{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:9998","slug":"opencode-9998","gitlabProjectId":9998,"name":"density-maps","pathWithNamespace":"uba-ki-lab/density-maps","description":"A minimal library for Gaussian density map workflows with PyTorch and albumentations. Keywords: uba, umweltbundesamt, ki-lab, computer vision, object counting","webUrl":"https://gitlab.opencode.de/uba-ki-lab/density-maps","commitSha":"1da30304236d86dfb376a429b1ea6e9fddba3a0a","commitUrl":"https://gitlab.opencode.de/uba-ki-lab/density-maps/-/commit/1da30304236d86dfb376a429b1ea6e9fddba3a0a","lastActivityAt":"2026-03-20T12:17:58.583Z","headCommittedAt":"2026-03-20T09:58:21.000Z","tree":{"complete":true,"entryCount":33,"truncated":false},"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"fa64e230fe01c25e6d465e090acbed3d4d86a694","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/density-maps/-/blob/1da30304236d86dfb376a429b1ea6e9fddba3a0a/uv.lock","commitSha":"1da30304236d86dfb376a429b1ea6e9fddba3a0a","contentSha256":"a3585500d962f78bc6cb14fec81c1117e03be3b4ca8961149d10c8a44c3682ed","byteCount":357047,"state":"parsed","componentCount":66}],"resolvedComponentCount":66,"artifactResolvedComponentCount":66,"exactManifestPinCount":0,"packageCount":66,"ecosystems":["pypi"],"aiPackageCount":1,"licenseExpressionCount":13,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-2fqr-mr3j-6wp8","GHSA-2vrm-gr82-f7m5","GHSA-3749-ghw9-m3mg","GHSA-3wq7-rqq7-wx6j","GHSA-4fvr-rgm6-gqmc","GHSA-4m7w-qmgq-4wj5","GHSA-5239-wwwm-4pmq","GHSA-53q9-r3pm-6pq6","GHSA-54jq-c3m8-4m76","GHSA-5rjg-fvgr-3xxf","GHSA-5xmw-vc9v-4wf2","GHSA-63hf-3vf5-4wqf","GHSA-63hw-fmq6-xxg2","GHSA-65pc-fj4g-8rjx","GHSA-69f9-5gxw-wvc2","GHSA-6jhg-hg63-jvvf","GHSA-6mq8-rvhq-8wgg","GHSA-6w46-j5rx-g56g","GHSA-887c-mr87-cxwp","GHSA-9548-qrrj-x5pj","GHSA-966j-vmvw-g2g9","GHSA-9x8q-7h8h-wcw9","GHSA-c427-h43c-vf67","GHSA-c678-jfcj-6jmf","GHSA-cfh3-3jmp-rvhc","GHSA-cpwx-vrp4-4pq7","GHSA-cx63-2mw6-8hw5","GHSA-f4hp-rmr7-r7v8","GHSA-fh55-r93g-j68g","GHSA-g3cq-j2xw-wf74","GHSA-g7vv-2v7x-gj9p","GHSA-g84x-mcqj-x9qq","GHSA-gmj6-6f8f-6699","GHSA-h75v-3vvj-5mfj","GHSA-hcc4-c3v8-rx92","GHSA-hg6j-4rv6-33pg","GHSA-hpj7-wq8m-9hgp","GHSA-jg22-mg44-37j8","GHSA-jj3x-wxrx-4x23","GHSA-m5qp-6w8w-w647","GHSA-m6qw-4cw2-hm4m","GHSA-mqqc-3gqh-h2x8","GHSA-mwh4-6h8g-pg8w","GHSA-p998-jp59-783m","GHSA-pwv6-vv43-88gr","GHSA-q2x7-8rv6-6q7h","GHSA-qfhq-4f3w-5fph","GHSA-qmgc-5h2g-mvrw","GHSA-r73j-pqj5-w3x7","GHSA-rrmf-rvhw-rf47","GHSA-vgrw-7cvw-pwgx","GHSA-w2fm-2cpv-w7v5","GHSA-w853-jp5j-5j7f","GHSA-whj4-6x5x-4v2j","GHSA-wjx4-4jcj-g98j","GHSA-x3gm-94wq-g975","GHSA-xcgm-r5h9-7989","GHSA-xg8h-j46f-w952","PYSEC-2025-198","PYSEC-2025-199","PYSEC-2025-200","PYSEC-2025-201","PYSEC-2025-202","PYSEC-2025-203","PYSEC-2025-204","PYSEC-2025-205","PYSEC-2025-206","PYSEC-2025-207","PYSEC-2025-208","PYSEC-2025-209","PYSEC-2026-139","PYSEC-2026-2253","PYSEC-2026-2254","PYSEC-2026-2255","PYSEC-2026-2256","PYSEC-2026-2257","PYSEC-2026-2286","PYSEC-2026-3447","PYSEC-2026-3451","PYSEC-2026-3452","PYSEC-2026-3453"],"advisoryCount":81,"providers":[]},"evidence":{"files":[{"path":"uv.lock","kind":"uv-lock","blobSha":"fa64e230fe01c25e6d465e090acbed3d4d86a694","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/density-maps/-/blob/1da30304236d86dfb376a429b1ea6e9fddba3a0a/uv.lock","commitSha":"1da30304236d86dfb376a429b1ea6e9fddba3a0a","contentSha256":"a3585500d962f78bc6cb14fec81c1117e03be3b4ca8961149d10c8a44c3682ed","byteCount":357047,"state":"parsed","componentCount":66}],"occurrenceCount":66},"related":{"packages":[{"id":"package:pypi:torch","slug":"torch-47a5352a","identity":"pypi:torch","label":"PyTorch","aiRelevant":true,"provider":null,"advisoryCount":23,"licenseExpressions":["BSD-3-Clause"],"versions":["2.10.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohttp","slug":"aiohttp-5a806a63","identity":"pypi:aiohttp","label":"aiohttp","aiRelevant":false,"provider":null,"advisoryCount":30,"licenseExpressions":["Apache-2.0","Apache-2.0 AND MIT"],"versions":["3.13.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pillow","slug":"pillow-834347dd","identity":"pypi:pillow","label":"pillow","aiRelevant":false,"provider":null,"advisoryCount":15,"licenseExpressions":["HPND","MIT-CMU"],"versions":["12.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:jinja2","slug":"jinja2-f7d34747","identity":"pypi:jinja2","label":"jinja2","aiRelevant":false,"provider":null,"advisoryCount":4,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.1.6"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:setuptools","slug":"setuptools-fe37c31a","identity":"pypi:setuptools","label":"setuptools","aiRelevant":false,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["82.0.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:filelock","slug":"filelock-b1c63968","identity":"pypi:filelock","label":"filelock","aiRelevant":false,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT","Unlicense"],"versions":["3.25.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:idna","slug":"idna-994c9929","identity":"pypi:idna","label":"idna","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.11"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pygments","slug":"pygments-ad71bc11","identity":"pypi:pygments","label":"pygments","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-2-Clause"],"versions":["2.19.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest","slug":"pytest-07c6f86c","identity":"pypi:pytest","label":"pytest","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["9.0.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:tqdm","slug":"tqdm-04b01f90","identity":"pypi:tqdm","label":"tqdm","aiRelevant":false,"provider":null,"advisoryCount":1,"licenseExpressions":["MIT AND MPL-2.0"],"versions":["4.67.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiohappyeyeballs","slug":"aiohappyeyeballs-ea4657b8","identity":"pypi:aiohappyeyeballs","label":"aiohappyeyeballs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0"],"versions":["2.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:aiosignal","slug":"aiosignal-b6794e75","identity":"pypi:aiosignal","label":"aiosignal","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:albucore","slug":"albucore-2d92e9fa","identity":"pypi:albucore","label":"albucore","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.0.24"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:albumentations","slug":"albumentations-d333cb03","identity":"pypi:albumentations","label":"albumentations","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["2.0.8"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:annotated-types","slug":"annotated-types-2304c38b","identity":"pypi:annotated-types","label":"annotated-types","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.7.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:attrs","slug":"attrs-2e7954ac","identity":"pypi:attrs","label":"attrs","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["25.4.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:colorama","slug":"colorama-abaf57c3","identity":"pypi:colorama","label":"colorama","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.4.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:coverage","slug":"coverage-7ba89558","identity":"pypi:coverage","label":"coverage","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["7.13.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cuda-bindings","slug":"cuda-bindings-63e94baa","identity":"pypi:cuda-bindings","label":"cuda-bindings","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.9.4"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:cuda-pathfinder","slug":"cuda-pathfinder-6d2ddb13","identity":"pypi:cuda-pathfinder","label":"cuda-pathfinder","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:frozenlist","slug":"frozenlist-110237da","identity":"pypi:frozenlist","label":"frozenlist","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.8.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:fsspec","slug":"fsspec-b1a7c311","identity":"pypi:fsspec","label":"fsspec","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2026.2.