[{"data":1,"prerenderedAt":3951},["ShallowReactive",2],{"ki-abhaengigkeitsatlas-repository-opencode-11432":3},{"schemaVersion":4,"dataset":5,"parserVersion":6,"generatedAt":7,"trackingSince":8,"source":9,"coverage":29,"methodology":43,"summary":62,"kind":76,"entity":77,"evidence":220,"related":223},"ki-abhaengigkeitsatlas\u002Fv1","german-public-sector-ai-dependency-atlas","1","2026-09-16T04:45:26.395Z","2026-07-18T21:20:30.334Z",{"codeRadar":10,"openCode":15,"depsDev":18,"osv":21,"spdx":24},{"dataset":11,"generatedAt":12,"parserVersion":13,"url":14},"german-public-sector-ai-code-radar","2026-09-16T04:44:00.147Z","3","https:\u002F\u002Fi6eal.de\u002Ftools\u002Fki-code-radar\u002F",{"label":16,"url":17},"openCode GitLab","https:\u002F\u002Fgitlab.opencode.de\u002F",{"label":19,"url":20},"deps.dev API v3","https:\u002F\u002Fdocs.deps.dev\u002Fapi\u002Fv3\u002F",{"label":22,"url":23},"OSV API","https:\u002F\u002Fgoogle.github.io\u002Fosv.dev\u002Fapi\u002F",{"label":25,"url":26,"version":27,"releaseDate":28},"SPDX License List","https:\u002F\u002Fspdx.org\u002Flicenses\u002F","3.28.0","2026-02-20T00:00:00Z",{"repositoryCount":30,"completeTreeCount":31,"incompleteTreeCount":32,"lockfileRepositoryCount":33,"sbomRepositoryCount":34,"artifactRepositoryCount":35,"resolvedRepositoryCount":36,"resolvedArtifactRepositoryCount":35,"dependencyFileCount":37,"parsedFileCount":38,"parseErrorCount":32,"unsupportedFileCount":39,"evaluatedVersionCount":40,"metadataResolvedCount":41,"metadataNotFoundCount":42,"osvEvaluatedVersionCount":40,"codeRadarRepositoryCount":30},43,42,1,23,4,26,40,37,36,0,4116,4105,11,{"componentParserSchemaVersion":44,"candidateBoundary":45,"resolvedVersionBoundary":46,"manifestRangesResolved":47,"latestVersionSubstitution":47,"containerTagsVulnerabilityChecked":47,"osvClaim":48,"depsDevLicenseSemantics":49,"providerSemantics":50,"generativeAiUsed":47,"scoreUsed":47,"treeEntryCeiling":51,"fileByteCeiling":52,"uniqueVersionCeiling":53,"observedFormats":54},"ki-dependency-atlas-components\u002Fv1","repositories_with_exact_ai_code_evidence","exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin",false,"osv_matched_observed_resolved_package_version_at_collection_time","spdx_expressions_as_reported_without_inferred_compatibility","package_interface_presence_not_api_configuration_procurement_or_use",2500,5242880,8000,[55,56,57,58,59,60,61],"package-lock.json \u002F npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins",{"repositoryCount":30,"packageCount":63,"aiPackageCount":64,"resolvedComponentCount":65,"resolvedVersionCount":40,"providerExposureRepositoryCount":66,"licenseExpressionCount":67,"knownLicensePackageCount":68,"unknownLicensePackageCount":69,"advisoryCount":70,"matchedAdvisoryRepositoryCount":37,"topPackage":71},2457,50,7121,9,55,2423,34,795,{"id":72,"slug":73,"label":74,"repositoryCount":33,"repositoryShare":75},"package:pypi:openai","openai-0dd26ac5","OpenAI SDK",0.5348837209302325,"repository",{"id":78,"slug":79,"gitlabProjectId":80,"name":81,"pathWithNamespace":82,"description":83,"webUrl":84,"commitSha":85,"commitUrl":86,"lastActivityAt":87,"headCommittedAt":88,"tree":89,"files":92,"resolvedComponentCount":100,"artifactResolvedComponentCount":100,"exactManifestPinCount":39,"packageCount":100,"ecosystems":101,"aiPackageCount":103,"licenseExpressionCount":104,"unknownLicensePackageCount":32,"advisoryIds":105,"advisoryCount":218,"providers":219},"opencode:11432","opencode-11432",11432,"URBAN.KI Sovia-app","vernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia-app",null,"https:\u002F\u002Fgitlab.opencode.de\u002Fvernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia-app","2351f6930f4d7a1c812f6c7d6e4b71bf88de6041","https:\u002F\u002Fgitlab.opencode.de\u002Fvernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia-app\u002F-\u002Fcommit\u002F2351f6930f4d7a1c812f6c7d6e4b71bf88de6041","2026-09-15T13:12:13.158Z","2026-09-14T08:20:02.000Z",{"complete":90,"entryCount":91,"truncated":47},true,57,[93],{"path":56,"kind":94,"blobSha":95,"sourceUrl":96,"commitSha":85,"contentSha256":97,"byteCount":98,"state":99,"componentCount":100},"uv-lock","23045eafdfb483ec149e375bcdcde05eebbacd50","https:\u002F\u002Fgitlab.opencode.de\u002Fvernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia-app\u002F-\u002Fblob\u002F2351f6930f4d7a1c812f6c7d6e4b71bf88de6041\u002Fuv.lock","b74bb096d47b3a37759845db494e848a6612ed5aae81025097905744d143687b",194138,"parsed",75,[102],"pypi",2,12,[106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217],"GHSA-248v-346w-9cwc","GHSA-284h-m62q-gf8w","GHSA-2f96-g7mh-g2hx","GHSA-2xpw-w6gg-jr37","GHSA-3749-ghw9-m3mg","GHSA-38jv-5279-wg99","GHSA-3f7w-8rr8-f37f","GHSA-3rp5-jjmw-4wv2","GHSA-3wxw-xv34-2frg","GHSA-3x9g-8vmp-wqvf","GHSA-45hq-cxwh-f6vc","GHSA-48p4-8xcf-vxj5","GHSA-4gmw-gg2m-w46p","GHSA-4x4j-2g7c-83w6","GHSA-539m-9xh6-q6rr","GHSA-53q9-r3pm-6pq6","GHSA-5rjg-fvgr-3xxf","GHSA-5x94-69rx-g8h2","GHSA-5xmw-vc9v-4wf2","GHSA-5xxx-qhh7-9287","GHSA-62p4-gmf7-7g93","GHSA-65pc-fj4g-8rjx","GHSA-6p8h-3wgx-97gf","GHSA-6r8x-57c9-28j4","GHSA-7545-fcxq-7j24","GHSA-7833-fr7j-v32q","GHSA-78cv-mqj4-43f7","GHSA-7cx3-6m66-7c5m","GHSA-7gcm-g887-7qv7","GHSA-7p48-42j8-8846","GHSA-8423-8fgw-73vq","GHSA-887c-mr87-cxwp","GHSA-8mcc-hrx5-hvxc","GHSA-8qvm-5x2c-j2w7","GHSA-8v84-f9pq-wr9x","GHSA-94p4-4cq8-9g67","GHSA-956x-8gvw-wg5v","GHSA-9hjg-9r4m-mvj7","GHSA-9hw9-ch79-4vh6","GHSA-9rj7-rf2p-w77r","GHSA-9wx4-h78v-vm56","GHSA-c678-jfcj-6jmf","GHSA-c98p-7wgm-6p64","GHSA-cfh3-3jmp-rvhc","GHSA-cpwx-vrp4-4pq7","GHSA-cx3h-4qpv-8hc9","GHSA-cx63-2mw6-8hw5","GHSA-f4hp-rmr7-r7v8","GHSA-fj7v-r99m-22gq","GHSA-fjr4-x663-mwxc","GHSA-gc5v-m9x4-r6x2","GHSA-gm62-xv2j-4w53","GHSA-gmj6-6f8f-6699","GHSA-h35f-9h28-mq5c","GHSA-h75v-3vvj-5mfj","GHSA-hh9p-6wh2-4mfc","GHSA-hmq2-w58f-27jc","GHSA-jhmp-mqwm-3gq8","GHSA-jjj6-mw9f-p565","GHSA-jm78-9fvv-mhgr","GHSA-mf9v-mfxr-j63j","GHSA-mgf9-4vpg-hj56","GHSA-mpf4-983q-p7j4","GHSA-mv93-w799-cj2w","GHSA-p538-c434-8v24","GHSA-pg7v-jwj7-p798","GHSA-phj9-mv4w-65pm","GHSA-pq67-6m6q-mj2v","GHSA-pr2v-jx2c-wg9f","GHSA-pw6j-qg29-8w7f","GHSA-pwv6-vv43-88gr","GHSA-q2x7-8rv6-6q7h","GHSA-qccp-gfcp-xxvc","GHSA-qfhq-4f3w-5fph","GHSA-qjxf-f2mg-c6mc","GHSA-qmgc-5h2g-mvrw","GHSA-r73j-pqj5-w3x7","GHSA-r9mr-m37c-5fr3","GHSA-rgxp-2hwp-jwgg","GHSA-rpm5-65cw-6hj4","GHSA-rrmf-rvhw-rf47","GHSA-rwj8-pgh3-r573","GHSA-v87r-6q3f-2j67","GHSA-vgrw-7cvw-pwgx","GHSA-vjc4-5qp5-m44j","GHSA-vqfr-h8mv-ghfj","GHSA-vqwp-45wm-r9r5","GHSA-w853-jp5j-5j7f","GHSA-whj4-6x5x-4v2j","GHSA-wjx4-4jcj-g98j","GHSA-wvpp-8hx9-p66j","GHSA-wwv5-g3v4-889x","GHSA-x2qx-6953-8485","GHSA-x3gm-94wq-g975","GHSA-xg8h-j46f-w952","GHSA-xj96-63gp-2gmr","PYSEC-2025-112","PYSEC-2025-198","PYSEC-2025-199","PYSEC-2025-200","PYSEC-2025-201","PYSEC-2025-202","PYSEC-2025-203","PYSEC-2025-204","PYSEC-2025-205","PYSEC-2025-206","PYSEC-2025-207","PYSEC-2025-208","PYSEC-2025-209","PYSEC-2026-139","PYSEC-2026-2132","PYSEC-2026-2286",112,[],{"files":221,"occurrenceCount