e4","dossier":false,"summary":"Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching","aliases":["CVE-2026-4539","PYSEC-2026-2987"],"sourceIds":["GHSA-5239-wwwm-4pmq","PYSEC-2026-2987"],"published":"2026-03-22T06:30:15Z","modified":"2026-09-10T03:50:59.780634752Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4539"},{"type":"WEB","url":"https://github.com/pygments/pygments/issues/3058"},{"type":"WEB","url":"https://github.com/pygments/pygments/pull/3064"},{"type":"WEB","url":"https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc"},{"type":"PACKAGE","url":"https://github.com/pygments/pygments"},{"type":"WEB","url":"https://github.com/pygments/pygments/releases/tag/2.20.0"},{"type":"WEB","url":"https://vuldb.com/?ctiid.352327"},{"type":"WEB","url":"https://vuldb.com/?id.352327"},{"type":"WEB","url":"https://vuldb.com/?submit.774685"},{"type":"PACKAGE","url":"https://pypi.org/project/pygments"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5239-wwwm-4pmq"}],"versionKeys":["pypi:pygments@2.19.1","pypi:pygments@2.19.2"],"packageCount":1,"repositoryCount":15},{"id":"GHSA-537c-gmf6-5ccf","slug":"ghsa-537c-gmf6-5ccf-23a24e16","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-537c-gmf6-5ccf"],"published":"2026-06-15T20:12:27Z","modified":"2026-09-10T03:50:48.298936410Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260609.txt"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-54jq-c3m8-4m76","slug":"ghsa-54jq-c3m8-4m76-bba4b2d3","dossier":false,"summary":"AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components","aliases":["CVE-2025-69226","PYSEC-2026-1097"],"sourceIds":["GHSA-54jq-c3m8-4m76","PYSEC-2026-1097"],"published":"2026-01-05T23:09:51Z","modified":"2026-09-10T03:50:32.751498447Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-54jq-c3m8-4m76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69226"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f2a86fd5ac0383000d1715afddfa704413f0711e"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-54jq-c3m8-4m76"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-597g-3phw-6986","slug":"ghsa-597g-3phw-6986-6d75801e","dossier":false,"summary":"virtualenv Has TOCTOU Vulnerabilities in Directory Creation","aliases":["BIT-virtualenv-2026-22702","CVE-2026-22702","PYSEC-2026-2009"],"sourceIds":["GHSA-597g-3phw-6986","PYSEC-2026-2009"],"published":"2026-01-13T18:45:57Z","modified":"2026-09-10T03:50:32.732715893Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-597g-3phw-6986"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22702"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3013"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/dec4cec5d16edaf83a00a658f32d1e032661cebc"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-597g-3phw-6986"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-59g5-xgcq-4qw3","slug":"ghsa-59g5-xgcq-4qw3-949fce0e","dossier":false,"summary":"Denial of service (DoS) via deformation `multipart/form-data` boundary","aliases":["CVE-2024-53981","PYSEC-2026-1851"],"sourceIds":["GHSA-59g5-xgcq-4qw3","PYSEC-2026-1851"],"published":"2024-12-02T21:37:04Z","modified":"2026-09-10T03:50:21.270678783Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-59g5-xgcq-4qw3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53981"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/commit/c4fe4d3cebc08c660e57dd709af1ffa7059b3177"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-59g5-xgcq-4qw3"}],"versionKeys":["pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5p39-cfhj-2xmp","slug":"ghsa-5p39-cfhj-2xmp-77a62550","dossier":false,"summary":"AnyIO process-pool workers can block indefinitely on undrained stderr","aliases":["CVE-2026-64847"],"sourceIds":["GHSA-5p39-cfhj-2xmp"],"published":"2026-09-18T17:17:10Z","modified":"2026-09-18T17:30:07.278440290Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/agronholm/anyio/security/advisories/GHSA-5p39-cfhj-2xmp"},{"type":"WEB","url":"https://github.com/agronholm/anyio/pull/1207"},{"type":"WEB","url":"https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"},{"type":"PACKAGE","url":"https://github.com/agronholm/anyio"},{"type":"WEB","url":"https://github.com/agronholm/anyio/releases/tag/4.14.2"}],"versionKeys":["pypi:anyio@4.10.0","pypi:anyio@4.11.0","pypi:anyio@4.12.1","pypi:anyio@4.13.0","pypi:anyio@4.3.0","pypi:anyio@4.5.2","pypi:anyio@4.8.0","pypi:anyio@4.9.0"],"packageCount":1,"repositoryCount":16},{"id":"GHSA-5rvq-cxj2-64vf","slug":"ghsa-5rvq-cxj2-64vf-5e3e7388","dossier":false,"summary":"python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service","aliases":["CVE-2026-53539","PYSEC-2026-3036"],"sourceIds":["GHSA-5rvq-cxj2-64vf","PYSEC-2026-3036"],"published":"2026-06-15T20:24:09Z","modified":"2026-09-10T03:50:48.426087467Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5rvq-cxj2-64vf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53539"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.28","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-63hf-3vf5-4wqf","slug":"ghsa-63hf-3vf5-4wqf-aadd9f0f","dossier":false,"summary":"AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass","aliases":["CVE-2026-34520","PYSEC-2026-2102"],"sourceIds":["GHSA-63hf-3vf5-4wqf","PYSEC-2026-2102"],"published":"2026-04-01T21:17:00.333Z","modified":"2026-09-10T03:50:43.255807027Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hf-3vf5-4wqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34520"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2026-2102.yaml"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-63hw-fmq6-xxg2","slug":"ghsa-63hw-fmq6-xxg2-00aac622","dossier":false,"summary":"aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines","aliases":["CVE-2026-54277","PYSEC-2026-2110"],"sourceIds":["GHSA-63hw-fmq6-xxg2","PYSEC-2026-2110"],"published":"2026-06-15T20:09:16Z","modified":"2026-09-10T03:50:48.460120366Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hw-fmq6-xxg2"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5ab61bb4cd88f19b712f12c7c9295fe262bf804d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-09-10T03:50:45.700124422Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.14","pypi:idna@3.7"],"packageCount":1,"repositoryCount":21},{"id":"GHSA-69f9-5gxw-wvc2","slug":"ghsa-69f9-5gxw-wvc2-eec14573","dossier":false,"summary":"AIOHTTP's unicode processing of header values could cause parsing discrepancies","aliases":["CVE-2025-69224","PYSEC-2026-1099"],"sourceIds":["GHSA-69f9-5gxw-wvc2","PYSEC-2026-1099"],"published":"2026-01-05T22:58:57Z","modified":"2026-09-10T03:49:54.440954011Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-69f9-5gxw-wvc2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69224"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/32677f2adfd907420c078dda6b79225c6f4ebce0"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69f9-5gxw-wvc2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-6jhg-hg63-jvvf","slug":"ghsa-6jhg-hg63-jvvf-74cd77d8","dossier":false,"summary":"AIOHTTP vulnerable to  denial of service through large payloads","aliases":["CVE-2025-69228","PYSEC-2026-1100"],"sourceIds":["GHSA-6jhg-hg63-jvvf","PYSEC-2026-1100"],"published":"2026-01-05T23:13:14Z","modified":"2026-09-10T03:50:32.839537992Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69228"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jhg-hg63-jvvf"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-6jv3-5f52-599m","slug":"ghsa-6jv3-5f52-599m-dd700d26","dossier":false,"summary":"python-multipart: Semicolon treated as querystring field separator enables parameter smuggling","aliases":["CVE-2026-53538","PYSEC-2026-3037"],"sourceIds":["GHSA-6jv3-5f52-599m","PYSEC-2026-3037"],"published":"2026-06-15T20:22:25Z","modified":"2026-09-10T03:51:07.925895532Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jv3-5f52-599m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53538"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.28","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6mq8-rvhq-8wgg","slug":"ghsa-6mq8-rvhq-8wgg-d94d738f","dossier":false,"summary":"AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb","aliases":["CVE-2025-69223","PYSEC-2026-1101"],"sourceIds":["GHSA-6mq8-rvhq-8wgg","PYSEC-2026-1101"],"published":"2026-01-05T22:58:41Z","modified":"2026-09-10T03:50:32.830751052Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69223"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6mq8-rvhq-8wgg"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-6w46-j5rx-g56g","slug":"ghsa-6w46-j5rx-g56g-5324d549","dossier":false,"summary":"pytest