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:iniconfig","slug":"iniconfig-1f66e358","identity":"pypi:iniconfig","label":"iniconfig","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lightning","slug":"lightning-28a5cccb","identity":"pypi:lightning","label":"lightning","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:lightning-utilities","slug":"lightning-utilities-46646cd2","identity":"pypi:lightning-utilities","label":"lightning-utilities","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.15.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:markupsafe","slug":"markupsafe-1bdd4c7f","identity":"pypi:markupsafe","label":"markupsafe","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:mpmath","slug":"mpmath-4ccb7a41","identity":"pypi:mpmath","label":"mpmath","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.3.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:multidict","slug":"multidict-b407a4ac","identity":"pypi:multidict","label":"multidict","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:networkx","slug":"networkx-c2336a8d","identity":"pypi:networkx","label":"networkx","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:numpy","slug":"numpy-ba79b98d","identity":"pypi:numpy","label":"numpy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib","non-standard"],"versions":["2.4.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cublas-cu12","slug":"nvidia-cublas-cu12-1d052261","identity":"pypi:nvidia-cublas-cu12","label":"nvidia-cublas-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.8.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cuda-cupti-cu12","slug":"nvidia-cuda-cupti-cu12-973480f1","identity":"pypi:nvidia-cuda-cupti-cu12","label":"nvidia-cuda-cupti-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.8.90"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cuda-nvrtc-cu12","slug":"nvidia-cuda-nvrtc-cu12-e32b7f38","identity":"pypi:nvidia-cuda-nvrtc-cu12","label":"nvidia-cuda-nvrtc-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.8.93"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cuda-runtime-cu12","slug":"nvidia-cuda-runtime-cu12-2b875d2a","identity":"pypi:nvidia-cuda-runtime-cu12","label":"nvidia-cuda-runtime-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.8.90"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cudnn-cu12","slug":"nvidia-cudnn-cu12-a21dce6d","identity":"pypi:nvidia-cudnn-cu12","label":"nvidia-cudnn-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["9.10.2.21"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cufft-cu12","slug":"nvidia-cufft-cu12-21ff54dd","identity":"pypi:nvidia-cufft-cu12","label":"nvidia-cufft-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["11.3.3.83"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cufile-cu12","slug":"nvidia-cufile-cu12-14048140","identity":"pypi:nvidia-cufile-cu12","label":"nvidia-cufile-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.13.1.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-curand-cu12","slug":"nvidia-curand-cu12-2fed778b","identity":"pypi:nvidia-curand-cu12","label":"nvidia-curand-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["10.3.9.90"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cusolver-cu12","slug":"nvidia-cusolver-cu12-7db0a33a","identity":"pypi:nvidia-cusolver-cu12","label":"nvidia-cusolver-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["11.7.3.90"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cusparse-cu12","slug":"nvidia-cusparse-cu12-d7e6a309","identity":"pypi:nvidia-cusparse-cu12","label":"nvidia-cusparse-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.5.8.93"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-cusparselt-cu12","slug":"nvidia-cusparselt-cu12-97587f50","identity":"pypi:nvidia-cusparselt-cu12","label":"nvidia-cusparselt-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.7.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nccl-cu12","slug":"nvidia-nccl-cu12-90361558","identity":"pypi:nvidia-nccl-cu12","label":"nvidia-nccl-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["2.27.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nvjitlink-cu12","slug":"nvidia-nvjitlink-cu12-6d08af75","identity":"pypi:nvidia-nvjitlink-cu12","label":"nvidia-nvjitlink-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["12.8.93"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nvshmem-cu12","slug":"nvidia-nvshmem-cu12-d7141303","identity":"pypi:nvidia-nvshmem-cu12","label":"nvidia-nvshmem-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["3.4.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:nvidia-nvtx-cu12","slug":"nvidia-nvtx-cu12-9a2d0378","identity":"pypi:nvidia-nvtx-cu12","label":"nvidia-nvtx-cu12","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0","non-standard"],"versions":["12.8.90"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:opencv-python-headless","slug":"opencv-python-headless-4c615221","identity":"pypi:opencv-python-headless","label":"opencv-python-headless","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["4.13.0.92"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:packaging","slug":"packaging-78ee1f47","identity":"pypi:packaging","label":"packaging","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0 OR BSD-2-Clause","non-standard"],"versions":["26.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pluggy","slug":"pluggy-24479aaf","identity":"pypi:pluggy","label":"pluggy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["1.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:propcache","slug":"propcache-1fcd6be4","identity":"pypi:propcache","label":"propcache","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["0.4.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic","slug":"pydantic-4ac148ca","identity":"pypi:pydantic","label":"pydantic","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.12.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pydantic-core","slug":"pydantic-core-f9814ebc","identity":"pypi:pydantic-core","label":"pydantic-core","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["2.41.5"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytest-cov","slug":"pytest-cov-1f608c88","identity":"pypi:pytest-cov","label":"pytest-cov","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["7.0.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pytorch-lightning","slug":"pytorch-lightning-1550c03a","identity":"pypi:pytorch-lightning","label":"pytorch-lightning","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["2.6.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:pyyaml","slug":"pyyaml-16000901","identity":"pypi:pyyaml","label":"pyyaml","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["6.0.3"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ruff","slug":"ruff-d5943bdf","identity":"pypi:ruff","label":"ruff","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.15.6"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:scipy","slug":"scipy-215f884d","identity":"pypi:scipy","label":"scipy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.17.1"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:simsimd","slug":"simsimd-7089790e","identity":"pypi:simsimd","label":"simsimd","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["6.5.16"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:stringzilla","slug":"stringzilla-f268dc86","identity":"pypi:stringzilla","label":"stringzilla","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["4.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:sympy","slug":"sympy-b30cb89e","identity":"pypi:sympy","label":"sympy","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["1.14.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:torchmetrics","slug":"torchmetrics-87072a51","identity":"pypi:torchmetrics","label":"torchmetrics","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.9.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:torchvision","slug":"torchvision-7f85cafa","identity":"pypi:torchvision","label":"torchvision","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["non-standard"],"versions":["0.25.