":100},[222],{"path":56,"kind":94,"blobSha":95,"sourceUrl":96,"commitSha":85,"contentSha256":97,"byteCount":98,"state":99,"componentCount":100},{"packages":224,"vulnerabilities":912},[225,235,245,255,267,277,288,298,308,317,327,336,345,355,364,373,382,391,400,409,418,427,436,445,454,463,472,481,490,499,508,517,526,535,544,553,562,571,580,590,599,608,617,625,634,643,652,661,670,679,688,697,705,714,722,732,741,750,759,768,777,786,795,804,813,823,832,841,850,859,868,877,887,895,904],{"id":226,"slug":227,"identity":228,"label":229,"aiRelevant":90,"provider":83,"advisoryCount":33,"licenseExpressions":230,"versions":232,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":234},"package:pypi:torch","torch-47a5352a","pypi:torch","PyTorch",[231],"BSD-3-Clause",[233],"2.9.0",[56],{"id":236,"slug":237,"identity":238,"label":239,"aiRelevant":90,"provider":83,"advisoryCount":39,"licenseExpressions":240,"versions":242,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":244},"package:pypi:opencv-python","opencv-python-bfa06e24","pypi:opencv-python","OpenCV",[241],"Apache-2.0",[243],"4.12.0.88",[56],{"id":246,"slug":247,"identity":248,"label":249,"aiRelevant":47,"provider":83,"advisoryCount":250,"licenseExpressions":251,"versions":252,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":254},"package:pypi:gitpython","gitpython-dcd13009","pypi:gitpython","gitpython",27,[231],[253],"3.1.45",[56],{"id":256,"slug":257,"identity":258,"label":259,"aiRelevant":47,"provider":83,"advisoryCount":260,"licenseExpressions":261,"versions":264,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":266},"package:pypi:pillow","pillow-834347dd","pypi:pillow","pillow",20,[262,263],"HPND","MIT-CMU",[265],"12.0.0",[56],{"id":268,"slug":269,"identity":270,"label":271,"aiRelevant":47,"provider":83,"advisoryCount":272,"licenseExpressions":273,"versions":274,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":276},"package:pypi:tornado","tornado-ab0f364e","pypi:tornado","tornado",13,[241],[275],"6.5.2",[56],{"id":278,"slug":279,"identity":280,"label":281,"aiRelevant":47,"provider":83,"advisoryCount":282,"licenseExpressions":283,"versions":285,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":287},"package:pypi:urllib3","urllib3-fa68f32c","pypi:urllib3","urllib3",7,[284],"MIT",[286],"2.5.0",[56],{"id":289,"slug":290,"identity":291,"label":292,"aiRelevant":47,"provider":83,"advisoryCount":34,"licenseExpressions":293,"versions":295,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":297},"package:pypi:jinja2","jinja2-f7d34747","pypi:jinja2","jinja2",[231,294],"non-standard",[296],"3.1.6",[56],{"id":299,"slug":300,"identity":301,"label":302,"aiRelevant":47,"provider":83,"advisoryCount":303,"licenseExpressions":304,"versions":305,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":307},"package:pypi:requests","requests-53653f76","pypi:requests","requests",3,[241],[306],"2.32.5",[56],{"id":309,"slug":310,"identity":311,"label":312,"aiRelevant":47,"provider":83,"advisoryCount":303,"licenseExpressions":313,"versions":314,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":316},"package:pypi:setuptools","setuptools-fe37c31a","pypi:setuptools","setuptools",[284],[315],"80.9.0",[56],{"id":318,"slug":319,"identity":320,"label":321,"aiRelevant":47,"provider":83,"advisoryCount":103,"licenseExpressions":322,"versions":324,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":326},"package:pypi:filelock","filelock-b1c63968","pypi:filelock","filelock",[284,323],"Unlicense",[325],"3.20.0",[56],{"id":328,"slug":329,"identity":330,"label":331,"aiRelevant":47,"provider":83,"advisoryCount":103,"licenseExpressions":332,"versions":333,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":335},"package:pypi:protobuf","protobuf-6e30009a","pypi:protobuf","protobuf",[231],[334],"6.33.0",[56],{"id":337,"slug":338,"identity":339,"label":340,"aiRelevant":47,"provider":83,"advisoryCount":103,"licenseExpressions":341,"versions":342,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":344},"package:pypi:streamlit","streamlit-b61aa01e","pypi:streamlit","streamlit",[241],[343],"1.51.0",[56],{"id":346,"slug":347,"identity":348,"label":349,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":350,"versions":352,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":354},"package:pypi:certifi","certifi-d4f0c37e","pypi:certifi","certifi",[351],"MPL-2.0",[353],"2025.10.5",[56],{"id":356,"slug":357,"identity":358,"label":359,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":360,"versions":361,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":363},"package:pypi:click","click-ef97f731","pypi:click","click",[231,294],[362],"8.3.0",[56],{"id":365,"slug":366,"identity":367,"label":368,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":369,"versions":370,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":372},"package:pypi:duckdb","duckdb-8c0332c9","pypi:duckdb","duckdb",[284],[371],"1.4.1",[56],{"id":374,"slug":375,"identity":376,"label":377,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":378,"versions":379,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":381},"package:pypi:h11","h11-48165ab1","pypi:h11","h11",[284],[380],"0.16.0",[56],{"id":383,"slug":384,"identity":385,"label":386,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":387,"versions":388,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":390},"package:pypi:idna","idna-994c9929","pypi:idna","idna",[231,294],[389],"3.11",[56],{"id":392,"slug":393,"identity":394,"label":395,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":396,"versions":397,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":399},"package:pypi:pyarrow","pyarrow-facb8516","pypi:pyarrow","pyarrow",[241,294],[398],"21.0.0",[56],{"id":401,"slug":402,"identity":403,"label":404,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":405,"versions":406,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":408},"package:pypi:altair","altair-01b7f976","pypi:altair","altair",[294],[407],"5.5.0",[56],{"id":410,"slug":411,"identity":412,"label":413,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":414,"versions":415,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":417},"package:pypi:anyio","anyio-399e5280","pypi:anyio","anyio",[284],[416],"4.11.0",[56],{"id":419,"slug":420,"identity":421,"label":422,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":423,"versions":424,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":426},"package:pypi:attrs","attrs-2e7954ac","pypi:attrs","attrs",[284],[425],"25.4.0",[56],{"id":428,"slug":429,"identity":430,"label":431,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":432,"versions":433,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":435},"package:pypi:blinker","blinker-409e1445","pypi:blinker","blinker",[284],[434],"1.9.0",[56],{"id":437,"slug":438,"identity":439,"label":440,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":441,"versions":442,