has vulnerable tmpdir handling","aliases":["CVE-2025-71176","PYSEC-2026-1845"],"sourceIds":["GHSA-6w46-j5rx-g56g","PYSEC-2026-1845"],"published":"2026-01-22T06:30:29Z","modified":"2026-09-10T03:50:32.768043789Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71176"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/issues/13669"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/pull/14343"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/commit/95d8423bd24992deea5b9df32555fa1741679e2c"},{"type":"PACKAGE","url":"https://github.com/pytest-dev/pytes"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/releases/tag/9.0.3"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/01/21/5"},{"type":"PACKAGE","url":"https://pypi.org/project/pytest"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6w46-j5rx-g56g"}],"versionKeys":["pypi:pytest@7.2.2","pypi:pytest@7.4.4","pypi:pytest@8.3.2","pypi:pytest@8.4.2","pypi:pytest@9.0.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-752w-5fwx-jx9f","slug":"ghsa-752w-5fwx-jx9f-389afa77","dossier":false,"summary":"PyJWT accepts unknown `crit` header extensions","aliases":["CVE-2026-32597","PYSEC-2026-120"],"sourceIds":["GHSA-752w-5fwx-jx9f","PYSEC-2026-120"],"published":"2026-03-13T19:55:09.500Z","modified":"2026-09-10T03:50:59.993704484Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32597"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-120.yaml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/05/msg00008.html"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-79v4-65xg-pq4g","slug":"ghsa-79v4-65xg-pq4g-b911b371","dossier":false,"summary":"Vulnerable OpenSSL included in cryptography wheels","aliases":["CVE-2024-12797","PYSEC-2026-1284"],"sourceIds":["GHSA-79v4-65xg-pq4g","PYSEC-2026-1284"],"published":"2025-02-11T18:06:42Z","modified":"2026-09-10T03:50:22.501671988Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12797"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20250211.txt"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-79v4-65xg-pq4g"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-7f5h-v6xp-fcq8","slug":"ghsa-7f5h-v6xp-fcq8-9393173e","dossier":false,"summary":"Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``","aliases":["CVE-2025-62727","PYSEC-2026-1942"],"sourceIds":["GHSA-7f5h-v6xp-fcq8","PYSEC-2026-1942"],"published":"2025-10-28T20:38:01Z","modified":"2026-09-10T03:50:29.490992457Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-7f5h-v6xp-fcq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62727"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/4ea6e22b489ec388d6004cfbca52dd5b147127c5"},{"type":"INTRODUCED","url":"https://github.com/Kludex/starlette/commit/69ed26a85956ef4bd0161807eb27abf49be7cd3c"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/Kludex/starlette/releases/tag/0.49.1"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7f5h-v6xp-fcq8"}],"versionKeys":["pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.48.0","pypi:starlette@0.49.0"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-7gcm-g887-7qv7","slug":"ghsa-7gcm-g887-7qv7-55bb9ff1","dossier":false,"summary":"protobuf affected by a JSON recursion depth bypass","aliases":["CVE-2026-0994","PYSEC-2026-1805"],"sourceIds":["GHSA-7gcm-g887-7qv7","PYSEC-2026-1805"],"published":"2026-01-23T15:31:35Z","modified":"2026-09-10T03:50:32.795512159Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0994"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/issues/25070"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/pull/25239"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/5ebddcb1bcbe51d1fe323baa145e85f4f23128cf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/d2b001626d137c62dfee6c88c87324102531868b"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7gcm-g887-7qv7"}],"versionKeys":["pypi:protobuf@4.25.7","pypi:protobuf@4.25.8","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4","pypi:protobuf@6.31.1","pypi:protobuf@6.32.0","pypi:protobuf@6.32.1","pypi:protobuf@6.33.0","pypi:protobuf@6.33.1","pypi:protobuf@6.33.4"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-82r6-8w77-94w6","slug":"ghsa-82r6-8w77-94w6-217253d8","dossier":false,"summary":"AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing","aliases":["CVE-2026-63374"],"sourceIds":["GHSA-82r6-8w77-94w6"],"published":"2026-09-18T17:17:18Z","modified":"2026-09-18T17:30:07.278457589Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/agronholm/anyio/security/advisories/GHSA-82r6-8w77-94w6"},{"type":"WEB","url":"https://github.com/agronholm/anyio/pull/1208"},{"type":"WEB","url":"https://github.com/agronholm/anyio/commit/68f58915f82d9be8109ebbbd8f5d70577d43f2ce"},{"type":"PACKAGE","url":"https://github.com/agronholm/anyio"},{"type":"WEB","url":"https://github.com/agronholm/anyio/releases/tag/4.14.2"}],"versionKeys":["pypi:anyio@4.10.0","pypi:anyio@4.11.0","pypi:anyio@4.12.1","pypi:anyio@4.13.0","pypi:anyio@4.3.0","pypi:anyio@4.5.2","pypi:anyio@4.8.0","pypi:anyio@4.9.0"],"packageCount":1,"repositoryCount":16},{"id":"GHSA-82w8-qh3p-5jfq","slug":"ghsa-82w8-qh3p-5jfq-a05ef51e","dossier":false,"summary":"Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS","aliases":["CVE-2026-54283","PYSEC-2026-249"],"sourceIds":["GHSA-82w8-qh3p-5jfq","PYSEC-2026-249"],"published":"2026-06-15T20:39:53Z","modified":"2026-09-10T03:51:08.156199030Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.48.0","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0","pypi:starlette@1.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-86qp-5c8j-p5mr","slug":"ghsa-86qp-5c8j-p5mr-13e563cb","dossier":false,"summary":"Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks","aliases":["CVE-2026-48710","PYSEC-2026-161","X41-2026-002"],"sourceIds":["GHSA-86qp-5c8j-p5mr","PYSEC-2026-161"],"published":"2026-05-22T13:10:03Z","modified":"2026-09-10T03:51:08.121685407Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48710"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6"},{"type":"WEB","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette"},{"type":"ARTICLE","url":"https://www.secwest.net/starlette"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-48710"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json"},{"type":"WEB","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481742"},{"type":"DETECTION","url":"https://badhost.org/"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48710"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:51357"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:44696"},{"type":"ARTICLE","url":"https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/"},{"type":"ADVISORY","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette/"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.48.0","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0","pypi:starlette@1.