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:triton","slug":"triton-601ea838","identity":"pypi:triton","label":"triton","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["3.6.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:ty","slug":"ty-9d155882","identity":"pypi:ty","label":"ty","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.23"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-extensions","slug":"typing-extensions-87d153eb","identity":"pypi:typing-extensions","label":"typing-extensions","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["PSF-2.0","non-standard"],"versions":["4.15.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:typing-inspection","slug":"typing-inspection-0abeb500","identity":"pypi:typing-inspection","label":"typing-inspection","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.4.2"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]},{"id":"package:pypi:yarl","slug":"yarl-05cd1b35","identity":"pypi:yarl","label":"yarl","aiRelevant":false,"provider":null,"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.23.0"],"dossier":false,"occurrenceCount":1,"directOccurrenceCount":0,"evidenceFiles":["uv.lock"]}],"vulnerabilities":[{"id":"GHSA-2fqr-mr3j-6wp8","slug":"ghsa-2fqr-mr3j-6wp8-5ee7c60f","dossier":false,"summary":"aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence","aliases":["CVE-2026-54279","PYSEC-2026-2112"],"sourceIds":["GHSA-2fqr-mr3j-6wp8","PYSEC-2026-2112"],"published":"2026-06-15T20:08:51Z","modified":"2026-07-13T07:26:35.059071977Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-2vrm-gr82-f7m5","slug":"ghsa-2vrm-gr82-f7m5-5092ea0c","dossier":false,"summary":"AIOHTTP has CRLF injection through multipart part content type header construction","aliases":["CVE-2026-34514","PYSEC-2026-2096"],"sourceIds":["GHSA-2vrm-gr82-f7m5","PYSEC-2026-2096"],"published":"2026-04-01T21:16:59.417Z","modified":"2026-07-13T07:26:28.471600737Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2vrm-gr82-f7m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34514"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-3749-ghw9-m3mg","slug":"ghsa-3749-ghw9-m3mg-fadf4a32","dossier":false,"summary":"PyTorch susceptible to local Denial of Service","aliases":["BIT-pytorch-2025-2953","CVE-2025-2953","PYSEC-2025-191"],"sourceIds":["GHSA-3749-ghw9-m3mg","PYSEC-2025-191"],"published":"2025-03-30T16:15:14.380Z","modified":"2026-06-10T17:02:35.808223212Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2953"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/149274"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/149274#issue-2923122269"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-191.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.302006"},{"type":"ADVISORY","url":"https://vuldb.com/?id.302006"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.521279"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3749-ghw9-m3mg"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-3wq7-rqq7-wx6j","slug":"ghsa-3wq7-rqq7-wx6j-29b8d785","dossier":false,"summary":"AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS","aliases":["CVE-2026-34517","PYSEC-2026-2099"],"sourceIds":["GHSA-3wq7-rqq7-wx6j","PYSEC-2026-2099"],"published":"2026-04-01T21:16:59.870Z","modified":"2026-07-13T07:26:13.561233517Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-3wq7-rqq7-wx6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34517"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/cbb774f38330563422ca0c413a71021d7b944145"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4fvr-rgm6-gqmc","slug":"ghsa-4fvr-rgm6-gqmc-c8b35c87","dossier":false,"summary":"aiohttp: HTTP/1 Pipelined Requests Queue Without Limit","aliases":["CVE-2026-54273","PYSEC-2026-2107"],"sourceIds":["GHSA-4fvr-rgm6-gqmc","PYSEC-2026-2107"],"published":"2026-06-15T20:10:32Z","modified":"2026-07-13T07:26:17.316378610Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-4m7w-qmgq-4wj5","slug":"ghsa-4m7w-qmgq-4wj5-f98433d3","dossier":false,"summary":"aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections","aliases":["CVE-2026-54275","PYSEC-2026-237"],"sourceIds":["GHSA-4m7w-qmgq-4wj5","PYSEC-2026-237"],"published":"2026-06-15T20:11:13Z","modified":"2026-06-27T11:26:29.646102490Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4m7w-qmgq-4wj5"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-5239-wwwm-4pmq","slug":"ghsa-5239-wwwm-4pmq-228840e4","dossier":true,"summary":"Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching","aliases":["CVE-2026-4539","PYSEC-2026-2987"],"sourceIds":["GHSA-5239-wwwm-4pmq","PYSEC-2026-2987"],"published":"2026-03-22T06:30:15Z","modified":"2026-07-13T16:42:36.989801915Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4539"},{"type":"WEB","url":"https://github.com/pygments/pygments/issues/3058"},{"type":"WEB","url":"https://github.com/pygments/pygments/pull/3064"},{"type":"WEB","url":"https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc"},{"type":"PACKAGE","url":"https://github.com/pygments/pygments"},{"type":"WEB","url":"https://github.com/pygments/pygments/releases/tag/2.20.0"},{"type":"WEB","url":"https://vuldb.com/?ctiid.352327"},{"type":"WEB","url":"https://vuldb.com/?id.352327"},{"type":"WEB","url":"https://vuldb.com/?submit.774685"},{"type":"PACKAGE","url":"https://pypi.org/project/pygments"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5239-wwwm-4pmq"}],"versionKeys":["pypi:pygments@2.19.1","pypi:pygments@2.19.2"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-53q9-r3pm-6pq6","slug":"ghsa-53q9-r3pm-6pq6-6fbb0149","dossier":false,"summary":"PyTorch: `torch.load` with `weights_only=True` leads to remote code execution","aliases":["BIT-pytorch-2025-32434","CVE-2025-32434","PYSEC-2025-41"],"sourceIds":["GHSA-53q9-r3pm-6pq6","PYSEC-2025-41"],"published":"2025-04-18T15:19:28Z","modified":"2026-02-04T02:38:45.601605Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32434"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/8d4b8a920a2172523deb95bf20e8e52d50649c04"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-41.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"}],"versionKeys":["pypi:torch@2.5.1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-54jq-c3m8-4m76","slug":"ghsa-54jq-c3m8-4m76-bba4b2d3","dossier":false,"summary":"AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components","aliases":["CVE-2025-69226","PYSEC-2026-1097"],"sourceIds":["GHSA-54jq-c3m8-4m76","PYSEC-2026-1097"],"published":"2026-01-05T23:09:51Z","modified":"2026-07-07T17:57:12.462419549Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-54jq-c3m8-4m76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69226"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f2a86fd5ac0383000d1715afddfa704413f0711e"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-54jq-c3m8-4m76"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-5rjg-fvgr-3xxf","slug":"ghsa-5rjg-fvgr-3xxf-79d39e6b","dossier":false,"summary":"setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write","aliases":["BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49"],"sourceIds":["GHSA-5rjg-fvgr-3xxf","PYSEC-2025-49"],"published":"2025-05-17T16:15:19Z","modified":"2026-05-11T00:26:34.671259971Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273"},{"type":"REPORT","url":"https://github.com/pypa/setuptools/issues/4946"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@75.8.