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":444},"package:pypi:branca","branca-e1a3550c","pypi:branca","branca",[284],[443],"0.8.2",[56],{"id":446,"slug":447,"identity":448,"label":449,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":450,"versions":451,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":453},"package:pypi:cachetools","cachetools-84fe6563","pypi:cachetools","cachetools",[284],[452],"6.2.1",[56],{"id":455,"slug":456,"identity":457,"label":458,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":459,"versions":460,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":462},"package:pypi:charset-normalizer","charset-normalizer-74ccb20a","pypi:charset-normalizer","charset-normalizer",[284],[461],"3.4.4",[56],{"id":464,"slug":465,"identity":466,"label":467,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":468,"versions":469,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":471},"package:pypi:colorama","colorama-abaf57c3","pypi:colorama","colorama",[294],[470],"0.4.6",[56],{"id":473,"slug":474,"identity":475,"label":476,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":477,"versions":478,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":480},"package:pypi:filepath","filepath-6e8545d1","pypi:filepath","filepath",[284],[479],"0.1",[56],{"id":482,"slug":483,"identity":484,"label":485,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":486,"versions":487,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":489},"package:pypi:folium","folium-6e89a148","pypi:folium","folium",[284],[488],"0.20.0",[56],{"id":491,"slug":492,"identity":493,"label":494,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":495,"versions":496,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":498},"package:pypi:fsspec","fsspec-b1a7c311","pypi:fsspec","fsspec",[231,294],[497],"2025.10.0",[56],{"id":500,"slug":501,"identity":502,"label":503,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":504,"versions":505,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":507},"package:pypi:gitdb","gitdb-dac4580b","pypi:gitdb","gitdb",[294],[506],"4.0.12",[56],{"id":509,"slug":510,"identity":511,"label":512,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":513,"versions":514,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":516},"package:pypi:httpcore","httpcore-ba6ae671","pypi:httpcore","httpcore",[231],[515],"1.0.9",[56],{"id":518,"slug":519,"identity":520,"label":521,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":522,"versions":523,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":525},"package:pypi:httpx","httpx-a512a166","pypi:httpx","httpx",[231],[524],"0.28.1",[56],{"id":527,"slug":528,"identity":529,"label":530,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":531,"versions":532,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":534},"package:pypi:jsonschema","jsonschema-df23f5cd","pypi:jsonschema","jsonschema",[284],[533],"4.25.1",[56],{"id":536,"slug":537,"identity":538,"label":539,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":540,"versions":541,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":543},"package:pypi:jsonschema-specifications","jsonschema-specifications-5d87863a","pypi:jsonschema-specifications","jsonschema-specifications",[284],[542],"2025.9.1",[56],{"id":545,"slug":546,"identity":547,"label":548,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":549,"versions":550,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":552},"package:pypi:markupsafe","markupsafe-1bdd4c7f","pypi:markupsafe","markupsafe",[231,294],[551],"3.0.3",[56],{"id":554,"slug":555,"identity":556,"label":557,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":558,"versions":559,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":561},"package:pypi:mpmath","mpmath-4ccb7a41","pypi:mpmath","mpmath",[294],[560],"1.3.0",[56],{"id":563,"slug":564,"identity":565,"label":566,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":567,"versions":568,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":570},"package:pypi:narwhals","narwhals-24e2f721","pypi:narwhals","narwhals",[284,294],[569],"2.11.0",[56],{"id":572,"slug":573,"identity":574,"label":575,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":576,"versions":577,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":579},"package:pypi:networkx","networkx-c2336a8d","pypi:networkx","networkx",[231,294],[578],"3.5",[56],{"id":581,"slug":582,"identity":583,"label":584,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":585,"versions":587,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":589},"package:pypi:numpy","numpy-ba79b98d","pypi:numpy","numpy",[586,294],"0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib",[588],"2.2.6",[56],{"id":591,"slug":592,"identity":593,"label":594,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":595,"versions":596,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":598},"package:pypi:nvidia-cublas-cu12","nvidia-cublas-cu12-1d052261","pypi:nvidia-cublas-cu12","nvidia-cublas-cu12",[294],[597],"12.8.4.1",[56],{"id":600,"slug":601,"identity":602,"label":603,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":604,"versions":605,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":607},"package:pypi:nvidia-cuda-cupti-cu12","nvidia-cuda-cupti-cu12-973480f1","pypi:nvidia-cuda-cupti-cu12","nvidia-cuda-cupti-cu12",[294],[606],"12.8.90",[56],{"id":609,"slug":610,"identity":611,"label":612,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":613,"versions":614,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":616},"package:pypi:nvidia-cuda-nvrtc-cu12","nvidia-cuda-nvrtc-cu12-e32b7f38","pypi:nvidia-cuda-nvrtc-cu12","nvidia-cuda-nvrtc-cu12",[294],[615],"12.8.93",[56],{"id":618,"slug":619,"identity":620,"label":621,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":622,"versions":623,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":624},"package:pypi:nvidia-cuda-runtime-cu12","nvidia-cuda-runtime-cu12-2b875d2a","pypi:nvidia-cuda-runtime-cu12","nvidia-cuda-runtime-cu12",[294],[606],[56],{"id":626,"slug":627,"identity":628,"label":629,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":630,"versions":631,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":633},"package:pypi:nvidia-cudnn-cu12","nvidia-cudnn-cu12-a21dce6d","pypi:nvidia-cudnn-cu12","nvidia-cudnn-cu12",[294],[632],"9.10.2.21",[56],{"id":635,"slug":636,"identity":637,"label":638,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":639,"versions":640,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":642},"package:pypi:nvidia-cufft-cu12","nvidia-cufft-cu12-21ff54dd","pypi:nvidia-cufft-cu12","nvidia-cufft-cu12",[294],[641],"11.3.3.83",[56],{"id":644,"slug":645,"identity":646,"label":647,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":648,"versions":649,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":651},"package:pypi:nvidia-cufile-cu12","nvidia-cufile-cu12-14048140","