sh/diwish/splitbot/kosmo/llm-serviceThis dossier retains 303 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:72d385efaa1c9d7ef74ecd2177161e9b80f5ec89cc764f9cf3892c4a65408df2pypi:langchain-core1.4.97 OSV records returnedpypi:langchain-community0.4.24 OSV records returnedpypi:langchain1.3.133 OSV records returnedpypi:langchain-text-splitters1.1.22 OSV records returnedpypi:langgraph1.2.92 OSV records returnedpypi:langchain-openai1.1.91 OSV record returnedpypi:anthropic0.116.0pypi:openai1.109.1pypi:tokenizers0.23.1pypi:langchain-google-community5.0.0pypi:langchain-mcp-adapters0.3.0pypi:langchain-mistralai0.2.12pypi:langchain-protocol0.0.18pypi:langchain-weaviate0.0.8pypi:opencv-python5.0.0.93pypi:tiktoken0.13.0pypi:weaviate-client4.22.0pypi:nltk3.10.047 OSV records returnedpypi:pypdf6.14.241 OSV records returnedpypi:aiohttp3.14.133 OSV records returnedpypi:pillow12.3.020 OSV records returnedpypi:mistune3.3.316 OSV records returnedpypi:tornado6.5.713 OSV records returnedpypi:jupyterlab4.6.110 OSV records returnedpypi:authlib1.7.29 OSV records returnedpypi:cryptography49.0.09 OSV records returnedpypi:python-multipart0.0.328 OSV records returnedpypi:starlette1.3.18 OSV records returnedpypi:jupyter-server2.20.07 OSV records returnedpypi:pyjwt2.13.07 OSV records returnedpypi:urllib32.7.07 OSV records returnedpypi:pyasn10.6.45 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:langsmith0.10.23 OSV records returnedpypi:mcp1.28.13 OSV records returnedpypi:nbconvert7.17.13 OSV records returnedpypi:notebook7.6.03 OSV records returnedpypi:requests2.34.23 OSV records returnedpypi:setuptools72.2.03 OSV records returnedpypi:bleach6.4.02 OSV records returnedpypi:filelock3.29.72 OSV records returnedpypi:pdfminer-six202601072 OSV records returnedpypi:protobuf5.29.62 OSV records returnedpypi:soupsieve2.8.42 OSV records returnedpypi:unstructured0.17.22 OSV records returnedpypi:certifi2026.6.171 OSV record returnedpypi:click8.4.21 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.181 OSV record returnedpypi:jupyter-core5.9.11 OSV record returnedpypi:langchain-classic1.0.81 OSV record returnedpypi:langgraph-checkpoint4.1.11 OSV record returnedpypi:langgraph-sdk0.4.21 OSV record returnedpypi:lxml6.1.11 OSV record returnedpypi:marshmallow3.26.21 OSV record returnedpypi:orjson3.11.91 OSV record returnedpypi:pydantic-settings2.14.21 OSV record returnedpypi:pygments2.20.01 OSV record returnedpypi:pytest9.1.11 OSV record returnedpypi:python-dotenv1.2.21 OSV record returnedpypi:tqdm4.68.41 OSV record returnedpypi:aiofiles25.1.0pypi:aiohappyeyeballs2.7.1pypi:aiosignal1.4.0pypi:amqp5.3.1pypi:annotated-doc0.0.4pypi:annotated-types0.7.0pypi:anyio4.14.2pypi:appnope0.1.4pypi:argon2-cffi25.1.0pypi:argon2-cffi-bindings25.1.0pypi:arrow1.4.0pypi:asttokens3.0.2pypi:async-lru2.3.0pypi:async-timeout5.0.1pypi:attrs26.1.0pypi:babel2.18.0pypi:backoff2.2.1pypi:beautifulsoup44.15.0pypi:billiard4.2.4pypi:cached-property2.0.1pypi:celery5.6.3pypi:cffi2.1.0pypi:chardet7.4.3pypi:charset-normalizer3.4.9pypi:click-didyoumean0.3.1pypi:click-plugins1.1.1.2pypi:click-repl0.3.0pypi:colorama0.4.6pypi:comm0.2.3pypi:dataclasses-json0.6.7pypi:debugpy1.8.21pypi:decorator5.3.1pypi:defusedxml0.7.1pypi:deprecated1.3.1pypi:distro1.9.0pypi:dnspython2.8.0pypi:docstring-parser0.18.0pypi:docx2txt0.8pypi:emoji2.15.0pypi:eventlet0.41.0pypi:exchangelib5.6.0pypi:executing2.2.1pypi:fastapi0.139.0pypi:fastjsonschema2.21.2pypi:filetype1.2.0pypi:flatbuffers25.12.19pypi:fqdn1.5.1pypi:frozenlist1.8.0pypi:fsspec2026.6.0pypi:google-api-core2.31.0pypi:google-api-python-client2.198.0pypi:google-auth2.55.2pypi:google-auth-httplib20.4.0pypi:google-auth-oauthlib1.4.0pypi:google-cloud-core2.6.0pypi:google-cloud-modelarmor0.7.0pypi:googleapis-common-protos1.75.0pypi:greenlet3.5.3pypi:grpcio1.78.0This page displays 120 of 303 ordered rows. The machine-readable dossier retains the complete exact projection.
pypdf: Possible long runtimes/large memory usage when retrieving outlines
10 Sept 2026pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
10 Sept 2026Certifi removes GLOBALTRUST root certificate
10 Sept 2026Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
10 Sept 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10 Sept 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
10 Sept 2026LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
10 Sept 2026Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
20 Jul 2026pypdf has possible Infinite Loop when processing outlines/bookmarks
10 Sept 2026pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
13 Jul 2026AIOHTTP has CRLF injection through multipart part content type header construction
10 Sept 2026Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
10 Sept 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
10 Sept 2026LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
10 Sept 2026JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
10 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
10 Sept 2026NLTK: Corpus Reader Sandbox Bypass
08 Sept 2026NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
02 Sept 2026NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
08 Sept 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
10 Sept 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10 Sept 2026Marshmallow has DoS in Schema.load(many)
10 Sept 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10 Sept 2026Langchain SQL Injection vulnerability
07 Jul 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
10 Sept 2026pypdf has possible long runtimes for malformed startxref
07 Jul 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
10 Sept 2026Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
20 Jul 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
10 Sept 2026unstructured: Server-Side Request Forgery in the URL-based partitioning
10 Sept 2026pypdf: Possible long runtimes for wrong size values in incremental mode
10 Sept 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10 Sept 2026pypdf has possible long runtimes for missing /Root object with large /Size values
07 Jul 2026pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
10 Sept 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10 Sept 2026pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
10 Sept 2026pypdf: Possible long runtimes for repeated malformed cross-reference entries
10 Sept 2026NLTK: Stable FrameNet and NKJP readers parse outside-root XML
08 Sept 2026Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
10 Sept 2026Mistune has XSS via unescaped figclass/figwidth in Figure directive
10 Sept 2026Denial of service (DoS) via deformation `multipart/form-data` boundary
10 Sept 2026langchain-core allows unauthorized users to read arbitrary files from the host file system
07 Jul 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): LLM Service — exact AI dependency evidence dossier, data state 14 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-12239/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.