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-5xmw-vc9v-4wf2","slug":"ghsa-5xmw-vc9v-4wf2-86a8861a","dossier":false,"summary":"Pillow has a heap buffer overflow with nested list coordinates","aliases":["BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251"],"sourceIds":["GHSA-5xmw-vc9v-4wf2","PYSEC-2026-2251"],"published":"2026-05-04T20:18:27Z","modified":"2026-07-13T07:26:28.768890335Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5xmw-vc9v-4wf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42309"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-63hf-3vf5-4wqf","slug":"ghsa-63hf-3vf5-4wqf-aadd9f0f","dossier":false,"summary":"AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass","aliases":["CVE-2026-34520","PYSEC-2026-2102"],"sourceIds":["GHSA-63hf-3vf5-4wqf","PYSEC-2026-2102"],"published":"2026-04-01T21:17:00.333Z","modified":"2026-07-15T22:00:51.319409225Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hf-3vf5-4wqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34520"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2026-2102.yaml"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-63hw-fmq6-xxg2","slug":"ghsa-63hw-fmq6-xxg2-00aac622","dossier":false,"summary":"aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines","aliases":["CVE-2026-54277","PYSEC-2026-2110"],"sourceIds":["GHSA-63hw-fmq6-xxg2","PYSEC-2026-2110"],"published":"2026-06-15T20:09:16Z","modified":"2026-07-13T07:26:29.010491244Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-63hw-fmq6-xxg2"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5ab61bb4cd88f19b712f12c7c9295fe262bf804d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-65pc-fj4g-8rjx","slug":"ghsa-65pc-fj4g-8rjx-9fe9e88a","dossier":true,"summary":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix","aliases":["CVE-2026-45409","PYSEC-2026-215"],"sourceIds":["GHSA-65pc-fj4g-8rjx","PYSEC-2026-215"],"published":"2026-05-19T14:34:32Z","modified":"2026-07-08T17:45:15.021597323Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409"},{"type":"PACKAGE","url":"https://github.com/kjd/idna"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"}],"versionKeys":["pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7"],"packageCount":1,"repositoryCount":17},{"id":"GHSA-69f9-5gxw-wvc2","slug":"ghsa-69f9-5gxw-wvc2-eec14573","dossier":false,"summary":"AIOHTTP's unicode processing of header values could cause parsing discrepancies","aliases":["CVE-2025-69224","PYSEC-2026-1099"],"sourceIds":["GHSA-69f9-5gxw-wvc2","PYSEC-2026-1099"],"published":"2026-01-05T22:58:57Z","modified":"2026-07-07T17:56:40.774148412Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-69f9-5gxw-wvc2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69224"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/32677f2adfd907420c078dda6b79225c6f4ebce0"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69f9-5gxw-wvc2"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6jhg-hg63-jvvf","slug":"ghsa-6jhg-hg63-jvvf-74cd77d8","dossier":false,"summary":"AIOHTTP vulnerable to  denial of service through large payloads","aliases":["CVE-2025-69228","PYSEC-2026-1100"],"sourceIds":["GHSA-6jhg-hg63-jvvf","PYSEC-2026-1100"],"published":"2026-01-05T23:13:14Z","modified":"2026-07-07T17:57:35.249454020Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69228"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6jhg-hg63-jvvf"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6mq8-rvhq-8wgg","slug":"ghsa-6mq8-rvhq-8wgg-d94d738f","dossier":false,"summary":"AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb","aliases":["CVE-2025-69223","PYSEC-2026-1101"],"sourceIds":["GHSA-6mq8-rvhq-8wgg","PYSEC-2026-1101"],"published":"2026-01-05T22:58:41Z","modified":"2026-07-07T17:56:11.402262091Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69223"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6mq8-rvhq-8wgg"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-6w46-j5rx-g56g","slug":"ghsa-6w46-j5rx-g56g-5324d549","dossier":false,"summary":"pytest has vulnerable tmpdir handling","aliases":["CVE-2025-71176","PYSEC-2026-1845"],"sourceIds":["GHSA-6w46-j5rx-g56g","PYSEC-2026-1845"],"published":"2026-01-22T06:30:29Z","modified":"2026-07-07T17:56:26.471696626Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71176"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/issues/13669"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/pull/14343"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/commit/95d8423bd24992deea5b9df32555fa1741679e2c"},{"type":"PACKAGE","url":"https://github.com/pytest-dev/pytes"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/releases/tag/9.0.3"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/01/21/5"},{"type":"PACKAGE","url":"https://pypi.org/project/pytest"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6w46-j5rx-g56g"}],"versionKeys":["pypi:pytest@7.2.2","pypi:pytest@7.4.4","pypi:pytest@8.3.2","pypi:pytest@9.0.2"],"packageCount":1,"repositoryCount":6},{"id":"GHSA-887c-mr87-cxwp","slug":"ghsa-887c-mr87-cxwp-233a2961","dossier":false,"summary":"PyTorch Improper Resource Shutdown or Release vulnerability","aliases":["BIT-pytorch-2025-3730","CVE-2025-3730","PYSEC-2026-1970"],"sourceIds":["GHSA-887c-mr87-cxwp","PYSEC-2026-1970"],"published":"2025-04-16T21:30:59Z","modified":"2026-07-14T16:44:12.813190902Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3730"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/150835"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/pull/150981"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/01f226bfb8f2c343f5c614a6bbf685d91160f3af"},{"type":"WEB","url":"https://github.com/timocafe/tewart-pytorch/commit/46fc5d8e360127361211cb237d5f9eef0223e567"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.305076"},{"type":"WEB","url":"https://vuldb.com/?id.305076"},{"type":"WEB","url":"https://vuldb.com/?submit.553645"},{"type":"PACKAGE","url":"https://pypi.org/project/torch"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-887c-mr87-cxwp"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-9548-qrrj-x5pj","slug":"ghsa-9548-qrrj-x5pj-6121f213","dossier":false,"summary":"AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections","aliases":["CVE-2025-53643","PYSEC-2026-1104"],"sourceIds":["GHSA-9548-qrrj-x5pj","PYSEC-2026-1104"],"published":"2025-07-14T19:33:31Z","modified":"2026-07-07T17:56:52.935544397Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9548-qrrj-x5pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53643"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9548-qrrj-x5pj"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-966j-vmvw-g2g9","slug":"ghsa-966j-vmvw-g2g9-dad9a989","dossier":false,"summary":"AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect","aliases":["CVE-2026-34518","PYSEC-2026-2100"],"sourceIds":["GHSA-966j-vmvw-g2g9","PYSEC-2026-2100"],"published":"2026-04-01T21:17:00.020Z","modified":"2026-07-13T07:26:39.502317923Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-966j-vmvw-g2g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34518"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-9x8q-7h8h-wcw9","slug":"ghsa-9x8q-7h8h-wcw9-af94166e","dossier":false,"summary":"aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect","aliases":["CVE-2026-54280","PYSEC-2026-2113"],"sourceIds":["GHSA-9x8q-7h8h-wcw9","PYSEC-2026-2113"],"published":"2026-06-15T20:10:44Z","modified":"2026-07-13T07:26:14.649569270Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9x8q-7h8h-wcw9"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c427-h43c-vf67","slug":"ghsa-c427-h43c-vf67-fa5b38aa","dossier":false,"summary":"AIOHTTP accepts duplicate Host headers","aliases":["CVE-2026-34525","PYSEC-2026-2103"],"sourceIds":["GHSA-c427-h43c-vf67","PYSEC-2026-2103"],"published":"2026-04-01T21:17:00.490Z","modified":"2026-07-13T07:26:42.158681139Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34525"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-c678-jfcj-6jmf","slug":"ghsa-c678-jfcj-6jmf-cd9a8774","dossier":false,"summary":"PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument","aliases":["BIT-pytorch-2025-2148","CVE-2025-2148","PYSEC-2025-189"],"sourceIds":["GHSA-c678-jfcj-6jmf"],"published":"2025-03-10T12:30:55Z","modified":"2026-06-09T21:26:06.844649427Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2148"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/147722"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-189.