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-8988-9cw3-xx77","slug":"ghsa-8988-9cw3-xx77-ee9c660c","dossier":true,"summary":"urllib3: HTTPS proxy TLS configuration may be ignored or overridden","aliases":["CVE-2026-97687"],"sourceIds":["GHSA-8988-9cw3-xx77"],"published":"2026-09-30T14:46:04Z","modified":"2026-09-30T15:00:05.369237042Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97687"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/pull/5093"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.8.0"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3","pypi:urllib3@2.7.0"],"packageCount":1,"repositoryCount":22},{"id":"GHSA-8qvm-5x2c-j2w7","slug":"ghsa-8qvm-5x2c-j2w7-8a075519","dossier":false,"summary":"protobuf-python has a potential Denial of Service issue","aliases":["CVE-2025-4565","PYSEC-2026-1806"],"sourceIds":["GHSA-8qvm-5x2c-j2w7","PYSEC-2026-1806"],"published":"2025-06-16T16:02:58Z","modified":"2026-09-10T03:50:25.255076549Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-735f-pc8j-v9w8"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8qvm-5x2c-j2w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4565"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/blob/main/python/google/protobuf/internal/decoder_test.py#L87-L98"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/blob/main/python/google/protobuf/internal/message_test.py#L1436-L1478"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/tree/main/python#implementation-backends"},{"type":"PACKAGE","url":"https://pypi.org/project/protobuf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8qvm-5x2c-j2w7"}],"versionKeys":["pypi:protobuf@4.25.7","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-8wjv-2p76-3863","slug":"ghsa-8wjv-2p76-3863-60244895","dossier":false,"summary":"PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header","aliases":["CVE-2026-102265"],"sourceIds":["GHSA-8wjv-2p76-3863"],"published":"2026-09-29T23:43:06Z","modified":"2026-09-29T23:45:37.333342767Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102265"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/06573692ebcdec8831c3927513b3e87c31fbbb62"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.13.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-94p9-xgh2-xp45","slug":"ghsa-94p9-xgh2-xp45-1ed45366","dossier":false,"summary":"virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use","aliases":["CVE-2026-102930","PYSEC-2026-4011"],"sourceIds":["GHSA-94p9-xgh2-xp45","PYSEC-2026-4011"],"published":"2026-09-18T01:41:45Z","modified":"2026-10-01T00:00:04.703718723Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102930"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3251"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4011.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/releases/tag/21.7.12"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4","pypi:virtualenv@21.2.4","pypi:virtualenv@21.3.1","pypi:virtualenv@21.7.1"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-9548-qrrj-x5pj","slug":"ghsa-9548-qrrj-x5pj-6121f213","dossier":false,"summary":"AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections","aliases":["CVE-2025-53643","PYSEC-2026-1104"],"sourceIds":["GHSA-9548-qrrj-x5pj","PYSEC-2026-1104"],"published":"2025-07-14T19:33:31Z","modified":"2026-09-10T03:50:26.231846188Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9548-qrrj-x5pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53643"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9548-qrrj-x5pj"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-966j-vmvw-g2g9","slug":"ghsa-966j-vmvw-g2g9-dad9a989","dossier":false,"summary":"AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect","aliases":["CVE-2026-34518","PYSEC-2026-2100"],"sourceIds":["GHSA-966j-vmvw-g2g9","PYSEC-2026-2100"],"published":"2026-04-01T21:17:00.020Z","modified":"2026-09-10T03:51:01.374434696Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-966j-vmvw-g2g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34518"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-993g-76c3-p5m4","slug":"ghsa-993g-76c3-p5m4-f823cd66","dossier":false,"summary":"PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes","aliases":["CVE-2026-48522","PYSEC-2026-175"],"sourceIds":["GHSA-993g-76c3-p5m4","PYSEC-2026-175"],"published":"2026-05-28T16:16:29.150Z","modified":"2026-09-10T03:50:49.179286182Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48522"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/8521"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-175.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-9h52-p55h-vw2f","slug":"ghsa-9h52-p55h-vw2f-fc4c91e7","dossier":false,"summary":"Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default","aliases":["CVE-2025-66416","PYSEC-2026-1617"],"sourceIds":["GHSA-9h52-p55h-vw2f","PYSEC-2026-1617"],"published":"2025-12-02T16:52:08Z","modified":"2026-09-10T03:50:31.741008234Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-9h52-p55h-vw2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66416"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/d3a184119e4479ea6a63590bc41f01dc06e3fa99"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9h52-p55h-vw2f"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mcp/PYSEC-2026-1617.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1","pypi:mcp@1.19.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-9h9j-4vrj-gf7g","slug":"ghsa-9h9j-4vrj-gf7g-c50a1cd4","dossier":false,"summary":"virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection","aliases":["CVE-2026-102938","PYSEC-2026-4012"],"sourceIds":["GHSA-9h9j-4vrj-gf7g","PYSEC-2026-4012"],"published":"2026-09-17T16:42:47Z","modified":"2026-10-01T00:00:04.697773611Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102938"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3247"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4012.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/releases/tag/21.7.11"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4","pypi:virtualenv@21.2.4","pypi:virtualenv@21.3.1","pypi:virtualenv@21.7.1"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-9hjg-9r4m-mvj7","slug":"ghsa-9hjg-9r4m-mvj7-32d7b63e","dossier":false,"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"sourceIds":["GHSA-9hjg-9r4m-mvj7","PYSEC-2026-1872"],"published":"2025-06-09T19:06:08Z","modified":"2026-09-10T03:50:25.139398550Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6965"},{"type":"FIX","url":"https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2025/Jun/2"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-9j54-fg26-wv3r","slug":"ghsa-9j54-fg26-wv3r-7789d387","dossier":false,"summary":"PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation","aliases":["CVE-2026-102266"],"sourceIds":["GHSA-9j54-fg26-wv3r"],"published":"2026-09-29T23:43:19Z","modified":"2026-09-30T00:00:04.438003579Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9j54-fg26-wv3r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102266"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/f91ed44dd65baaf457f4b3353ed35e98a753934c"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.13.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-9v7f-9g4p-ffgj","slug":"ghsa-9v7f-9g4p-ffgj-61cfc8ce","dossier":false,"summary":"PyJWT: PyJWKClient follows redirects when fetching JWKS","aliases":["CVE-2026-102267"],"sourceIds":["GHSA-9v7f-9g4p-ffgj"],"published":"2026-09-29T23:15:00Z","modified":"2026-09-29T23:30:03.872305369Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102267"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-9wx4-h78v-vm56","slug":"ghsa-9wx4-h78v-vm56-6a334c57","dossier":false,"summary":"Requests `Session` object does not verify requests after making first request with verify=False","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"sourceIds":["GHSA-9wx4-h78v-vm56","PYSEC-2026-1873"],"published":"2024-05-20T20:15:00Z","modified":"2026-09-10T03:50:13.740879755Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195"},{"type":"WEB","url":"https://github.com/psf/requests/pull/6655"},{"type":"FIX","url":"https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ"},{"type":"PACKAGE","url":"https://pypi.org/project/requests"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wx4-h78v-vm56"}],"versionKeys":["pypi:requests@2.31.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9x8q-7h8h-wcw9","slug":"ghsa-9x8q-7h8h-wcw9-af94166e","dossier":false,"summary":"aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect","aliases":["CVE-2026-54280","PYSEC-2026-2113"],"sourceIds":["GHSA-9x8q-7h8h-wcw9","PYSEC-2026-2113"],"published":"2026-06-15T20:10:44Z","modified":"2026-09-10T03:50:55.382836820Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9x8q-7h8h-wcw9"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-c427-h43c-vf67","slug":"ghsa-c427-h43c-vf67-fa5b38aa","dossier":false,"summary":"AIOHTTP accepts duplicate Host headers","aliases":["CVE-2026-34525","PYSEC-2026-2103"],"sourceIds":["GHSA-c427-h43c-vf67","PYSEC-2026-2103"],"published":"2026-04-01T21:17:00.490Z","modified":"2026-09-10T03:51:01.505705751Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34525"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-cpwx-vrp4-4pq7","slug":"ghsa-cpwx-vrp4-4pq7-799bdc98","dossier":false,"summary":"Jinja2 vulnerable to sandbox breakout through attr filter selecting format method","aliases":["CVE-2025-27516","PYSEC-2026-1471"],"sourceIds":["GHSA-cpwx-vrp4-4pq7","PYSEC-2026-1471"],"published":"2025-03-05T20:40:14Z","modified":"2026-09-10T03:49:48.526758681Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-cpwx-vrp4-4pq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27516"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/90457bbf33b8662926ae65cdde4c4c32e756e403"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00045.