pypi:nvidia-cufile-cu12","nvidia-cufile-cu12",[294],[650],"1.13.1.3",[56],{"id":653,"slug":654,"identity":655,"label":656,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":657,"versions":658,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":660},"package:pypi:nvidia-curand-cu12","nvidia-curand-cu12-2fed778b","pypi:nvidia-curand-cu12","nvidia-curand-cu12",[294],[659],"10.3.9.90",[56],{"id":662,"slug":663,"identity":664,"label":665,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":666,"versions":667,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":669},"package:pypi:nvidia-cusolver-cu12","nvidia-cusolver-cu12-7db0a33a","pypi:nvidia-cusolver-cu12","nvidia-cusolver-cu12",[294],[668],"11.7.3.90",[56],{"id":671,"slug":672,"identity":673,"label":674,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":675,"versions":676,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":678},"package:pypi:nvidia-cusparse-cu12","nvidia-cusparse-cu12-d7e6a309","pypi:nvidia-cusparse-cu12","nvidia-cusparse-cu12",[294],[677],"12.5.8.93",[56],{"id":680,"slug":681,"identity":682,"label":683,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":684,"versions":685,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":687},"package:pypi:nvidia-cusparselt-cu12","nvidia-cusparselt-cu12-97587f50","pypi:nvidia-cusparselt-cu12","nvidia-cusparselt-cu12",[294],[686],"0.7.1",[56],{"id":689,"slug":690,"identity":691,"label":692,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":693,"versions":694,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":696},"package:pypi:nvidia-nccl-cu12","nvidia-nccl-cu12-90361558","pypi:nvidia-nccl-cu12","nvidia-nccl-cu12",[231,294],[695],"2.27.5",[56],{"id":698,"slug":699,"identity":700,"label":701,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":702,"versions":703,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":704},"package:pypi:nvidia-nvjitlink-cu12","nvidia-nvjitlink-cu12-6d08af75","pypi:nvidia-nvjitlink-cu12","nvidia-nvjitlink-cu12",[294],[615],[56],{"id":706,"slug":707,"identity":708,"label":709,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":710,"versions":711,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":713},"package:pypi:nvidia-nvshmem-cu12","nvidia-nvshmem-cu12-d7141303","pypi:nvidia-nvshmem-cu12","nvidia-nvshmem-cu12",[231,294],[712],"3.3.20",[56],{"id":715,"slug":716,"identity":717,"label":718,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":719,"versions":720,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":721},"package:pypi:nvidia-nvtx-cu12","nvidia-nvtx-cu12-9a2d0378","pypi:nvidia-nvtx-cu12","nvidia-nvtx-cu12",[241,294],[606],[56],{"id":723,"slug":724,"identity":725,"label":726,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":727,"versions":729,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":731},"package:pypi:packaging","packaging-78ee1f47","pypi:packaging","packaging",[728,294],"Apache-2.0 OR BSD-2-Clause",[730],"25.0",[56],{"id":733,"slug":734,"identity":735,"label":736,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":737,"versions":738,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":740},"package:pypi:pandas","pandas-e8d52445","pypi:pandas","pandas",[294],[739],"2.3.3",[56],{"id":742,"slug":743,"identity":744,"label":745,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":746,"versions":747,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":749},"package:pypi:pydeck","pydeck-75380c92","pypi:pydeck","pydeck",[241],[748],"0.9.1",[56],{"id":751,"slug":752,"identity":753,"label":754,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":755,"versions":756,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":758},"package:pypi:python-dateutil","python-dateutil-8eac96b7","pypi:python-dateutil","python-dateutil",[294],[757],"2.9.0.post0",[56],{"id":760,"slug":761,"identity":762,"label":763,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":764,"versions":765,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":767},"package:pypi:pytz","pytz-cbf1d95c","pypi:pytz","pytz",[284],[766],"2025.2",[56],{"id":769,"slug":770,"identity":771,"label":772,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":773,"versions":774,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":776},"package:pypi:referencing","referencing-b8d98ce1","pypi:referencing","referencing",[284],[775],"0.37.0",[56],{"id":778,"slug":779,"identity":780,"label":781,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":782,"versions":783,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":785},"package:pypi:rpds-py","rpds-py-67c64be8","pypi:rpds-py","rpds-py",[284],[784],"0.28.0",[56],{"id":787,"slug":788,"identity":789,"label":790,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":791,"versions":792,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":794},"package:pypi:shapely","shapely-1cd2f2ba","pypi:shapely","shapely",[231],[793],"2.1.2",[56],{"id":796,"slug":797,"identity":798,"label":799,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":800,"versions":801,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":803},"package:pypi:six","six-3c3888bd","pypi:six","six",[284],[802],"1.17.0",[56],{"id":805,"slug":806,"identity":807,"label":808,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":809,"versions":810,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":812},"package:pypi:smmap","smmap-943fc5aa","pypi:smmap","smmap",[231],[811],"5.0.2",[56],{"id":814,"slug":815,"identity":816,"label":817,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":818,"versions":820,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":822},"package:pypi:sniffio","sniffio-83f32c9d","pypi:sniffio","sniffio",[819],"Apache-2.0 OR MIT",[821],"1.3.1",[56],{"id":824,"slug":825,"identity":826,"label":827,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":828,"versions":829,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":831},"package:pypi:streamlit-folium","streamlit-folium-e76fb4ea","pypi:streamlit-folium","streamlit-folium",[],[830],"0.25.3",[56],{"id":833,"slug":834,"identity":835,"label":836,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":837,"versions":838,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":840},"package:pypi:sympy","sympy-b30cb89e","pypi:sympy","sympy",[294],[839],"1.14.0",[56],{"id":842,"slug":843,"identity":844,"label":845,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":846,"versions":847,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":849},"package:pypi:tenacity","tenacity-415454f8","pypi:tenacity","tenacity",[241],[848],"9.1.2",[56],{"id":851,"slug":852,"identity":853,"label":854,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":855,"versions":856,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":858},"package:pypi:toml","toml-490ac3c8","pypi:toml","toml",[284],[857],"0.10.2",[56],{"id":860,"slug":861,"identity":862,"label":863,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