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/blob/b0a67c7495bb11ecb23e556058db059ba48354af/torch/autograd/profiler.py#L990"},{"type":"WEB","url":"https://vuldb.com/?ctiid.299059"},{"type":"WEB","url":"https://vuldb.com/?id.299059"},{"type":"WEB","url":"https://vuldb.com/?submit.505959"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cfh3-3jmp-rvhc","slug":"ghsa-cfh3-3jmp-rvhc-4e95572c","dossier":false,"summary":"Pillow affected by out-of-bounds write when loading PSD images","aliases":["BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249"],"sourceIds":["GHSA-cfh3-3jmp-rvhc","PYSEC-2026-2249"],"published":"2026-02-11T14:22:50Z","modified":"2026-07-13T07:26:49.514806069Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25990"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9427"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-25990"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14873"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14874"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:28385"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4128"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4942"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0"],"packageCount":1,"repositoryCount":12},{"id":"GHSA-cpwx-vrp4-4pq7","slug":"ghsa-cpwx-vrp4-4pq7-799bdc98","dossier":false,"summary":"Jinja2 vulnerable to sandbox breakout through attr filter selecting format method","aliases":["CVE-2025-27516","PYSEC-2026-1471"],"sourceIds":["GHSA-cpwx-vrp4-4pq7","PYSEC-2026-1471"],"published":"2025-03-05T20:40:14Z","modified":"2026-07-07T17:56:16.836141266Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-cpwx-vrp4-4pq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27516"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/90457bbf33b8662926ae65cdde4c4c32e756e403"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00045.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cpwx-vrp4-4pq7"}],"versionKeys":["pypi:jinja2@3.1.3","pypi:jinja2@3.1.5"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-cx63-2mw6-8hw5","slug":"ghsa-cx63-2mw6-8hw5-1754ad59","dossier":false,"summary":"setuptools vulnerable to Command Injection via package URL","aliases":["BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918"],"sourceIds":["GHSA-cx63-2mw6-8hw5","PYSEC-2026-1918"],"published":"2024-07-15T03:30:57Z","modified":"2026-07-07T17:57:13.326243614Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6345"},{"type":"WEB","url":"https://github.com/pypa/setuptools/pull/4332"},{"type":"WEB","url":"https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html"},{"type":"PACKAGE","url":"https://pypi.org/project/setuptools"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx63-2mw6-8hw5"}],"versionKeys":["pypi:setuptools@69.2.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-f4hp-rmr7-r7v8","slug":"ghsa-f4hp-rmr7-r7v8-fe038cb7","dossier":false,"summary":"PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function","aliases":["BIT-pytorch-2025-2998","CVE-2025-2998","PYSEC-2025-192"],"sourceIds":["GHSA-f4hp-rmr7-r7v8"],"published":"2025-03-31T15:30:48Z","modified":"2026-06-09T22:11:09.050788278Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2998"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622#issue-2935495265"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-192.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302047"},{"type":"WEB","url":"https://vuldb.com/?id.302047"},{"type":"WEB","url":"https://vuldb.com/?submit.524151"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-fh55-r93g-j68g","slug":"ghsa-fh55-r93g-j68g-a231bc8e","dossier":false,"summary":"AIOHTTP Vulnerable to Cookie Parser Warning Storm","aliases":["CVE-2025-69230","PYSEC-2026-1105"],"sourceIds":["GHSA-fh55-r93g-j68g","PYSEC-2026-1105"],"published":"2026-01-05T23:13:46Z","modified":"2026-07-07T17:56:34.702331996Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-fh55-r93g-j68g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69230"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/64629a0834f94e46d9881f4e99c41a137e1f3326"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh55-r93g-j68g"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-g3cq-j2xw-wf74","slug":"ghsa-g3cq-j2xw-wf74-4475e17b","dossier":false,"summary":"aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup","aliases":["CVE-2026-54278","PYSEC-2026-2111"],"sourceIds":["GHSA-g3cq-j2xw-wf74","PYSEC-2026-2111"],"published":"2026-06-15T20:09:51Z","modified":"2026-07-13T07:26:25.190325605Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g3cq-j2xw-wf74"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-g7vv-2v7x-gj9p","slug":"ghsa-g7vv-2v7x-gj9p-5ef970c3","dossier":false,"summary":"tqdm CLI arguments injection attack","aliases":["CVE-2024-34062","PYSEC-2026-1976"],"sourceIds":["GHSA-g7vv-2v7x-gj9p","PYSEC-2026-1976"],"published":"2024-05-03T19:33:28Z","modified":"2026-07-07T17:56:20.187915678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"},{"type":"WEB","url":"https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316"},{"type":"PACKAGE","url":"https://github.com/tqdm/tqdm"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC"},{"type":"PACKAGE","url":"https://pypi.org/project/tqdm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g7vv-2v7x-gj9p"}],"versionKeys":["pypi:tqdm@4.66.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g84x-mcqj-x9qq","slug":"ghsa-g84x-mcqj-x9qq-fc677e5d","dossier":false,"summary":"AIOHTTP vulnerable to DoS through chunked messages","aliases":["CVE-2025-69229","PYSEC-2026-1106"],"sourceIds":["GHSA-g84x-mcqj-x9qq","PYSEC-2026-1106"],"published":"2026-01-05T23:13:29Z","modified":"2026-07-07T17:56:31.463290158Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g84x-mcqj-x9qq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g84x-mcqj-x9qq"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-gmj6-6f8f-6699","slug":"ghsa-gmj6-6f8f-6699-e3e02f35","dossier":false,"summary":"Jinja has a sandbox breakout through malicious filenames","aliases":["CVE-2024-56201","PYSEC-2026-1472"],"sourceIds":["GHSA-gmj6-6f8f-6699","PYSEC-2026-1472"],"published":"2024-12-23T17:54:12Z","modified":"2026-07-07T17:56:55.074166933Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-gmj6-6f8f-6699"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56201"},{"type":"WEB","url":"https://github.com/pallets/jinja/issues/1792"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/767b23617628419ae3709ccfb02f9602ae9fe51f"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gmj6-6f8f-6699"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-h75v-3vvj-5mfj","slug":"ghsa-h75v-3vvj-5mfj-d8fc6bb7","dossier":false,"summary":"Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter","aliases":["CVE-2024-34064","PYSEC-2026-1474"],"sourceIds":["GHSA-h75v-3vvj-5mfj","PYSEC-2026-1474"],"published":"2024-05-06T14:20:59Z","modified":"2026-07-07T17:57:30.872296178Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34064"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h75v-3vvj-5mfj"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-hcc4-c3v8-rx92","slug":"ghsa-hcc4-c3v8-rx92-ddf32b5c","dossier":false,"summary":"AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector","aliases":["CVE-2026-34513","PYSEC-2026-2095"],"sourceIds":["GHSA-hcc4-c3v8-rx92","PYSEC-2026-2095"],"published":"2026-04-01T21:16:59.267Z","modified":"2026-07-13T07:26:43.174352940Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hcc4-c3v8-rx92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34513"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hg6j-4rv6-33pg","slug":"ghsa-hg6j-4rv6-33pg-d0ac8db0","dossier":false,"summary":"AIOHTTP is vulnerable to cross-origin redirect with per-request cookies","aliases":["CVE-2026-47265","PYSEC-2026-2105"],"sourceIds":["GHSA-hg6j-4rv6-33pg","PYSEC-2026-2105"],"published":"2026-06-02T20:16:37.903Z","modified":"2026-07-13T07:26:51.969507320Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hg6j-4rv6-33pg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47265"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-hpj7-wq8m-9hgp","slug":"ghsa-hpj7-wq8m-9hgp-fac25647","dossier":false,"summary":"aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges","aliases":["CVE-2026-54276","PYSEC-2026-2109"],"sourceIds":["GHSA-hpj7-wq8m-9hgp","PYSEC-2026-2109"],"published":"2026-06-15T20:09:06Z","modified":"2026-07-13T07:26:28.701980401Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hpj7-wq8m-9hgp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/38d16060037e1bfcd6d677abababa3c2a4bb58fa"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-jg22-mg44-37j8","slug":"ghsa-jg22-mg44-37j8-b8064c77","dossier":false,"summary":"AIOHTTP