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cpwx-vrp4-4pq7"}],"versionKeys":["pypi:jinja2@3.1.3","pypi:jinja2@3.1.5"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cq5v-8q36-5273","slug":"ghsa-cq5v-8q36-5273-b5e8d025","dossier":false,"summary":"AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)","aliases":["CVE-2026-69244","PYSEC-2026-3545"],"sourceIds":["GHSA-cq5v-8q36-5273","PYSEC-2026-3545"],"published":"2026-08-03T20:51:13Z","modified":"2026-09-10T03:51:13.983479281Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/pull/13223"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cq5v-8q36-5273"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69244"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5","pypi:aiohttp@3.14.1"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-f96h-pmfr-66vw","slug":"ghsa-f96h-pmfr-66vw-6763f20e","dossier":false,"summary":"Starlette Denial of service (DoS) via multipart/form-data","aliases":["CVE-2024-47874","PYSEC-2026-1943"],"sourceIds":["GHSA-f96h-pmfr-66vw","PYSEC-2026-1943"],"published":"2024-10-15T18:12:57Z","modified":"2026-09-10T03:50:19.756287586Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47874"},{"type":"FIX","url":"https://github.com/encode/starlette/commit/fd038f3070c302bff17ef7d173dbb0b007617733"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"PACKAGE","url":"https://pypi.org/project/starlette"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f96h-pmfr-66vw"}],"versionKeys":["pypi:starlette@0.37.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-ffc3-869f-jxw9","slug":"ghsa-ffc3-869f-jxw9-318ae071","dossier":false,"summary":"PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard","aliases":["CVE-2026-102268"],"sourceIds":["GHSA-ffc3-869f-jxw9"],"published":"2026-09-29T23:17:33Z","modified":"2026-09-29T23:30:03.866776038Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102268"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-fh55-r93g-j68g","slug":"ghsa-fh55-r93g-j68g-a231bc8e","dossier":false,"summary":"AIOHTTP Vulnerable to Cookie Parser Warning Storm","aliases":["CVE-2025-69230","PYSEC-2026-1105"],"sourceIds":["GHSA-fh55-r93g-j68g","PYSEC-2026-1105"],"published":"2026-01-05T23:13:46Z","modified":"2026-09-10T03:50:33.047685052Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-fh55-r93g-j68g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69230"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/64629a0834f94e46d9881f4e99c41a137e1f3326"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh55-r93g-j68g"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-fhv5-28vv-h8m8","slug":"ghsa-fhv5-28vv-h8m8-c54a3f91","dossier":false,"summary":"PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)","aliases":["CVE-2026-48524","PYSEC-2026-177"],"sourceIds":["GHSA-fhv5-28vv-h8m8","PYSEC-2026-177"],"published":"2026-05-28T16:16:29.403Z","modified":"2026-09-10T03:50:49.375741307Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48524"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/8522"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-177.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-g3cq-j2xw-wf74","slug":"ghsa-g3cq-j2xw-wf74-4475e17b","dossier":false,"summary":"aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup","aliases":["CVE-2026-54278","PYSEC-2026-2111"],"sourceIds":["GHSA-g3cq-j2xw-wf74","PYSEC-2026-2111"],"published":"2026-06-15T20:09:51Z","modified":"2026-09-10T03:51:08.751749295Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g3cq-j2xw-wf74"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-g6cj-pr64-35w5","slug":"ghsa-g6cj-pr64-35w5-fd75eedf","dossier":false,"summary":"cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing","aliases":["CVE-2026-69247","PYSEC-2026-3552"],"sourceIds":["GHSA-g6cj-pr64-35w5","PYSEC-2026-3552"],"published":"2026-08-03T21:17:00Z","modified":"2026-09-10T03:50:53.610446769Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"},{"type":"WEB","url":"https://github.com/pyca/cryptography/pull/15369"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g6cj-pr64-35w5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247"}],"versionKeys":["pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3","pypi:cryptography@49.0.0"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-g7vv-2v7x-gj9p","slug":"ghsa-g7vv-2v7x-gj9p-5ef970c3","dossier":false,"summary":"tqdm CLI arguments injection attack","aliases":["CVE-2024-34062","PYSEC-2026-1976"],"sourceIds":["GHSA-g7vv-2v7x-gj9p","PYSEC-2026-1976"],"published":"2024-05-03T19:33:28Z","modified":"2026-09-10T03:50:13.776534451Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"},{"type":"WEB","url":"https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316"},{"type":"PACKAGE","url":"https://github.com/tqdm/tqdm"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC"},{"type":"PACKAGE","url":"https://pypi.org/project/tqdm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7vv-2v7x-gj9p"}],"versionKeys":["pypi:tqdm@4.66.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g84x-mcqj-x9qq","slug":"ghsa-g84x-mcqj-x9qq-fc677e5d","dossier":false,"summary":"AIOHTTP vulnerable to DoS through chunked messages","aliases":["CVE-2025-69229","PYSEC-2026-1106"],"sourceIds":["GHSA-g84x-mcqj-x9qq","PYSEC-2026-1106"],"published":"2026-01-05T23:13:29Z","modified":"2026-09-10T03:50:33.073865205Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g84x-mcqj-x9qq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g84x-mcqj-x9qq"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-gc5v-m9x4-r6x2","slug":"ghsa-gc5v-m9x4-r6x2-b9828ad8","dossier":true,"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"sourceIds":["GHSA-gc5v-m9x4-r6x2","PYSEC-2026-2275"],"published":"2026-03-25T16:56:28Z","modified":"2026-09-10T03:50:39.207922076Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645"},{"type":"FIX","url":"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"},{"type":"PACKAGE","url":"https://github.com/psf/requests"},{"type":"ADVISORY","url":"https://github.com/psf/requests/releases/tag/v2.33.0"}],"versionKeys":["pypi:requests@2.31.0","pypi:requests@2.32.3","pypi:requests@2.32.4","pypi:requests@2.32.5"],"packageCount":1,"repositoryCount":18},{"id":"GHSA-gh4c-6fx4-qh6g","slug":"ghsa-gh4c-6fx4-qh6g-a56f6cb1","dossier":false,"summary":"urllib3: Chunked Deflate streaming can enter an infinite loop","aliases":["CVE-2026-97688"],"sourceIds":["GHSA-gh4c-6fx4-qh6g"],"published":"2026-09-30T15:00:38Z","modified":"2026-09-30T15:15:04.066660799Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97688"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.8.0"}],"versionKeys":["pypi:urllib3@2.6.3","pypi:urllib3@2.7.0"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-gm62-xv2j-4w53","slug":"ghsa-gm62-xv2j-4w53-5befa184","dossier":false,"summary":"urllib3 allows an unbounded number of links in the decompression chain","aliases":["CVE-2025-66418","PYSEC-2026-1998"],"sourceIds":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"published":"2025-12-05T18:15:19Z","modified":"2026-09-10T03:50:58.741847479Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gm62-xv2j-4w53"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0"],"packageCount":1,"repositoryCount":16},{"id":"GHSA-gmj6-6f8f-6699","slug":"ghsa-gmj6-6f8f-6699-e3e02f35","dossier":false,"summary":"Jinja has a sandbox breakout through malicious filenames","aliases":["CVE-2024-56201","PYSEC-2026-1472"],"sourceIds":["GHSA-gmj6-6f8f-6699","PYSEC-2026-1472"],"published":"2024-12-23T17:54:12Z","modified":"2026-09-10T03:50:56.152882717Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-gmj6-6f8f-6699"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56201"},{"type":"WEB","url":"https://github.com/pallets/jinja/issues/1792"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/767b23617628419ae3709ccfb02f9602ae9fe51f"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gmj6-6f8f-6699"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-gvp8-978c-rx2q","slug":"ghsa-gvp8-978c-rx2q-c33a029f","dossier":false,"summary":"PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse","aliases":["CVE-2026-103001"],"sourceIds":["GHSA-gvp8-978c-rx2q"],"published":"2026-09-30T23:53:17Z","modified":"2026-10-01T00:00:04.690126325Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"}],"versionKeys":["pypi:pyjwt@2.13.