":864,"versions":865,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":867},"package:pypi:torchvision","torchvision-7f85cafa","pypi:torchvision","torchvision",[294],[866],"0.24.0",[56],{"id":869,"slug":870,"identity":871,"label":872,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":873,"versions":874,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":876},"package:pypi:triton","triton-601ea838","pypi:triton","triton",[284],[875],"3.5.0",[56],{"id":878,"slug":879,"identity":880,"label":881,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":882,"versions":884,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":886},"package:pypi:typing-extensions","typing-extensions-87d153eb","pypi:typing-extensions","typing-extensions",[883,294],"PSF-2.0",[885],"4.15.0",[56],{"id":888,"slug":889,"identity":890,"label":891,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":892,"versions":893,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":894},"package:pypi:tzdata","tzdata-f80b3bb7","pypi:tzdata","tzdata",[241],[766],[56],{"id":896,"slug":897,"identity":898,"label":899,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":900,"versions":901,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":903},"package:pypi:watchdog","watchdog-55ddb444","pypi:watchdog","watchdog",[241],[902],"6.0.0",[56],{"id":905,"slug":906,"identity":907,"label":908,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":909,"versions":910,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":911},"package:pypi:xyzservices","xyzservices-a1955a18","pypi:xyzservices","xyzservices",[231],[497],[56],[913,952,986,1017,1049,1092,1119,1146,1166,1196,1225,1261,1288,1317,1346,1370,1394,1430,1453,1476,1499,1529,1558,1584,1610,1633,1665,1695,1720,1760,1789,1813,1852,1884,1916,1939,1964,1992,2026,2052,2079,2109,2141,2165,2220,2252,2276,2308,2342,2370,2389,2417,2440,2468,2502,2535,2562,2594,2616,2643,2667,2689,2710,2735,2752,2779,2806,2830,2854,2879,2895,2922,2948,2969,3006,3033,3065,3093,3116,3146,3166,3200,3228,3248,3276,3303,3330,3373,3403,3455,3478,3505,3528,3551,3583,3610,3635,3657,3677,3694,3713,3730,3751,3767,3782,3799,3814,3831,3848,3865,3888,3921],{"id":106,"slug":914,"dossier":47,"summary":915,"aliases":916,"sourceIds":919,"published":920,"modified":921,"checkedAt":7,"severity":922,"references":926,"versionKeys":950,"packageCount":32,"repositoryCount":32},"ghsa-248v-346w-9cwc-8a7dbdf1","Certifi removes GLOBALTRUST root certificate",[917,918],"CVE-2024-39689","PYSEC-2024-230",[106,918],"2024-07-05T19:15:10Z","2026-09-10T03:50:15.994602411Z",[923],{"type":924,"score":925},"CVSS_V3","CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[927,930,932,935,938,941,944,946,948],{"type":928,"url":929},"ADVISORY","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi\u002Fsecurity\u002Fadvisories\u002FGHSA-248v-346w-9cwc",{"type":928,"url":931},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39689",{"type":933,"url":934},"FIX","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi\u002Fcommit\u002Fbd8153872e9c6fc98f4023df9c2deaffea2fa463",{"type":936,"url":937},"PACKAGE","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi",{"type":939,"url":940},"WEB","https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fcertifi\u002FPYSEC-2024-230.yaml",{"type":942,"url":943},"ARTICLE","https:\u002F\u002Fgroups.google.com\u002Fa\u002Fmozilla.org\u002Fg\u002Fdev-security-policy\u002Fc\u002FXpknYMPO8dI",{"type":939,"url":945},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20241206-0001",{"type":928,"url":947},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20241206-0001\u002F",{"type":928,"url":949},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-248v-346w-9cwc",[951],"pypi:certifi@2024.6.2",{"id":107,"slug":953,"dossier":47,"summary":954,"aliases":955,"sourceIds":958,"published":959,"modified":960,"checkedAt":7,"severity":961,"references":969,"versionKeys":981,"packageCount":32,"repositoryCount":985},"ghsa-284h-m62q-gf8w-da9acb0c","GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE",[956,957],"CVE-2026-78676","PYSEC-2026-3786",[107,957],"2026-08-25T02:16:52.030Z","2026-09-08T19:00:06.885837775Z",[962,964,967],{"type":924,"score":963},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":965,"score":966},"CVSS_V4","CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":965,"score":968},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[970,973,975,977,979],{"type":971,"url":972},"EVIDENCE","https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-284h-m62q-gf8w",{"type":928,"url":974},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78676",{"type":936,"url":976},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython",{"type":939,"url":978},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3786.yaml",{"type":928,"url":980},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-config-injection",[982,983,984],"pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46",6,{"id":108,"slug":987,"dossier":47,"summary":988,"aliases":989,"sourceIds":992,"published":993,"modified":994,"checkedAt":7,"severity":995,"references":998,"versionKeys":1016,"packageCount":32,"repositoryCount":985},"ghsa-2f96-g7mh-g2hx-dd7ec02d","GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist",[990,991],"CVE-2026-67325","PYSEC-2026-3836",[108,991],"2026-07-21T19:43:43Z","2026-09-10T12:25:28.694037561Z",[996],{"type":924,"score":997},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[999,1001,1003,1005,1007,1008,1010,1012,1014],{"type":939,"url":1000},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-2f96-g7mh-g2hx",{"type":928,"url":1002},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-67325",{"type":939,"url":1004},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2161",{"type":939,"url":1006},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F56806080c1348749b07daa4a2024ce47b3cad285",{"type":936,"url":976},{"type":939,"url":1009},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.51",{"type":939,"url":1011},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-command-injection-via-option-prefix-abbreviation",{"type":936,"url":1013},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fgitpython",{"type":928,"url":1015},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2f96-g7mh-g2hx",[982,983,984],{"id":109,"slug":1018,"dossier":90,"summary":1019,"aliases":1020,"sourceIds":1023,"published":1024,"modified":1025,"checkedAt":7,"severity":1026,"references":1029,"versionKeys":1042,"packageCount":32,"repositoryCount":1048},"ghsa-2xpw-w6gg-jr37-91cead57","urllib3 streaming API improperly handles highly compressed