is Vulnerable to Deserialization of Untrusted Data","aliases":["CVE-2026-34993","PYSEC-2026-2104"],"sourceIds":["GHSA-jg22-mg44-37j8","PYSEC-2026-2104"],"published":"2026-06-02T20:16:34.857Z","modified":"2026-07-13T07:26:37.684367184Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-jj3x-wxrx-4x23","slug":"ghsa-jj3x-wxrx-4x23-407bafac","dossier":false,"summary":"AIOHTTP vulnerable to DoS when bypassing asserts","aliases":["CVE-2025-69227","PYSEC-2026-1107"],"sourceIds":["GHSA-jj3x-wxrx-4x23","PYSEC-2026-1107"],"published":"2026-01-05T23:10:15Z","modified":"2026-07-07T17:57:17.782415842Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jj3x-wxrx-4x23"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69227"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj3x-wxrx-4x23"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-m5qp-6w8w-w647","slug":"ghsa-m5qp-6w8w-w647-495897bd","dossier":false,"summary":"AIOHTTP has a Multipart Header Size Bypass","aliases":["CVE-2026-34516","PYSEC-2026-2098"],"sourceIds":["GHSA-m5qp-6w8w-w647","PYSEC-2026-2098"],"published":"2026-04-01T21:16:59.723Z","modified":"2026-07-13T07:26:19.821892403Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m5qp-6w8w-w647"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34516"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/8a74257b3804c9aac0bf644af93070f68f6c5a6f"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-m6qw-4cw2-hm4m","slug":"ghsa-m6qw-4cw2-hm4m-3f6d3ee7","dossier":false,"summary":"aiohttp: CRLF injection in multipart headers","aliases":["CVE-2026-50269","PYSEC-2026-2106"],"sourceIds":["GHSA-m6qw-4cw2-hm4m","PYSEC-2026-2106"],"published":"2026-06-15T20:07:26Z","modified":"2026-07-13T07:26:17.983947245Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-mqqc-3gqh-h2x8","slug":"ghsa-mqqc-3gqh-h2x8-6d702daf","dossier":false,"summary":"AIOHTTP has unicode match groups in regexes for ASCII protocol elements","aliases":["CVE-2025-69225","PYSEC-2026-1109"],"sourceIds":["GHSA-mqqc-3gqh-h2x8","PYSEC-2026-1109"],"published":"2026-01-05T23:09:30Z","modified":"2026-07-07T17:56:18.569417663Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}],"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69225"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"PACKAGE","url":"https://pypi.org/project/aiohttp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqqc-3gqh-h2x8"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2"],"packageCount":1,"repositoryCount":7},{"id":"GHSA-mwh4-6h8g-pg8w","slug":"ghsa-mwh4-6h8g-pg8w-881420d8","dossier":false,"summary":"AIOHTTP has HTTP response splitting via \\r in reason phrase","aliases":["CVE-2026-34519","PYSEC-2026-2101"],"sourceIds":["GHSA-mwh4-6h8g-pg8w","PYSEC-2026-2101"],"published":"2026-04-01T21:17:00.170Z","modified":"2026-07-13T07:26:39.246105773Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mwh4-6h8g-pg8w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34519"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/53b35a2f8869c37a133e60bf1a82a1c01642ba2b"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-p998-jp59-783m","slug":"ghsa-p998-jp59-783m-17c88f0d","dossier":false,"summary":"AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows","aliases":["CVE-2026-34515","PYSEC-2026-2097"],"sourceIds":["GHSA-p998-jp59-783m","PYSEC-2026-2097"],"published":"2026-04-01T21:16:59.570Z","modified":"2026-07-13T07:26:55.790859426Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34515"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-pwv6-vv43-88gr","slug":"ghsa-pwv6-vv43-88gr-c5f811d0","dossier":true,"summary":"Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)","aliases":["BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252"],"sourceIds":["GHSA-pwv6-vv43-88gr","PYSEC-2026-2252"],"published":"2026-05-04T20:20:31Z","modified":"2026-07-13T07:26:52.198871129Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42311"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9520"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-q2x7-8rv6-6q7h","slug":"ghsa-q2x7-8rv6-6q7h-1113a288","dossier":false,"summary":"Jinja has a sandbox breakout through indirect reference to format method","aliases":["CVE-2024-56326","PYSEC-2026-1475"],"sourceIds":["GHSA-q2x7-8rv6-6q7h","PYSEC-2026-1475"],"published":"2024-12-23T17:56:08Z","modified":"2026-07-07T17:56:44.376174317Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56326"},{"type":"FIX","url":"https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"},{"type":"PACKAGE","url":"https://pypi.org/project/jinja2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q2x7-8rv6-6q7h"}],"versionKeys":["pypi:jinja2@3.1.3"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qfhq-4f3w-5fph","slug":"ghsa-qfhq-4f3w-5fph-33bc3f14","dossier":false,"summary":"PyTorch is vulnerable to memory corruption through its torch.lstm_cell function","aliases":["BIT-pytorch-2025-3001","CVE-2025-3001","PYSEC-2025-195"],"sourceIds":["GHSA-qfhq-4f3w-5fph"],"published":"2025-03-31T18:31:08Z","modified":"2026-06-10T18:26:26.736808954Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3001"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149626"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149626#issue-2935860995"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/999d94b5ede5f4ec111ba7dd144129e2c2725b03"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-195.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302050"},{"type":"WEB","url":"https://vuldb.com/?id.302050"},{"type":"WEB","url":"https://vuldb.com/?submit.524212"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-qmgc-5h2g-mvrw","slug":"ghsa-qmgc-5h2g-mvrw-199eacc8","dossier":false,"summary":"filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock","aliases":["CVE-2026-22701","PYSEC-2026-1374"],"sourceIds":["GHSA-qmgc-5h2g-mvrw","PYSEC-2026-1374"],"published":"2026-01-13T18:44:55Z","modified":"2026-07-07T17:56:19.485233787Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22701"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/255ed068bc85d1ef406e50a135e1459170dd1bf0"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qmgc-5h2g-mvrw"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-r73j-pqj5-w3x7","slug":"ghsa-r73j-pqj5-w3x7-8d4d543f","dossier":true,"summary":"Pillow has a PDF Parsing Trailer Infinite Loop (DoS)","aliases":["BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874"],"sourceIds":["GHSA-r73j-pqj5-w3x7","PYSEC-2026-2874"],"published":"2026-05-04T20:19:30Z","modified":"2026-07-13T16:42:37.358429541Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-r73j-pqj5-w3x7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42310"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9519"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3bf614e4b8615d0ce1d5039efaf6db447fe7c468"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r73j-pqj5-w3x7"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-rrmf-rvhw-rf47","slug":"ghsa-rrmf-rvhw-rf47-389d8330","dossier":false,"summary":"PyTorch is vulnerable to memory corruption through its torch.jit.script function","aliases":["BIT-pytorch-2025-3000","CVE-2025-3000","PYSEC-2025-194"],"sourceIds":["GHSA-rrmf-rvhw-rf47"],"published":"2025-03-31T15:30:48Z","modified":"2026-07-17T17:15:51.452848951Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3000"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149623"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149623#issue-2935703015"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/b90c94991cdf8b87c8f7439f79518e0ef2c4ca4f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-194.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302049"},{"type":"WEB","url":"https://vuldb.com/?id.302049"},{"type":"WEB","url":"https://vuldb.com/?submit.524197"}],"versionKeys":["pypi:torch@2.10.0","pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-vgrw-7cvw-pwgx","slug":"ghsa-vgrw-7cvw-pwgx-766c6098","dossier":false,"summary":"PyTorch is vulnerable to memory corruption through its unpack_sequence function","aliases":["BIT-pytorch-2025-2999","CVE-2025-2999","PYSEC-2025-193"],"sourceIds":["GHSA-vgrw-7cvw-pwgx"],"published":"2025-03-31T15:30:48Z","modified":"2026-06-10T17:41:15.774477397Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2999"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/149622#issue-2935495265"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-193.