vernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-sovia-appThis dossier retains 75 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:b74bb096d47b3a37759845db494e848a6612ed5aae81025097905744d143687bpypi:torch2.9.023 OSV records returnedpypi:opencv-python4.12.0.88pypi:gitpython3.1.4527 OSV records returnedpypi:pillow12.0.020 OSV records returnedpypi:tornado6.5.213 OSV records returnedpypi:urllib32.5.07 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:requests2.32.53 OSV records returnedpypi:setuptools80.9.03 OSV records returnedpypi:filelock3.20.02 OSV records returnedpypi:protobuf6.33.02 OSV records returnedpypi:streamlit1.51.02 OSV records returnedpypi:certifi2025.10.51 OSV record returnedpypi:click8.3.01 OSV record returnedpypi:duckdb1.4.11 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.111 OSV record returnedpypi:pyarrow21.0.01 OSV record returnedpypi:altair5.5.0pypi:anyio4.11.0pypi:attrs25.4.0pypi:blinker1.9.0pypi:branca0.8.2pypi:cachetools6.2.1pypi:charset-normalizer3.4.4pypi:colorama0.4.6pypi:filepath0.1pypi:folium0.20.0pypi:fsspec2025.10.0pypi:gitdb4.0.12pypi:httpcore1.0.9pypi:httpx0.28.1pypi:jsonschema4.25.1pypi:jsonschema-specifications2025.9.1pypi:markupsafe3.0.3pypi:mpmath1.3.0pypi:narwhals2.11.0pypi:networkx3.5pypi:numpy2.2.6pypi:nvidia-cublas-cu1212.8.4.1pypi:nvidia-cuda-cupti-cu1212.8.90pypi:nvidia-cuda-nvrtc-cu1212.8.93pypi:nvidia-cuda-runtime-cu1212.8.90pypi:nvidia-cudnn-cu129.10.2.21pypi:nvidia-cufft-cu1211.3.3.83pypi:nvidia-cufile-cu121.13.1.3pypi:nvidia-curand-cu1210.3.9.90pypi:nvidia-cusolver-cu1211.7.3.90pypi:nvidia-cusparse-cu1212.5.8.93pypi:nvidia-cusparselt-cu120.7.1pypi:nvidia-nccl-cu122.27.5pypi:nvidia-nvjitlink-cu1212.8.93pypi:nvidia-nvshmem-cu123.3.20pypi:nvidia-nvtx-cu1212.8.90pypi:packaging25.0pypi:pandas2.3.3pypi:pydeck0.9.1pypi:python-dateutil2.9.0.post0pypi:pytz2025.2pypi:referencing0.37.0pypi:rpds-py0.28.0pypi:shapely2.1.2pypi:six1.17.0pypi:smmap5.0.2pypi:sniffio1.3.1pypi:streamlit-folium0.25.3pypi:sympy1.14.0pypi:tenacity9.1.2pypi:toml0.10.2pypi:torchvision0.24.0pypi:triton3.5.0pypi:typing-extensions4.15.0pypi:tzdata2025.2pypi:watchdog6.0.0pypi:xyzservices2025.10.0Certifi removes GLOBALTRUST root certificate
10 Sept 2026GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
08 Sept 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
10 Sept 2026PyTorch susceptible to local Denial of Service
10 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
10 Sept 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
10 Sept 2026GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
10 Sept 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10 Sept 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
10 Sept 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10 Sept 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
10 Sept 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07 Aug 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10 Sept 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10 Sept 2026Pillow has a heap buffer overflow with nested list coordinates
10 Sept 2026GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
08 Sept 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10 Sept 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10 Sept 2026GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
10 Sept 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
10 Sept 2026GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
10 Sept 2026GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
08 Sept 2026Tornado has incomplete validation of cookie attributes
10 Sept 2026Tornado vulnerable to excessive logging caused by malformed multipart form data
10 Sept 2026protobuf affected by a JSON recursion depth bypass
10 Sept 2026Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
13 Jul 2026tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
16 Sept 2026PyTorch Improper Resource Shutdown or Release vulnerability
10 Sept 2026GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
08 Sept 2026protobuf-python has a potential Denial of Service issue
10 Sept 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
10 Sept 2026GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
10 Sept 2026GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
10 Sept 2026Requests vulnerable to .netrc credentials leak via malicious URLs
10 Sept 2026Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
10 Sept 2026GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
10 Sept 2026Requests `Session` object does not verify requests after making first request with verify=False
10 Sept 2026PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
09 Jun 2026Tornado: Quadratic DoS via Repeated Header Coalescing
20 Jul 2026Pillow affected by out-of-bounds write when loading PSD images
10 Sept 2026Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
10 Sept 2026Tornado has out-of-bounds memory access via C extension
10 Sept 2026setuptools vulnerable to Command Injection via package URL
10 Sept 2026PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
10 Jun 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): URBAN.KI Sovia-app — exact AI dependency evidence dossier, data state 16 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-11432/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.