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-h4gh-qq45-vh27","slug":"ghsa-h4gh-qq45-vh27-43490265","dossier":false,"summary":"pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels","aliases":[],"sourceIds":["GHSA-h4gh-qq45-vh27"],"published":"2024-09-03T21:59:48Z","modified":"2026-09-10T03:50:18.241644273Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20240903.txt"}],"versionKeys":["pypi:cryptography@42.0.8"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h75v-3vvj-5mfj","slug":"ghsa-h75v-3vvj-5mfj-d8fc6bb7","dossier":false,"summary":"Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter","aliases":["CVE-2024-34064","PYSEC-2026-1474"],"sourceIds":["GHSA-h75v-3vvj-5mfj","PYSEC-2026-1474"],"published":"2024-05-06T14:20:59Z","modified":"2026-09-10T03:50:13.786450101Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34064"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h75v-3vvj-5mfj"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-hcc4-c3v8-rx92","slug":"ghsa-hcc4-c3v8-rx92-ddf32b5c","dossier":false,"summary":"AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector","aliases":["CVE-2026-34513","PYSEC-2026-2095"],"sourceIds":["GHSA-hcc4-c3v8-rx92","PYSEC-2026-2095"],"published":"2026-04-01T21:16:59.267Z","modified":"2026-09-10T03:51:02.067006429Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hcc4-c3v8-rx92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34513"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-hg6j-4rv6-33pg","slug":"ghsa-hg6j-4rv6-33pg-d0ac8db0","dossier":false,"summary":"AIOHTTP is vulnerable to cross-origin redirect with per-request cookies","aliases":["CVE-2026-47265","PYSEC-2026-2105"],"sourceIds":["GHSA-hg6j-4rv6-33pg","PYSEC-2026-2105"],"published":"2026-06-02T20:16:37.903Z","modified":"2026-09-10T03:50:49.888335735Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hg6j-4rv6-33pg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47265"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-hpj7-wq8m-9hgp","slug":"ghsa-hpj7-wq8m-9hgp-fac25647","dossier":false,"summary":"aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges","aliases":["CVE-2026-54276","PYSEC-2026-2109"],"sourceIds":["GHSA-hpj7-wq8m-9hgp","PYSEC-2026-2109"],"published":"2026-06-15T20:09:06Z","modified":"2026-09-10T03:50:49.899674354Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hpj7-wq8m-9hgp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/38d16060037e1bfcd6d677abababa3c2a4bb58fa"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-hxm8-2xgr-2p9m","slug":"ghsa-hxm8-2xgr-2p9m-bfcf1f86","dossier":false,"summary":"PyJWT: Non-canonical signature segments enable raw-token revocation bypass","aliases":["CVE-2026-102269"],"sourceIds":["GHSA-hxm8-2xgr-2p9m"],"published":"2026-09-29T23:17:55Z","modified":"2026-09-29T23:30:03.865434818Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102269"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/e6f48401001609a8f99e71fcaf355fb895d508a8"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-jg22-mg44-37j8","slug":"ghsa-jg22-mg44-37j8-b8064c77","dossier":false,"summary":"AIOHTTP is Vulnerable to Deserialization of Untrusted Data","aliases":["CVE-2026-34993","PYSEC-2026-2104"],"sourceIds":["GHSA-jg22-mg44-37j8","PYSEC-2026-2104"],"published":"2026-06-02T20:16:34.857Z","modified":"2026-09-10T03:51:08.847676311Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-jj3x-wxrx-4x23","slug":"ghsa-jj3x-wxrx-4x23-407bafac","dossier":false,"summary":"AIOHTTP vulnerable to DoS when bypassing asserts","aliases":["CVE-2025-69227","PYSEC-2026-1107"],"sourceIds":["GHSA-jj3x-wxrx-4x23","PYSEC-2026-1107"],"published":"2026-01-05T23:10:15Z","modified":"2026-09-10T03:50:33.308966616Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jj3x-wxrx-4x23"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69227"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj3x-wxrx-4x23"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-jp82-jpqv-5vv3","slug":"ghsa-jp82-jpqv-5vv3-4d50530e","dossier":false,"summary":"Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname","aliases":["CVE-2026-54282","PYSEC-2026-248"],"sourceIds":["GHSA-jp82-jpqv-5vv3","PYSEC-2026-248"],"published":"2026-06-15T20:38:08Z","modified":"2026-09-10T03:50:50.050800090Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-jp82-jpqv-5vv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54282"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-248.yaml"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.48.0","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0","pypi:starlette@1.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-jpw9-pfvf-9f58","slug":"ghsa-jpw9-pfvf-9f58-39682a8f","dossier":false,"summary":"MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal","aliases":["CVE-2026-52869","PYSEC-2026-3482"],"sourceIds":["GHSA-jpw9-pfvf-9f58","PYSEC-2026-3482"],"published":"2026-07-16T19:58:53Z","modified":"2026-09-10T03:50:52.526763662Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52869"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2690"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2719"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/1abcca2408a6b50e10ec601181f63f9978705c00"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/ce267b6fc515dc4efc1dc70b6975b16ff0feef0a"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jpw9-pfvf-9f58"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1","pypi:mcp@1.19.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-jq35-7prp-9v3f","slug":"ghsa-jq35-7prp-9v3f-75660907","dossier":false,"summary":"PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys","aliases":["CVE-2026-48523","PYSEC-2026-176"],"sourceIds":["GHSA-jq35-7prp-9v3f","PYSEC-2026-176"],"published":"2026-05-28T16:16:29.280Z","modified":"2026-09-10T03:51:08.776007275Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48523"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-176.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-jwrc-g2q2-pq5p","slug":"ghsa-jwrc-g2q2-pq5p-dfb984e1","dossier":false,"summary":"PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.","aliases":["CVE-2026-102270"],"sourceIds":["GHSA-jwrc-g2q2-pq5p"],"published":"2026-09-30T14:40:25Z","modified":"2026-09-30T14:45:04.897791001Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jwrc-g2q2-pq5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102270"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-jwv3-5hgf-82ww","slug":"ghsa-jwv3-5hgf-82ww-d34fc541","dossier":false,"summary":"python-cryptography: Duplicate self-signed intermediates can cause exponential path-building","aliases":["CVE-2026-69249","PYSEC-2026-3553"],"sourceIds":["GHSA-jwv3-5hgf-82ww","PYSEC-2026-3553"],"published":"2026-08-03T21:26:50Z","modified":"2026-09-24T14:45:10.238420831Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249"},{"type":"WEB","url":"https://github.com/pyca/cryptography/pull/14960"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/3763aa79b"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jwv3-5hgf-82ww"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-m2h6-j472-rp4c","slug":"ghsa-m2h6-j472-rp4c-112d8b91","dossier":false,"summary":"python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees","aliases":["CVE-2026-69248","PYSEC-2026-3554"],"sourceIds":["GHSA-m2h6-j472-rp4c","PYSEC-2026-3554"],"published":"2026-08-03T21:26:57Z","modified":"2026-09-24T15:00:04.719975807Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69248"},{"type":"WEB","url":"https://github.com/pyca/cryptography/pull/14888"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/286c89128"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3554.