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.302048"},{"type":"WEB","url":"https://vuldb.com/?id.302048"},{"type":"WEB","url":"https://vuldb.com/?submit.524198"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"GHSA-w2fm-2cpv-w7v5","slug":"ghsa-w2fm-2cpv-w7v5-c2f7701a","dossier":false,"summary":"aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage","aliases":["CVE-2026-22815","PYSEC-2026-2094"],"sourceIds":["GHSA-w2fm-2cpv-w7v5","PYSEC-2026-2094"],"published":"2026-04-01T19:45:17Z","modified":"2026-07-13T07:26:28.950069528Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-w2fm-2cpv-w7v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22815"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-w853-jp5j-5j7f","slug":"ghsa-w853-jp5j-5j7f-2786386f","dossier":false,"summary":"filelock has a TOCTOU race condition which allows symlink attacks during lock file creation","aliases":["CVE-2025-68146","PYSEC-2026-1375"],"sourceIds":["GHSA-w853-jp5j-5j7f","PYSEC-2026-1375"],"published":"2025-12-16T20:52:55Z","modified":"2026-07-07T17:56:10.949145470Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e"},{"type":"PACKAGE","url":"https://github.com/tox-dev/filelock"},{"type":"WEB","url":"https://github.com/tox-dev/filelock/releases/tag/3.20.1"},{"type":"WEB","url":"https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants"},{"type":"WEB","url":"https://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html"},{"type":"PACKAGE","url":"https://pypi.org/project/filelock"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w853-jp5j-5j7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68146"}],"versionKeys":["pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0"],"packageCount":1,"repositoryCount":10},{"id":"GHSA-whj4-6x5x-4v2j","slug":"ghsa-whj4-6x5x-4v2j-eb5fc6a1","dossier":true,"summary":"FITS GZIP decompression bomb in Pillow","aliases":["BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250"],"sourceIds":["GHSA-whj4-6x5x-4v2j","PYSEC-2026-2250"],"published":"2026-04-13T19:22:35Z","modified":"2026-07-13T07:26:24.246094941Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40192"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9521"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40192"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16008"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16009"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17609"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17611"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19375"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21017"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22465"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22629"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22840"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-wjx4-4jcj-g98j","slug":"ghsa-wjx4-4jcj-g98j-e937161b","dossier":true,"summary":"Pillow has an integer overflow when processing fonts","aliases":["BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165"],"sourceIds":["GHSA-wjx4-4jcj-g98j","PYSEC-2026-165"],"published":"2026-05-04T20:18:45Z","modified":"2026-06-08T23:45:16.414580348Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42308"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"GHSA-x3gm-94wq-g975","slug":"ghsa-x3gm-94wq-g975-a197ba31","dossier":false,"summary":"PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module","aliases":["BIT-pytorch-2025-2149","CVE-2025-2149","PYSEC-2025-190"],"sourceIds":["GHSA-x3gm-94wq-g975"],"published":"2025-03-10T15:30:47Z","modified":"2026-06-09T22:11:08.734544854Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2149"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/147818"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/issues/147818#issue-2877301660"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-190.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://vuldb.com/?ctiid.299060"},{"type":"WEB","url":"https://vuldb.com/?id.299060"},{"type":"WEB","url":"https://vuldb.com/?submit.506563"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-xcgm-r5h9-7989","slug":"ghsa-xcgm-r5h9-7989-77bcbc26","dossier":false,"summary":"aiohttp: Incomplete websocket frame payloads bypass memory limits","aliases":["CVE-2026-54274","PYSEC-2026-2108"],"sourceIds":["GHSA-xcgm-r5h9-7989","PYSEC-2026-2108"],"published":"2026-06-15T20:11:22Z","modified":"2026-07-13T07:26:54.330692251Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d"}],"versionKeys":["pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3"],"packageCount":1,"repositoryCount":9},{"id":"GHSA-xg8h-j46f-w952","slug":"ghsa-xg8h-j46f-w952-da36a616","dossier":false,"summary":"Pillow vulnerability can cause write buffer overflow on BCn encoding","aliases":["BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61"],"sourceIds":["GHSA-xg8h-j46f-w952","PYSEC-2025-61"],"published":"2025-07-01T17:29:37Z","modified":"2026-02-04T03:49:31.268130Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48379"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9041"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2025-61.yaml"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/11.3.0"}],"versionKeys":["pypi:pillow@11.2.1"],"packageCount":1,"repositoryCount":4},{"id":"PYSEC-2025-198","slug":"pysec-2025-198-62b25ed4","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46148","CVE-2025-46148"],"sourceIds":["PYSEC-2025-198"],"published":"2025-09-25T15:16:12.007Z","modified":"2026-05-20T09:19:19.437232Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/65a587a579dfdff887b9b35bb79b9093"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151198"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/152993"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":2},{"id":"PYSEC-2025-199","slug":"pysec-2025-199-c528cb5a","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46149","CVE-2025-46149"],"sourceIds":["PYSEC-2025-199"],"published":"2025-09-25T15:16:12.153Z","modified":"2026-05-20T09:19:19.498677Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/147848"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/147961"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-200","slug":"pysec-2025-200-d11172cd","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46150","CVE-2025-46150"],"sourceIds":["PYSEC-2025-200"],"published":"2025-09-25T15:16:12.303Z","modified":"2026-05-20T09:19:19.559970Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/141538"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/141538#issuecomment-2537424658"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/144395"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-201","slug":"pysec-2025-201-c002b022","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46152","CVE-2025-46152"],"sourceIds":["PYSEC-2025-201"],"published":"2025-09-25T15:16:12.470Z","modified":"2026-05-20T09:19:19.618679Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/143555"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/143635"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-202","slug":"pysec-2025-202-f0ff1751","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-46153","CVE-2025-46153"],"sourceIds":["PYSEC-2025-202"],"published":"2025-09-25T15:16:12.603Z","modified":"2026-05-20T09:19:19.678555Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/pytorch/pytorch/compare/v2.6.0...v2.7.0"},{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/4bcefba4004f8271e64b5185c95a248a"},{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/e636f2e7a306105b7e96809e2b85c28a"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/142853"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/143460"}],"versionKeys":["pypi:torch@2.6.0"],"packageCount":1,"repositoryCount":1},{"id":