sh/diwish/splitbot/kosmo/llm-serviceThis dossier retains 303 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:72d385efaa1c9d7ef74ecd2177161e9b80f5ec89cc764f9cf3892c4a65408df2pypi:langchain-core1.4.97 OSV records returnedpypi:langchain-community0.4.24 OSV records returnedpypi:langchain1.3.133 OSV records returnedpypi:langgraph1.2.92 OSV records returnedpypi:langchain-openai1.1.91 OSV record returnedpypi:langchain-text-splitters1.1.21 OSV record returnedpypi:anthropic0.116.0pypi:openai1.109.1pypi:tokenizers0.23.1pypi:langchain-google-community5.0.0pypi:langchain-mcp-adapters0.3.0pypi:langchain-mistralai0.2.12pypi:langchain-protocol0.0.18pypi:langchain-weaviate0.0.8pypi:opencv-python5.0.0.93pypi:tiktoken0.13.0pypi:weaviate-client4.22.0pypi:pypdf6.14.235 OSV records returnedpypi:aiohttp3.14.130 OSV records returnedpypi:pillow12.3.020 OSV records returnedpypi:mistune3.3.316 OSV records returnedpypi:nltk3.10.015 OSV records returnedpypi:jupyterlab4.6.110 OSV records returnedpypi:tornado6.5.710 OSV records returnedpypi:authlib1.7.29 OSV records returnedpypi:python-multipart0.0.328 OSV records returnedpypi:starlette1.3.18 OSV records returnedpypi:jupyter-server2.20.07 OSV records returnedpypi:pyjwt2.13.07 OSV records returnedpypi:urllib32.7.07 OSV records returnedpypi:cryptography49.0.06 OSV records returnedpypi:pyasn10.6.45 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:langsmith0.10.23 OSV records returnedpypi:mcp1.28.13 OSV records returnedpypi:nbconvert7.17.13 OSV records returnedpypi:notebook7.6.03 OSV records returnedpypi:requests2.34.23 OSV records returnedpypi:setuptools72.2.03 OSV records returnedpypi:bleach6.4.02 OSV records returnedpypi:filelock3.29.72 OSV records returnedpypi:pdfminer-six202601072 OSV records returnedpypi:protobuf5.29.62 OSV records returnedpypi:soupsieve2.8.42 OSV records returnedpypi:certifi2026.6.171 OSV record returnedpypi:click8.4.21 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.181 OSV record returnedpypi:jupyter-core5.9.11 OSV record returnedpypi:langchain-classic1.0.81 OSV record returnedpypi:langgraph-checkpoint4.1.11 OSV record returnedpypi:langgraph-sdk0.4.21 OSV record returnedpypi:lxml6.1.11 OSV record returnedpypi:marshmallow3.26.21 OSV record returnedpypi:orjson3.11.91 OSV record returnedpypi:pydantic-settings2.14.21 OSV record returnedpypi:pygments2.20.01 OSV record returnedpypi:pytest9.1.11 OSV record returnedpypi:python-dotenv1.2.21 OSV record returnedpypi:tqdm4.68.41 OSV record returnedpypi:unstructured0.17.21 OSV record returnedpypi:aiofiles25.1.0pypi:aiohappyeyeballs2.7.1pypi:aiosignal1.4.0pypi:amqp5.3.1pypi:annotated-doc0.0.4pypi:annotated-types0.7.0pypi:anyio4.14.2pypi:appnope0.1.4pypi:argon2-cffi25.1.0pypi:argon2-cffi-bindings25.1.0pypi:arrow1.4.0pypi:asttokens3.0.2pypi:async-lru2.3.0pypi:async-timeout5.0.1pypi:attrs26.1.0pypi:babel2.18.0pypi:backoff2.2.1pypi:beautifulsoup44.15.0pypi:billiard4.2.4pypi:cached-property2.0.1pypi:celery5.6.3pypi:cffi2.1.0pypi:chardet7.4.3pypi:charset-normalizer3.4.9pypi:click-didyoumean0.3.1pypi:click-plugins1.1.1.2pypi:click-repl0.3.0pypi:colorama0.4.6pypi:comm0.2.3pypi:dataclasses-json0.6.7pypi:debugpy1.8.21pypi:decorator5.3.1pypi:defusedxml0.7.1pypi:deprecated1.3.1pypi:distro1.9.0pypi:dnspython2.8.0pypi:docstring-parser0.18.0pypi:docx2txt0.8pypi:emoji2.15.0pypi:eventlet0.41.0pypi:exchangelib5.6.0pypi:executing2.2.1pypi:fastapi0.139.0pypi:fastjsonschema2.21.2pypi:filetype1.2.0pypi:flatbuffers25.12.19pypi:fqdn1.5.1pypi:frozenlist1.8.0pypi:fsspec2026.6.0pypi:google-api-core2.31.0pypi:google-api-python-client2.198.0pypi:google-auth2.55.2pypi:google-auth-httplib20.4.0pypi:google-auth-oauthlib1.4.0pypi:google-cloud-core2.6.0pypi:google-cloud-modelarmor0.7.0pypi:googleapis-common-protos1.75.0pypi:greenlet3.5.3pypi:grpcio1.78.0This page displays 120 of 303 ordered rows. The machine-readable dossier retains the complete exact projection.
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
13 Jul 2026Certifi removes GLOBALTRUST root certificate
10 Jun 2026Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)
13 Jul 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
07 Jul 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
13 Jul 2026LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
13 Jul 2026Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
20 Jul 2026pypdf has possible Infinite Loop when processing outlines/bookmarks
07 Jul 2026pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
13 Jul 2026AIOHTTP has CRLF injection through multipart part content type header construction
13 Jul 2026Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
13 Jul 2026urllib3 streaming API improperly handles highly compressed data
07 Jul 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
07 Jul 2026LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
13 Jul 2026JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
08 Jun 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul 2026pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
13 Jul 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
13 Jul 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
13 Jul 2026Marshmallow has DoS in Schema.load(many)
07 Jul 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22 Jul 2026Langchain SQL Injection vulnerability
07 Jul 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
13 Jul 2026urllib3 does not control redirects in browsers and Node.js
07 Jul 2026nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
13 Jul 2026pypdf has possible long runtimes for malformed startxref
07 Jul 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
13 Jul 2026Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
20 Jul 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
27 Jun 2026pypdf: Possible long runtimes for wrong size values in incremental mode
13 Jul 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22 Jul 2026pypdf has possible long runtimes for missing /Root object with large /Size values
07 Jul 2026pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
08 Jul 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
13 Jul 2026pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
13 Jul 2026Vulnerable OpenSSL included in cryptography wheels
16 Jun 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
07 Jul 2026pypdf: Possible long runtimes for repeated malformed cross-reference entries
29 Jul 2026Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
06 Jun 2026Mistune has XSS via unescaped figclass/figwidth in Figure directive
09 Jun 2026Denial of service (DoS) via deformation `multipart/form-data` boundary
07 Jul 2026langchain-core allows unauthorized users to read arbitrary files from the host file system
07 Jul 2026pypdf: Inefficient decoding of FlateDecode PNG predictor streams
13 Jul 2026Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
06 Jun 2026pypdf: Possible large memory usage for wrong image dimensions
29 Jul 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
11 May 2026python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
13 Jul 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
22 Jul 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): LLM Service — exact AI dependency evidence dossier, data state 31 Jul 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-12239/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.