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/cryptography"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m2h6-j472-rp4c"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-m5qp-6w8w-w647","slug":"ghsa-m5qp-6w8w-w647-495897bd","dossier":false,"summary":"AIOHTTP has a Multipart Header Size Bypass","aliases":["CVE-2026-34516","PYSEC-2026-2098"],"sourceIds":["GHSA-m5qp-6w8w-w647","PYSEC-2026-2098"],"published":"2026-04-01T21:16:59.723Z","modified":"2026-09-10T03:51:02.372876858Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m5qp-6w8w-w647"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34516"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/8a74257b3804c9aac0bf644af93070f68f6c5a6f"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-m6qw-4cw2-hm4m","slug":"ghsa-m6qw-4cw2-hm4m-3f6d3ee7","dossier":false,"summary":"aiohttp: CRLF injection in multipart headers","aliases":["CVE-2026-50269","PYSEC-2026-2106"],"sourceIds":["GHSA-m6qw-4cw2-hm4m","PYSEC-2026-2106"],"published":"2026-06-15T20:07:26Z","modified":"2026-09-10T03:51:09.078868018Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-m959-cc7f-wv43","slug":"ghsa-m959-cc7f-wv43-3b497c67","dossier":false,"summary":"cryptography has incomplete DNS name constraint enforcement on peer names","aliases":["CVE-2026-34073","PYSEC-2026-35"],"sourceIds":["GHSA-m959-cc7f-wv43","PYSEC-2026-35"],"published":"2026-03-27T19:56:21Z","modified":"2026-09-10T03:51:00.592317622Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34073"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-35.yaml"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mf9v-mfxr-j63j","slug":"ghsa-mf9v-mfxr-j63j-1a7db6d4","dossier":false,"summary":"urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API","aliases":["CVE-2026-44432","PYSEC-2026-142"],"sourceIds":["GHSA-mf9v-mfxr-j63j","PYSEC-2026-142"],"published":"2026-05-11T14:51:45Z","modified":"2026-09-10T03:51:06.409994465Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-mf9w-mj56-hr94","slug":"ghsa-mf9w-mj56-hr94-a492e0f4","dossier":false,"summary":"python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback","aliases":["CVE-2026-28684","PYSEC-2026-2270"],"sourceIds":["GHSA-mf9w-mj56-hr94","PYSEC-2026-2270"],"published":"2026-04-20T17:16:33.087Z","modified":"2026-09-10T03:51:02.363430883Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/security/advisories/GHSA-mf9w-mj56-hr94"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28684"},{"type":"FIX","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311"},{"type":"WEB","url":"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311.patch"},{"type":"PACKAGE","url":"https://github.com/theskumar/python-dotenv"},{"type":"ADVISORY","url":"https://github.com/theskumar/python-dotenv/releases/tag/v1.2.2"}],"versionKeys":["pypi:python-dotenv@1.0.1","pypi:python-dotenv@1.1.0","pypi:python-dotenv@1.1.1","pypi:python-dotenv@1.2.1"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-mfx4-hv73-q22v","slug":"ghsa-mfx4-hv73-q22v-b33d9650","dossier":false,"summary":"AIOHTTP: HTTP request smuggling via WebSocket upgrade","aliases":["CVE-2026-69243","PYSEC-2026-3546"],"sourceIds":["GHSA-mfx4-hv73-q22v","PYSEC-2026-3546"],"published":"2026-08-03T20:46:10Z","modified":"2026-09-10T03:51:14.385788837Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/pull/13017"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mfx4-hv73-q22v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69243"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5","pypi:aiohttp@3.14.1"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-mj87-hwqh-73pj","slug":"ghsa-mj87-hwqh-73pj-92a4d569","dossier":false,"summary":"python-multipart affected by Denial of Service via large multipart preamble or epilogue data","aliases":["CVE-2026-40347","PYSEC-2026-3038"],"sourceIds":["GHSA-mj87-hwqh-73pj","PYSEC-2026-3038"],"published":"2026-04-15T19:45:44Z","modified":"2026-09-10T03:51:02.322677211Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-mj87-hwqh-73pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40347"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/releases/tag/0.0.26"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mj87-hwqh-73pj"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-mq44-7p77-q5h7","slug":"ghsa-mq44-7p77-q5h7-6bd0337a","dossier":false,"summary":"AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate","aliases":["CVE-2026-59881","PYSEC-2026-3547"],"sourceIds":["GHSA-mq44-7p77-q5h7","PYSEC-2026-3547"],"published":"2026-08-03T20:40:55Z","modified":"2026-09-10T03:51:14.489650589Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59881"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/pull/12978"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mq44-7p77-q5h7"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5","pypi:aiohttp@3.14.1"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-mqqc-3gqh-h2x8","slug":"ghsa-mqqc-3gqh-h2x8-6d702daf","dossier":false,"summary":"AIOHTTP has unicode match groups in regexes for ASCII protocol elements","aliases":["CVE-2025-69225","PYSEC-2026-1109"],"sourceIds":["GHSA-mqqc-3gqh-h2x8","PYSEC-2026-1109"],"published":"2026-01-05T23:09:30Z","modified":"2026-09-10T03:50:33.538693726Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69225"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqqc-3gqh-h2x8"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-mwh4-6h8g-pg8w","slug":"ghsa-mwh4-6h8g-pg8w-881420d8","dossier":false,"summary":"AIOHTTP has HTTP response splitting via \\r in reason phrase","aliases":["CVE-2026-34519","PYSEC-2026-2101"],"sourceIds":["GHSA-mwh4-6h8g-pg8w","PYSEC-2026-2101"],"published":"2026-04-01T21:17:00.170Z","modified":"2026-09-10T03:50:44.819886754Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mwh4-6h8g-pg8w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34519"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53b35a2f8869c37a133e60bf1a82a1c01642ba2b"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-p423-j2cm-9vmq","slug":"ghsa-p423-j2cm-9vmq-1455bc4c","dossier":false,"summary":"Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs","aliases":["CVE-2026-39892","PYSEC-2026-36"],"sourceIds":["GHSA-p423-j2cm-9vmq","PYSEC-2026-36"],"published":"2026-04-08T19:23:08Z","modified":"2026-09-10T03:50:44.766981051Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39892"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml"}],"versionKeys":["pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-p4g4-x82p-q773","slug":"ghsa-p4g4-x82p-q773-9c537199","dossier":false,"summary":"PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard","aliases":["CVE-2026-102271"],"sourceIds":["GHSA-p4g4-x82p-q773"],"published":"2026-09-29T23:14:33Z","modified":"2026-09-29T23:30:03.853857825Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102271"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-p998-jp59-783m","slug":"ghsa-p998-jp59-783m-17c88f0d","dossier":false,"summary":"AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows","aliases":["CVE-2026-34515","PYSEC-2026-2097"],"sourceIds":["GHSA-p998-jp59-783m","PYSEC-2026-2097"],"published":"2026-04-01T21:16:59.570Z","modified":"2026-09-10T03:51:02.565661873Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34515"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-pp6c-gr5w-3c5g","slug":"ghsa-pp6c-gr5w-3c5g-de40aafe","dossier":false,"summary":"python-multipart has Denial of Service via unbounded multipart part