vernetzte-stadt-gelsenkirchen/urban.ki/urban-ki-airguardaiDieses Dossier bewahrt 102 exakte Komponentenvorkommen aus 1 veröffentlichten Evidenzdateien an einem unveränderlichen Repository-Commit.
Veröffentlichte Abhängigkeitsevidenz belegt weder Betrieb noch produktive Nutzung, Beschaffung oder Erreichbarkeit zur Laufzeit.
Projekt-ID + Commit-SHA + exakter EvidenzpfadJede Datei bleibt mit dem beobachteten Commit verknüpft. Ein Parserfehler bleibt sichtbar und wird nie zu einer Null.
sha256:59cb0231b92ede8e7f9c5ef5b78867b9fa36e7a4e0fc2600956a5c532b08c9e0pypi:transformers5.8.026 zurückgegebene OSV-Meldungenpypi:torch2.11.023 zurückgegebene OSV-Meldungenpypi:datasets4.8.51 zurückgegebene OSV-Meldungpypi:accelerate1.13.01 zurückgegebene OSV-Meldungpypi:scikit-learn1.8.01 zurückgegebene OSV-Meldungpypi:tokenizers0.22.2pypi:lightgbm4.6.0pypi:aiohttp3.13.533 zurückgegebene OSV-Meldungenpypi:pillow12.2.020 zurückgegebene OSV-Meldungenpypi:python-multipart0.0.288 zurückgegebene OSV-Meldungenpypi:starlette1.0.08 zurückgegebene OSV-Meldungenpypi:urllib32.7.07 zurückgegebene OSV-Meldungenpypi:jinja23.1.64 zurückgegebene OSV-Meldungenpypi:requests2.34.03 zurückgegebene OSV-Meldungenpypi:setuptools81.0.03 zurückgegebene OSV-Meldungenpypi:filelock3.29.02 zurückgegebene OSV-Meldungenpypi:certifi2026.4.221 zurückgegebene OSV-Meldungpypi:click8.3.31 zurückgegebene OSV-Meldungpypi:fonttools4.62.11 zurückgegebene OSV-Meldungpypi:h110.16.01 zurückgegebene OSV-Meldungpypi:idna3.141 zurückgegebene OSV-Meldungpypi:orjson3.11.91 zurückgegebene OSV-Meldungpypi:pyarrow24.0.01 zurückgegebene OSV-Meldungpypi:pygments2.20.01 zurückgegebene OSV-Meldungpypi:python-dotenv1.2.21 zurückgegebene OSV-Meldungpypi:tqdm4.67.31 zurückgegebene OSV-Meldungpypi:aiohappyeyeballs2.6.1pypi:aiosignal1.4.0pypi:annotated-doc0.0.4pypi:anyio4.13.0pypi:attrs26.1.0pypi:charset-normalizer3.4.7pypi:colorama0.4.6pypi:contourpy1.3.3pypi:cuda-bindings13.2.0pypi:cuda-pathfinder1.5.4pypi:cuda-toolkit13.0.2pypi:cycler0.12.1pypi:dill0.4.1pypi:frozenlist1.8.0pypi:fsspec2026.2.0pypi:gradio-client2.5.0pypi:hf-xet1.5.0pypi:httpcore1.0.9pypi:httptools0.7.1pypi:httpx0.28.1pypi:huggingface-hub1.14.0pypi:joblib1.5.3pypi:kiwisolver1.5.0pypi:markdown-it-py4.2.0pypi:markupsafe3.0.3pypi:matplotlib3.10.9pypi:mdurl0.1.2pypi:mpmath1.3.0pypi:multidict6.7.1pypi:multiprocess0.70.19pypi:networkx3.6.1pypi:numpy2.4.4pypi:nvidia-cublas13.1.0.3pypi:nvidia-cuda-cupti13.0.85pypi:nvidia-cuda-nvrtc13.0.88pypi:nvidia-cuda-runtime13.0.96pypi:nvidia-cudnn-cu139.19.0.56pypi:nvidia-cufft12.0.0.61pypi:nvidia-cufile1.15.1.6pypi:nvidia-curand10.4.0.35pypi:nvidia-cusolver12.0.4.66pypi:nvidia-cusparse12.6.3.3pypi:nvidia-cusparselt-cu130.8.0pypi:nvidia-nccl-cu132.28.9pypi:nvidia-nvjitlink13.0.88pypi:nvidia-nvshmem-cu133.4.5pypi:nvidia-nvtx13.0.85pypi:packaging26.2pypi:pandas3.0.3pypi:polars1.40.1pypi:polars-runtime-321.40.1pypi:propcache0.5.2pypi:psutil7.2.2pypi:pyparsing3.3.2pypi:pyproj3.7.2pypi:python-dateutil2.9.0.post0pypi:pyyaml6.0.3pypi:regex2026.5.9pypi:rich15.0.0pypi:safetensors0.7.0pypi:scipy1.17.1pypi:shellingham1.5.4pypi:six1.17.0pypi:sympy1.14.0pypi:threadpoolctl3.6.0pypi:trackio0.25.1pypi:triton3.6.0pypi:typer0.25.1pypi:typing-extensions4.15.0pypi:tzdata2026.2pypi:uvicorn0.46.0pypi:uvloop0.22.1pypi:watchfiles1.1.1pypi:websockets16.0pypi:xxhash3.7.0pypi:yarl1.23.0Certifi removes GLOBALTRUST root certificate
10. Sept. 2026HuggingFace transformers vulnerable to remote code execution
10. Sept. 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10. Sept. 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