"PYSEC-2025-203","slug":"pysec-2025-203-2febb201","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55551","CVE-2025-55551"],"sourceIds":["PYSEC-2025-203"],"published":"2025-09-25T15:16:12.887Z","modified":"2026-05-20T09:19:19.739357Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151401"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-204","slug":"pysec-2025-204-cdae47da","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55552","CVE-2025-55552"],"sourceIds":["PYSEC-2025-204"],"published":"2025-09-25T16:15:34.320Z","modified":"2026-05-20T09:19:19.802802Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/147847"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-205","slug":"pysec-2025-205-fd5e58fd","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55553","CVE-2025-55553"],"sourceIds":["PYSEC-2025-205"],"published":"2025-09-25T16:15:34.460Z","modified":"2026-05-20T09:19:19.866970Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151432"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/154645"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-206","slug":"pysec-2025-206-58322476","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55554","CVE-2025-55554"],"sourceIds":["PYSEC-2025-206"],"published":"2025-09-25T16:15:34.593Z","modified":"2026-05-20T09:19:19.928295Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151510"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0"],"packageCount":1,"repositoryCount":8},{"id":"PYSEC-2025-207","slug":"pysec-2025-207-2abef3fc","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55557","CVE-2025-55557"],"sourceIds":["PYSEC-2025-207"],"published":"2025-09-25T16:15:34.833Z","modified":"2026-05-20T09:19:19.989717Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151738"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/151931"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-208","slug":"pysec-2025-208-6e93fe9d","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55558","CVE-2025-55558"],"sourceIds":["PYSEC-2025-208"],"published":"2025-09-25T16:15:34.960Z","modified":"2026-05-20T09:19:20.054109Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151523"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/151887"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2025-209","slug":"pysec-2025-209-e6f352b0","dossier":false,"summary":null,"aliases":["BIT-pytorch-2025-55560","CVE-2025-55560"],"sourceIds":["PYSEC-2025-209"],"published":"2025-09-25T16:15:35.197Z","modified":"2026-05-20T09:19:20.117285Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/151522"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/151897"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-139","slug":"pysec-2026-139-96951ff6","dossier":false,"summary":null,"aliases":["BIT-pytorch-2026-4538","CVE-2026-4538"],"sourceIds":["PYSEC-2026-139"],"published":"2026-03-22T05:16:20.273Z","modified":"2026-05-21T15:00:31.962442644Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/pytorch/pytorch/"},{"type":"ADVISORY","url":"https://vuldb.com/?id.352326"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.774681"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.352326"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/pull/176791"}],"versionKeys":["pypi:torch@2.10.0","pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":10},{"id":"PYSEC-2026-2253","slug":"pysec-2026-2253-e1ccf3df","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-54059","CVE-2026-54059","GHSA-8v84-f9pq-wr9x"],"sourceIds":["PYSEC-2026-2253"],"published":"2026-07-06T19:17:08.127Z","modified":"2026-07-13T07:26:49.281845979Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2254","slug":"pysec-2026-2254-a1ed1fd2","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-54060","CVE-2026-54060","GHSA-5x94-69rx-g8h2"],"sourceIds":["PYSEC-2026-2254"],"published":"2026-07-06T19:17:08.270Z","modified":"2026-07-13T07:26:56.196935469Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2255","slug":"pysec-2026-2255-d0951b98","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55379","CVE-2026-55379","GHSA-45hq-cxwh-f6vc"],"sourceIds":["PYSEC-2026-2255"],"published":"2026-07-06T19:17:08.577Z","modified":"2026-07-13T07:26:26.726353373Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2256","slug":"pysec-2026-2256-0f333f0b","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55380","CVE-2026-55380","GHSA-phj9-mv4w-65pm"],"sourceIds":["PYSEC-2026-2256"],"published":"2026-07-06T19:17:08.703Z","modified":"2026-07-13T07:26:17.085341343Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2257","slug":"pysec-2026-2257-bcbe5d79","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-55798","CVE-2026-55798","GHSA-4x4j-2g7c-83w6"],"sourceIds":["PYSEC-2026-2257"],"published":"2026-07-06T19:17:08.830Z","modified":"2026-07-13T07:26:48.229039344Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8a"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/88194166691b7b603529b8b036ab3ab9cedd2de4"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/b0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-2286","slug":"pysec-2026-2286-8795b007","dossier":false,"summary":null,"aliases":["BIT-pytorch-2026-24747","CVE-2026-24747","GHSA-63cw-57p8-fm3p","PYSEC-2026-1856"],"sourceIds":["PYSEC-2026-2286"],"published":"2026-01-27T22:15:56.470Z","modified":"2026-07-13T07:26:23.701611780Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-24747"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24747.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://github.com/pytorch/pytorch/releases/tag/v2.10.0"},{"type":"ADVISORY","url":"https://github.com/pytorch/pytorch/security/advisories/GHSA-63cw-57p8-fm3p"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433612"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/163105"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/163122/commit/954dc5183ee9205cbe79876ad05dd2d9ae752139"}],"versionKeys":["pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0","pypi:torch@2.7.1","pypi:torch@2.7.1+cpu","pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu"],"packageCount":1,"repositoryCount":9},{"id":"PYSEC-2026-3447","slug":"pysec-2026-3447-df031425","dossier":true,"summary":null,"aliases":["BIT-setuptools-2026-59890","CVE-2026-59890","GHSA-h35f-9h28-mq5c"],"sourceIds":["PYSEC-2026-3447"],"published":"2026-07-08T17:17:27.020Z","modified":"2026-07-14T10:56:37.948360943Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/pypa/setuptools/releases/tag/v83.0.0"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f"},{"type":"EVIDENCE","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"}],"versionKeys":["pypi:setuptools@69.2.0","pypi:setuptools@75.8.0","pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@82.0.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3451","slug":"pysec-2026-3451-3e5eac34","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-59199","CVE-2026-59199","GHSA-6r8x-57c9-28j4"],"sourceIds":["PYSEC-2026-3451"],"published":"2026-07-14T16:17:01.937Z","modified":"2026-07-15T20:11:36.266805254Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9703"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13},{"id":"PYSEC-2026-3452","slug":"pysec-2026-3452-0999fd2a","dossier":false,"summary":null,"aliases":["BIT-pillow-2026-59203","CVE-2026-59203","GHSA-pg7v-jwj7-p798"],"sourceIds":["PYSEC-2026-3452"],"published":"2026-07-14T16:17:02.063Z","modified":"2026-07-15T20:11:27.953713427Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9708"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798"}],"versionKeys":["pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":4},{"id":"PYSEC-2026-3453","slug":"pysec-2026-3453-83974725","dossier":true,"summary":null,"aliases":["BIT-pillow-2026-59205","CVE-2026-59205","GHSA-9hw9-ch79-4vh6"],"sourceIds":["PYSEC-2026-3453"],"published":"2026-07-14T16:17:02.370Z","modified":"2026-07-15T20:11:15.582336837Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9715"},{"type":"EVIDENCE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6"}],"versionKeys":["pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1"],"packageCount":1,"repositoryCount":13}]}}