headers","aliases":["CVE-2026-42561","PYSEC-2026-3039"],"sourceIds":["GHSA-pp6c-gr5w-3c5g","PYSEC-2026-3039"],"published":"2026-05-06T21:56:14Z","modified":"2026-09-10T03:50:47.215892833Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-pp6c-gr5w-3c5g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42561"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pp6c-gr5w-3c5g"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-pq67-6m6q-mj2v","slug":"ghsa-pq67-6m6q-mj2v-3522d1d4","dossier":false,"summary":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","aliases":["CVE-2025-50181","PYSEC-2026-1999"],"sourceIds":["GHSA-pq67-6m6q-mj2v","PYSEC-2026-1999"],"published":"2025-06-18T17:50:00Z","modified":"2026-09-10T03:50:25.299291456Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/urllib3"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-q2x7-8rv6-6q7h","slug":"ghsa-q2x7-8rv6-6q7h-1113a288","dossier":false,"summary":"Jinja has a sandbox breakout through indirect reference to format method","aliases":["CVE-2024-56326","PYSEC-2026-1475"],"sourceIds":["GHSA-q2x7-8rv6-6q7h","PYSEC-2026-1475"],"published":"2024-12-23T17:56:08Z","modified":"2026-09-10T03:50:21.662855250Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56326"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2x7-8rv6-6q7h"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qccp-gfcp-xxvc","slug":"ghsa-qccp-gfcp-xxvc-0d988969","dossier":true,"summary":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects","aliases":["CVE-2026-44431","PYSEC-2026-141"],"sourceIds":["GHSA-qccp-gfcp-xxvc","PYSEC-2026-141"],"published":"2026-05-11T14:51:20Z","modified":"2026-09-10T03:50:47.272765640Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3"],"packageCount":1,"repositoryCount":18},{"id":"GHSA-qmgc-5h2g-mvrw","slug":"ghsa-qmgc-5h2g-mvrw-199eacc8","dossier":false,"summary":"filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock","aliases":["CVE-2026-22701","PYSEC-2026-1374"],"sourceIds":["GHSA-qmgc-5h2g-mvrw","PYSEC-2026-1374"],"published":"2026-01-13T18:44:55Z","modified":"2026-09-10T03:50:33.702580779Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22701"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qmgc-5h2g-mvrw"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-r6ph-v2qm-q3c2","slug":"ghsa-r6ph-v2qm-q3c2-c75907df","dossier":false,"summary":"cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves","aliases":["CVE-2026-26007","PYSEC-2026-2141"],"sourceIds":["GHSA-r6ph-v2qm-q3c2","PYSEC-2026-2141"],"published":"2026-02-10T21:27:06Z","modified":"2026-09-10T03:50:59.750965345Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26007"},{"type":"WEB","url":"https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c"},{"type":"PACKAGE","url":"https://github.com/pyca/cryptography"},{"type":"WEB","url":"https://github.com/pyca/cryptography/releases/tag/46.0.5"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-26007"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:12176"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13553"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13672"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19355"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21431"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21517"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22330"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22993"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:2694"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:cryptography@42.0.8","pypi:cryptography@43.0.3","pypi:cryptography@44.0.0","pypi:cryptography@44.0.3","pypi:cryptography@45.0.7","pypi:cryptography@46.0.3"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-r6x4-923q-g947","slug":"ghsa-r6x4-923q-g947-b796420c","dossier":false,"summary":"PyJWT BOM Bypass","aliases":["CVE-2026-102272"],"sourceIds":["GHSA-r6x4-923q-g947"],"published":"2026-09-29T23:14:00Z","modified":"2026-09-29T23:30:03.855539261Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102272"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/180783930de91876bc0d601f826a1f2956057291"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.13.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-v9pg-7xvm-68hf","slug":"ghsa-v9pg-7xvm-68hf-bd9c7524","dossier":false,"summary":"python-multipart: Negative Content-Length in parse_form buffers the entire body in memory","aliases":["CVE-2026-53540","PYSEC-2026-3040"],"sourceIds":["GHSA-v9pg-7xvm-68hf","PYSEC-2026-3040"],"published":"2026-06-15T20:23:45Z","modified":"2026-09-10T03:50:50.590441047Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-v9pg-7xvm-68hf"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v9pg-7xvm-68hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53540"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.28","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-vffw-93wf-4j4q","slug":"ghsa-vffw-93wf-4j4q-3828c302","dossier":false,"summary":"python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters","aliases":["CVE-2026-53537","PYSEC-2026-3041"],"sourceIds":["GHSA-vffw-93wf-4j4q","PYSEC-2026-3041"],"published":"2026-06-15T20:20:51Z","modified":"2026-09-10T03:50:50.585695996Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-vffw-93wf-4j4q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53537"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vffw-93wf-4j4q"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/blob/main/vulns/python-multipart/PYSEC-2026-3041.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.28","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-vj7q-gjh5-988w","slug":"ghsa-vj7q-gjh5-988w-54882ae8","dossier":false,"summary":"MCP Python SDK: WebSocket server transport does not support Host/Origin validation","aliases":["CVE-2026-59950","PYSEC-2026-3483"],"sourceIds":["GHSA-vj7q-gjh5-988w","PYSEC-2026-3483"],"published":"2026-07-16T20:14:34Z","modified":"2026-09-10T03:50:53.083568399Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-vj7q-gjh5-988w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59950"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2992"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.28.1"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vj7q-gjh5-988w"}],"versionKeys":["pypi:mcp@1.10.0","pypi:mcp@1.14.1","pypi:mcp@1.19.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-vqfr-h8mv-ghfj","slug":"ghsa-vqfr-h8mv-ghfj-49515033","dossier":false,"summary":"h11 accepts some malformed Chunked-Encoding bodies","aliases":["CVE-2025-43859","PYSEC-2026-348"],"sourceIds":["GHSA-vqfr-h8mv-ghfj","PYSEC-2026-348"],"published":"2025-04-24T16:07:56Z","modified":"2026-09-10T03:50:24.086696793Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43859"},{"type":"WEB","url":"https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h11"},{"type":"PACKAGE","url":"https://pypi.org/project/h11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqfr-h8mv-ghfj"}],"versionKeys":["pypi:h11@0.14.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-vxq7-64xx-v4gw","slug":"ghsa-vxq7-64xx-v4gw-3e875898","dossier":true,"summary":"urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory","aliases":["CVE-2026-97689"],"sourceIds":["GHSA-vxq7-64xx-v4gw"],"published":"2026-09-30T14:46:18Z","modified":"2026-09-30T15:00:05.904945330Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/2.8.0"}],"versionKeys":["pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0","pypi:urllib3@2.6.3","pypi:urllib3@2.7.0"],"packageCount":1,"repositoryCount":22},{"id":"GHSA-w2cx-738m-mc7w","slug":"ghsa-w2cx-738m-mc7w-6741b272","dossier":false,"summary":"PyJWT accepts public JWK containers as HMAC secrets","aliases":["CVE-2026-102273"],"sourceIds":["GHSA-w2cx-738m-mc7w"],"published":"2026-09-29T23:16:55Z","modified":"2026-09-29T23:30:03.873701729Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102273"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.13.