10. Sept. 2026AIOHTTP has CRLF injection through multipart part content type header construction
10. Sept. 2026urllib3 streaming API improperly handles highly compressed data
10. Sept. 2026PyTorch susceptible to local Denial of Service
10. Sept. 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
10. Sept. 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10. Sept. 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
10. Sept. 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10. Sept. 2026urllib3 does not control redirects in browsers and Node.js
10. Sept. 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
10. Sept. 2026Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
10. Sept. 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
10. Sept. 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
10. Sept. 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10. Sept. 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10. Sept. 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07. Aug. 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
10. Sept. 2026Denial of service (DoS) via deformation `multipart/form-data` boundary
10. Sept. 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
10. Sept. 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10. Sept. 2026python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
10. Sept. 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10. Sept. 2026Pillow has a heap buffer overflow with nested list coordinates
10. Sept. 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10. Sept. 2026AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
10. Sept. 2026aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
10. Sept. 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10. Sept. 2026AIOHTTP's unicode processing of header values could cause parsing discrepancies
10. Sept. 2026HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
10. Sept. 2026AIOHTTP vulnerable to denial of service through large payloads
10. Sept. 2026python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
10. Sept. 2026AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
10. Sept. 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
10. Sept. 2026Transformers Regular Expression Denial of Service (ReDoS) vulnerability
13. Aug. 2026fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
10. Sept. 2026Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
10. Sept. 2026Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
10. Sept. 2026Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
10. Sept. 2026PyTorch Improper Resource Shutdown or Release vulnerability
10. Sept. 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
10. Sept. 2026Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
10. Sept. 2026AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
10. Sept. 2026AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
10. Sept. 2026Requests vulnerable to .netrc credentials leak via malicious URLs
10. Sept. 2026Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
10. Sept. 2026Der Collector liest begrenzte Lockfiles, SBOMs und exakte Doppelgleich-Pins an einem unveränderlichen Commit. Versionsbereiche werden nie durch Annahmen aufgelöst.
Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.i6eal (2026): URBAN.KI AirGuardAI – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 16. Sept. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/repository/opencode-11301/
Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.
Diese Tools ergänzen die aktuelle Auswertung.