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-w2fm-2cpv-w7v5","slug":"ghsa-w2fm-2cpv-w7v5-c2f7701a","dossier":false,"summary":"aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage","aliases":["CVE-2026-22815","PYSEC-2026-2094"],"sourceIds":["GHSA-w2fm-2cpv-w7v5","PYSEC-2026-2094"],"published":"2026-04-01T19:45:17Z","modified":"2026-09-10T03:51:03.588955358Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-w2fm-2cpv-w7v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22815"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-w6j9-cwv2-h6wq","slug":"ghsa-w6j9-cwv2-h6wq-1e6b5139","dossier":false,"summary":"PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set","aliases":["CVE-2026-102274"],"sourceIds":["GHSA-w6j9-cwv2-h6wq"],"published":"2026-09-29T18:23:01Z","modified":"2026-09-29T18:30:41.171809330Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102274"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/8915570a0bfda9f0ff0e34e7fb09bdb9d71580cf"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.13.0","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":5},{"id":"GHSA-w7vc-732c-9m39","slug":"ghsa-w7vc-732c-9m39-90a52664","dossier":false,"summary":"PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS","aliases":["CVE-2026-48525","PYSEC-2026-178"],"sourceIds":["GHSA-w7vc-732c-9m39","PYSEC-2026-178"],"published":"2026-05-28T16:16:29.533Z","modified":"2026-09-10T03:50:50.801195449Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48525"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-178.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-w853-jp5j-5j7f","slug":"ghsa-w853-jp5j-5j7f-2786386f","dossier":false,"summary":"filelock has a TOCTOU race condition which allows symlink attacks during lock file creation","aliases":["CVE-2025-68146","PYSEC-2026-1375"],"sourceIds":["GHSA-w853-jp5j-5j7f","PYSEC-2026-1375"],"published":"2025-12-16T20:52:55Z","modified":"2026-09-10T03:50:32.252960082Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/releases/tag/3.20.1"},{"type":"WEB","url":"https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants"},{"type":"WEB","url":"https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w853-jp5j-5j7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68146"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-wp53-j4wj-2cfg","slug":"ghsa-wp53-j4wj-2cfg-22cec3c5","dossier":false,"summary":"Python-Multipart has Arbitrary File Write via Non-Default Configuration","aliases":["CVE-2026-24486","PYSEC-2026-1852"],"sourceIds":["GHSA-wp53-j4wj-2cfg","PYSEC-2026-1852"],"published":"2026-01-26T23:28:05Z","modified":"2026-09-10T03:50:59.359593372Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"}],"references":[{"type":"WEB","url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-wp53-j4wj-2cfg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24486"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/commit/9433f4bbc9652bdde82bbe380984e32f8cfc89c4"},{"type":"PACKAGE","url":"https://github.com/Kludex/python-multipart"},{"type":"WEB","url":"https://github.com/Kludex/python-multipart/releases/tag/0.0.22"},{"type":"PACKAGE","url":"https://pypi.org/project/python-multipart"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wp53-j4wj-2cfg"}],"versionKeys":["pypi:python-multipart@0.0.18","pypi:python-multipart@0.0.20","pypi:python-multipart@0.0.9"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-wqp7-x3pw-xc5r","slug":"ghsa-wqp7-x3pw-xc5r-4caabf81","dossier":false,"summary":"Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows","aliases":["CVE-2026-48818","PYSEC-2026-2281"],"sourceIds":["GHSA-wqp7-x3pw-xc5r","PYSEC-2026-2281"],"published":"2026-06-15T20:16:30Z","modified":"2026-09-10T03:50:51.079936646Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-wqp7-x3pw-xc5r"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48818"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48818.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30087"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490020"},{"type":"FIX","url":"https://github.com/Kludex/starlette/commit/fd53168a7767b6b55ba5af787fd88f49e33cabc5"},{"type":"FIX","url":"https://github.com/Kludex/starlette/pull/3287"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.48.0","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0","pypi:starlette@1.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-x746-7m8f-x49c","slug":"ghsa-x746-7m8f-x49c-c0349d3f","dossier":false,"summary":"Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`","aliases":["CVE-2026-48817","PYSEC-2026-2280"],"sourceIds":["GHSA-x746-7m8f-x49c","PYSEC-2026-2280"],"published":"2026-06-15T20:16:05Z","modified":"2026-09-10T03:50:12.272722043Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-x746-7m8f-x49c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48817"},{"type":"PACKAGE","url":"https://github.com/Kludex/starlette"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/releases/tag/1.1.0"}],"versionKeys":["pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2","pypi:starlette@0.47.3","pypi:starlette@0.48.0","pypi:starlette@0.49.0","pypi:starlette@0.49.3","pypi:starlette@0.50.0","pypi:starlette@1.0.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-xcgm-r5h9-7989","slug":"ghsa-xcgm-r5h9-7989-77bcbc26","dossier":false,"summary":"aiohttp: Incomplete websocket frame payloads bypass memory limits","aliases":["CVE-2026-54274","PYSEC-2026-2108"],"sourceIds":["GHSA-xcgm-r5h9-7989","PYSEC-2026-2108"],"published":"2026-06-15T20:11:22Z","modified":"2026-09-10T03:50:12.346397944Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3","pypi:aiohttp@3.13.5"],"packageCount":1,"repositoryCount":11},{"id":"GHSA-xgmm-8j9v-c9wx","slug":"ghsa-xgmm-8j9v-c9wx-bc6db7ad","dossier":false,"summary":"PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed","aliases":["CVE-2026-48526","PYSEC-2026-179"],"sourceIds":["GHSA-xgmm-8j9v-c9wx","PYSEC-2026-179"],"published":"2026-05-28T16:16:29.657Z","modified":"2026-09-10T03:51:09.678127621Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48526"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-179.yaml"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-183","slug":"pysec-2025-183-08217171","dossier":false,"summary":null,"aliases":["CVE-2025-45768"],"sourceIds":["PYSEC-2025-183"],"published":"2025-07-31T21:15:27.320Z","modified":"2026-05-21T15:00:28.178881228Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/jpadilla"},{"type":"REPORT","url":"https://gist.github.com/ZupeiNie/6f65e564f2067b876321d3dfdbb76569"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"}],"versionKeys":["pypi:pyjwt@2.10.1","pypi:pyjwt@2.9.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-2132","slug":"pysec-2026-2132-627bf7c7","dossier":true,"summary":null,"aliases":["CVE-2026-7246","GHSA-47fr-3ffg-hgmw"],"sourceIds":["PYSEC-2026-2132"],"published":"2026-04-30T14:16:36.433Z","modified":"2026-07-13T07:15:21.899333658Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-7246"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464121"},{"type":"FIX","url":"https://github.com/pallets/click/releases/tag/8.3.3"},{"type":"EVIDENCE","url":"https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw"}],"versionKeys":["pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1"],"packageCount":1,"repositoryCount":17},{"id":"PYSEC-2026-4013","slug":"pysec-2026-4013-c111658c","dossier":false,"summary":"virtualenv bash and fish activation scripts execute commands embedded in paths","aliases":["CVE-2026-102925","GHSA-p58f-9548-mpm2"],"sourceIds":["PYSEC-2026-4013"],"published":"2026-09-18T04:37:14Z","modified":"2026-09-30T16:45:02.556138982Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3252"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/releases/tag/21.7.13"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4","pypi:virtualenv@21.2.4","pypi:virtualenv@21.3.1","pypi:virtualenv@21.7.1"],"packageCount":1,"repositoryCount":9},{"id":"PYSEC-2026-4014","slug":"pysec-2026-4014-0a5c8171","dossier":false,"summary":"Command injection via --prompt in activate.bat (batch activator)","aliases":["CVE-2026-102937","GHSA-x78j-v8h9-3j2q"],"sourceIds":["PYSEC-2026-4014"],"published":"2026-09-18T01:41:45Z","modified":"2026-09-30T16:45:02.570148666Z","checkedAt":"2026-10-01T06:23:02.848Z","severity":[],"references":[{"type":"WEB","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/pull/3250"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6"},{"type":"WEB","url":"https://github.com/pypa/virtualenv/releases/tag/21.7.12"},{"type":"PACKAGE","url":"https://github.com/pypa/virtualenv"},{"type":"PACKAGE","url":"https://pypi.org/project/virtualenv"}],"versionKeys":["pypi:virtualenv@20.30.0","pypi:virtualenv@20.31.1","pypi:virtualenv@20.34.0","pypi:virtualenv@20.35.4","pypi:virtualenv@21.2.4","pypi:virtualenv@21.3.1","pypi:virtualenv@21.7.1"],"packageCount":1,"repositoryCount":9}]}}