data",[1021,1022],"CVE-2025-66471","PYSEC-2026-1994",[109,1022],"2025-12-05T18:15:54Z","2026-09-10T03:50:31.327173527Z",[1027],{"type":965,"score":1028},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:H",[1030,1032,1034,1036,1038,1040],{"type":939,"url":1031},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-2xpw-w6gg-jr37",{"type":928,"url":1033},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66471",{"type":933,"url":1035},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Fc19571de34c47de3a766541b041637ba5f716ed7",{"type":936,"url":1037},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3",{"type":936,"url":1039},"https:\u002F\u002Fpypi.org\u002Fproject\u002Furllib3",{"type":928,"url":1041},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2xpw-w6gg-jr37",[1043,1044,1045,1046,1047],"pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0",16,{"id":110,"slug":1050,"dossier":47,"summary":1051,"aliases":1052,"sourceIds":1056,"published":1057,"modified":1058,"checkedAt":7,"severity":1059,"references":1066,"versionKeys":1088,"packageCount":32,"repositoryCount":303},"ghsa-3749-ghw9-m3mg-fadf4a32","PyTorch susceptible to local Denial of Service",[1053,1054,1055],"BIT-pytorch-2025-2953","CVE-2025-2953","PYSEC-2025-191",[110,1055],"2025-03-30T16:15:14.380Z","2026-09-10T03:50:22.781448235Z",[1060,1062,1064],{"type":924,"score":1061},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",{"type":965,"score":1063},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":924,"score":1065},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",[1067,1069,1072,1074,1076,1078,1080,1082,1084,1086],{"type":928,"url":1068},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2953",{"type":1070,"url":1071},"REPORT","https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149274",{"type":1070,"url":1073},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149274#issue-2923122269",{"type":939,"url":1075},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-191.yaml",{"type":936,"url":1077},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch",{"type":939,"url":1079},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fblob\u002Fmain\u002FSECURITY.md#untrusted-models",{"type":1070,"url":1081},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302006",{"type":928,"url":1083},"https:\u002F\u002Fvuldb.com\u002F?id.302006",{"type":928,"url":1085},"https:\u002F\u002Fvuldb.com\u002F?submit.521279",{"type":928,"url":1087},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3749-ghw9-m3mg",[1089,1090,1091],"pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0",{"id":111,"slug":1093,"dossier":90,"summary":1094,"aliases":1095,"sourceIds":1098,"published":1099,"modified":1100,"checkedAt":7,"severity":1101,"references":1105,"versionKeys":1118,"packageCount":32,"repositoryCount":1048},"ghsa-38jv-5279-wg99-c9df8f7b","Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)",[1096,1097],"CVE-2026-21441","PYSEC-2026-1996",[111,1097],"2026-01-07T19:18:14Z","2026-09-10T03:50:32.562010895Z",[1102,1104],{"type":924,"score":1103},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",{"type":965,"score":1028},[1106,1108,1110,1112,1113,1115,1116],{"type":939,"url":1107},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-38jv-5279-wg99",{"type":928,"url":1109},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-21441",{"type":933,"url":1111},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F8864ac407bba8607950025e0979c4c69bc7abc7b",{"type":936,"url":1037},{"type":939,"url":1114},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F01\u002Fmsg00017.html",{"type":936,"url":1039},{"type":928,"url":1117},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-38jv-5279-wg99",[1043,1044,1045,1046,1047],{"id":112,"slug":1120,"dossier":47,"summary":1121,"aliases":1122,"sourceIds":1125,"published":1126,"modified":1127,"checkedAt":7,"severity":1128,"references":1133,"versionKeys":1145,"packageCount":32,"repositoryCount":985},"ghsa-3f7w-8rr8-f37f-9cab61a6","GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read",[1123,1124],"CVE-2026-73620","PYSEC-2026-3949",[112,1124],"2026-08-03T20:09:56Z","2026-09-10T13:10:44.075529324Z",[1129,1131],{"type":924,"score":1130},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",{"type":965,"score":1132},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[1134,1136,1138,1140,1141,1143],{"type":971,"url":1135},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3f7w-8rr8-f37f",{"type":939,"url":1137},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2193",{"type":939,"url":1139},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F3af0c2516c5e18c829da30338614688f6b69b49c",{"type":936,"url":976},{"type":939,"url":1142},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.57",{"type":928,"url":1144},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-overwrite-and-read",[982,983,984],{"id":113,"slug":1147,"dossier":47,"summary":1148,"aliases":1149,"sourceIds":1151,"published":1152,"modified":1153,"checkedAt":7,"severity":1154,"references":1157,"versionKeys":1165,"packageCount":32,"repositoryCount":985},"ghsa-3rp5-jjmw-4wv2-6d7352e6","GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)",[1150],"CVE-2026-69097",[113],"2026-07-24T16:22:02Z","2026-09-10T03:51:10.099586625Z",[1155],{"type":924,"score":1156},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[1158,1160,1162,1163],{"type":939,"url":1159},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3rp5-jjmw-4wv2",{"type":939,"url":1161},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1ed1b924f4e2d2ee7bab296df77b978af21853f1",{"type":936,"url":976},{"type":939,"url":1164},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.53",[982,983,984],{"id":114,"slug":1167,"dossier":47,"summary":1168,"aliases":1169,"sourceIds":1172,"published":1173,"modified":1174,"checkedAt":7,"severity":1175,"references":1178,"versionKeys":1195,"packageCount":32,"repositoryCount":985},"ghsa-3wxw-xv34-2frg-c013ae2d","GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)",[1170,1171],"CVE-2026-78679","PYSEC-2026-3837",[114,1171],"2026-09-08T19:42:22Z","2026-09-10T12:25:33.369776672Z",[1176],{"type":924,"score":1177},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[1179,1181,1183,1185,1187,1188,1190,1192,1193],{"type":939,"url":1180},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3wxw-xv34-2frg",{"type":928,"url":1182},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78679",{"type":939,"url":1184},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2208",{"type":939,"url":1186},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6",{"type":936,"url":976},{"type":939,"url":1189},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.59",{"type":939,"url":1191},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-tagreference-create",{"type":936,"url":1013},{"type":928,"url":1194},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3wxw-xv34-2frg",[982,983,984],{"id":115,"slug":1197,"dossier":47,"summary":1198,"aliases":1199,"sourceIds":1202,"published":1203,"modified":1204,"checkedAt":7,"severity":1205,"references":1208,"versionKeys":1219,"packageCount":32,"repositoryCount":66},"ghsa-3x9g-8vmp-wqvf-6d03bf5f","Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient",[1200,1201],"CVE-2026-49853","PYSEC-2026-3387",[115,1201],"2026-06-15T20:20:00Z","2026-09-10T03:50:55.306087854Z",[1206],{"type":924,"score":1207},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[1209,1211,1213,1215,1217],{"type":939,"url":1210},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-3x9g-8vmp-wqvf",{"type":936,"url":1212},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado",{"type":936,"url":1214},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftornado",{"type":928,"url":1216},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3x9g-8vmp-wqvf",{"type":928,"url":1218},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49853",[1220,1221,1222,1223,1224],"pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5",{"id":116,"slug":1226,"dossier":90,"summary":1227,"aliases":1228,"sourceIds":1232,"published":1233,"modified":1234,"checkedAt":7,"severity":1235,"references":1237,"versionKeys":1250,"packageCount":32,"repositoryCount":1260},"ghsa-45hq-cxwh-f6vc-d18d2872","Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading",[1229,1230,1231],"BIT-pillow-2026-55379","CVE-2026-55379","PYSEC-2026-2255",[116,1231],"2026-07-06T19:17:08.577Z","2026-09-10T03:50:51.372929814Z",[1236],{"type":924,"score":1103},[1238,1240,1242,1244,1246,1248],{"type":971,"url":1239},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-45hq-cxwh-f6vc",{"type":928,"url":1241},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55379",{"type":933,"url":1243},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F0a263e6264aa5399988d9acd3bbfbca2ca3ec77d",{"type":939,"url":1245},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2255.yaml",{"type":936,"url":1247},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow",{"type":928,"url":1249},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fblob\u002Fmain\u002Fdocs\u002Freleasenotes\u002F12.3.0.rst",[1251,1252,1253,1254,1255,1256,1257,1258,1259],"pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1","pypi:pillow@12.2.0",17,{"id":117,"slug":1262,"dossier":47,"summary":1263,"aliases":1264,"sourceIds":1267,"published":1268,"modified":1269,"checkedAt":7,"severity":1270,"references":1273,"versionKeys":1286,"packageCount":32,"repositoryCount":1287},"ghsa-48p4-8xcf-vxj5-13f12656","urllib3 does not control redirects in browsers and Node.js",[1265,1266],"CVE-2025-50182","PYSEC-2026-1997",[117,1266],"2025-06-18T17:50:11Z","2026-09-10T03:50:24.821170285Z",[1271],{"type":924,"score":1272},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[1274,1276,1278,1280,1281,1283,1284],{"type":939,"url":1275},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-48p4-8xcf-vxj5",{"type":928,"url":1277},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-50182",{"type":933,"url":1279},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f",{"type":936,"url":1037},{"type":939,"url":1282},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Freleases\u002Ftag\u002F2.5.0",{"type":936,"url":1039},{"type":928,"url":1285},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-48p4-8xcf-vxj5",[1043,1044,1045,1046],8,{"id":118,"slug":1289,"dossier":47,"summary":1290,"aliases":1291,"sourceIds":1294,"published":1295,"modified":1296,"checkedAt":7,"severity":1297,"references":1299,"versionKeys":1316,"packageCount":32,"repositoryCount":985},"ghsa-4gmw-gg2m-w46p-58f27cb8","GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree\u002Freset\u002Fmerge_tree enables arbitrary file overwrite",[1292,1293],"CVE-2026-76219","PYSEC-2026-3838",[118,1293],"2026-08-07T15:33:57Z","2026-09-10T12:25:42.767166279Z",[1298],{"type":924,"score":1130},[1300,1302,1304,1306,1308,1309,1311,1313,1314],{"type":939,"url":1301},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-4gmw-gg2m-w46p",{"type":928,"url":1303},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76219",{"type":939,"url":1305},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2204",{"type":939,"url":1307},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F9b5dcaf85da5946dbf69dcd53f9edba08f760b32",{"type":936,"url":976},{"type":939,"url":1310},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.58",{"type":939,"url":1312},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-overwrite-via-read-tree",{"type":936,"url":1013},{"type":928,"url":1315},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4gmw-gg2m-w46p",[982,983,984],{"id":119,"slug":1318,"dossier":90,"summary":1319,"aliases":1320,"sourceIds":1324,"published":1325,"modified":1326,"checkedAt":7,"severity":1327,"references":1330,"versionKeys":1345,"packageCount":32,"repositoryCount":1260},"ghsa-4x4j-2g7c-83w6-326c14d2","Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path",[1321,1322,1323],"BIT-pillow-2026-55798","CVE-2026-55798","PYSEC-2026-2257",[119,1323],"2026-07-06T19:17:08.830Z","2026-09-10T03:51:10.324377232Z",[1328],{"type":924,"score":1329},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:L",[1331,1333,1335,1337,1339,1341,1343,1344],{"type":971,"url":1332},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-4x4j-2g7c-83w6",{"type":928,"url":1334},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55798",{"type":933,"url":1336},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F8404ea5fe5df40fc34aa1e51403dd6fce0778b8a",{"type":933,"url":1338},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F88194166691b7b603529b8b036ab3ab9cedd2de4",{"type":933,"url":1340},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fb0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f",{"type":939,"url":1342},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2257.yaml",{"type":936,"url":1247},{"type":928,"url":1249},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":120,"slug":1347,"dossier":47,"summary":1348,"aliases":1349,"sourceIds":1352,"published":1353,"modified":1354,"checkedAt":7,"severity":1355,"references":1359,"versionKeys":1369,"packageCount":32,"repositoryCount":985},"ghsa-539m-9xh6-q6rr-c4575e3c","GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file \u002F --add-virtual-file, enabling arbitrary file read via Repo.archive()",[1350,1351],"CVE-2026-73619","PYSEC-2026-3948",[120,1351],"2026-08-03T20:14:28Z","2026-09-10T13:11:01.695990206Z",[1356,1357],{"type":924,"score":1177},{"type":965,"score":1358},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[1360,1362,1363,1365,1366,1367],{"type":971,"url":1361},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-539m-9xh6-q6rr",{"type":939,"url":1137},{"type":939,"url":1364},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F7a4f5dcb7bf3cbcbf6e438017efcdfe0bc0d36ca",{"type":936,"url":976},{"type":939,"url":1142},{"type":928,"url":1368},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-repo-archive",[982,983,984],{"id":121,"slug":1371,"dossier":47,"summary":1372,"aliases":1373,"sourceIds":1377,"published":1378,"modified":1379,"checkedAt":7,"severity":1380,"references":1383,"versionKeys":1393,"packageCount":32,"repositoryCount":32},"ghsa-53q9-r3pm-6pq6-6fbb0149","PyTorch: `torch.load` with `weights_only=True` leads to remote code execution",[1374,1375,1376],"BIT-pytorch-2025-32434","CVE-2025-32434","PYSEC-2025-41",[121,1376],"2025-04-18T15:19:28Z","2026-08-07T08:12:20.395044060Z",[1381,1382],{"type":965,"score":966},{"type":924,"score":963},[1384,1386,1388,1390,1392],{"type":928,"url":1385},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fsecurity\u002Fadvisories\u002FGHSA-53q9-r3pm-6pq6",{"type":928,"url":1387},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-32434",{"type":939,"url":1389},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F8d4b8a920a2172523deb95bf20e8e52d50649c04",{"type":939,"url":1391},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-41.yaml",{"type":936,"url":1077},[1089],{"id":122,"slug":1395,"dossier":47,"summary":1396,"aliases":1397,"sourceIds":1401,"published":1402,"modified":1403,"checkedAt":7,"severity":1404,"references":1408,"versionKeys":1425,"packageCount":32,"repositoryCount":34},"ghsa-5rjg-fvgr-3xxf-79d39e6b","setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write",[1398,1399,1400],"BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49",[122,1400],"2025-05-17T16:15:19Z","2026-09-10T03:50:24.253527717Z",[1405,1407],{"type":965,"score":1406},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":924,"score":997},[1409,1411,1413,1415,1417,1419,1421,1423],{"type":971,"url":1410},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fsecurity\u002Fadvisories\u002FGHSA-5rjg-fvgr-3xxf",{"type":928,"url":1412},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-47273",{"type":1070,"url":1414},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fissues\u002F4946",{"type":933,"url":1416},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002F250a6d17978f9f6ac3ac887091f2d32886fbbb0b",{"type":939,"url":1418},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fsetuptools\u002FPYSEC-2025-49.yaml",{"type":936,"url":1420},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools",{"type":939,"url":1422},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fblob\u002F6ead555c5fb29bc57fe6105b1bffc163f56fd558\u002Fsetuptools\u002Fpackage_index.py#L810C1-L825C88",{"type":942,"url":1424},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F05\u002Fmsg00035.html",[1426,1427,1428,1429],"pypi:setuptools@69.2.0","pypi:setuptools@72.2.0","pypi:setuptools@75.8.0","pypi:setuptools@78.1.0",{"id":123,"slug":1431,"dossier":90,"summary":1432,"aliases":1433,"sourceIds":1437,"published":1438,"modified":1439,"checkedAt":7,"severity":1440,"references":1442,"versionKeys":1452,"packageCount":32,"repositoryCount":1260},"ghsa-5x94-69rx-g8h2-0bc05f88","Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`",[1434,1435,1436],"BIT-pillow-2026-54060","CVE-2026-54060","PYSEC-2026-2254",[123,1436],"2026-07-06T19:17:08.270Z","2026-09-10T03:51:10.514604451Z",[1441],{"type":924,"score":1103},[1443,1445,1447,1448,1450,1451],{"type":971,"url":1444},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-5x94-69rx-g8h2",{"type":928,"url":1446},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54060",{"type":933,"url":1243},{"type":939,"url":1449},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2254.yaml",{"type":936,"url":1247},{"type":928,"url":1249},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":124,"slug":1454,"dossier":47,"summary":1455,"aliases":1456,"sourceIds":1460,"published":1461,"modified":1462,"checkedAt":7,"severity":1463,"references":1467,"versionKeys":1475,"packageCount":32,"repositoryCount":104},"ghsa-5xmw-vc9v-4wf2-86a8861a","Pillow has a heap buffer overflow with nested list coordinates",[1457,1458,1459],"BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251",[124,1459],"2026-05-04T20:18:27Z","2026-09-10T03:51:04.701007027Z",[1464,1465],{"type":924,"score":1065},{"type":965,"score":1466},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[1468,1470,1472,1473],{"type":928,"url":1469},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-5xmw-vc9v-4wf2",{"type":928,"url":1471},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42309",{"type":936,"url":1247},{"type":928,"url":1474},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F12.2.0",[1254,1255,1256,1257,1258],{"id":125,"slug":1477,"dossier":47,"summary":1478,"aliases":1479,"sourceIds":1482,"published":1483,"modified":1484,"checkedAt":7,"severity":1485,"references":1488,"versionKeys":1498,"packageCount":32,"repositoryCount":985},"ghsa-5xxx-qhh7-9287-87d91b3e","GitPython: Incomplete unsafe_git_revision_options denylist omits --contents\u002F-S, enabling arbitrary file read via Repo.blame()",[1480,1481],"CVE-2026-78678","PYSEC-2026-3788",[125,1481],"2026-08-25T02:16:52.313Z","2026-09-08T19:00:06.904435463Z",[1486,1487],{"type":924,"score":1177},{"type":965,"score":1358},[1489,1491,1493,1494,1496],{"type":971,"url":1490},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-5xxx-qhh7-9287",{"type":928,"url":1492},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78678",{"type":936,"url":976},{"type":939,"url":1495},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3788.yaml",{"type":928,"url":1497},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-repo-blame",[982,983,984],{"id":126,"slug":1500,"dossier":90,"summary":1501,"aliases":1502,"sourceIds":1506,"published":1507,"modified":1508,"checkedAt":7,"severity":1509,"references":1512,"versionKeys":1528,"packageCount":32,"repositoryCount":1260},"ghsa-62p4-gmf7-7g93-cb81341c","Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)",[1503,1504,1505],"BIT-pillow-2026-54058","CVE-2026-54058","PYSEC-2026-3493",[126,1505],"2026-07-20T21:08:13Z","2026-09-10T03:51:10.632149522Z",[1510],{"type":965,"score":1511},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[1513,1515,1517,1519,1521,1522,1524,1526],{"type":939,"url":1514},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-62p4-gmf7-7g93",{"type":928,"url":1516},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54058",{"type":939,"url":1518},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9719",{"type":939,"url":1520},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F6a8de891fb00968e5ea79bfa84368ed90b3cfc1d",{"type":936,"url":1247},{"type":939,"url":1523},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F12.3.0",{"type":936,"url":1525},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fpillow",{"type":928,"url":1527},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-62p4-gmf7-7g93",[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":127,"slug":1530,"dossier":90,"summary":1531,"aliases":1532,"sourceIds":1535,"published":1536,"modified":1537,"checkedAt":7,"severity":1538,"references":1543,"versionKeys":1552,"packageCount":32,"repositoryCount":1557},"ghsa-65pc-fj4g-8rjx-9fe9e88a","Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix",[1533,1534],"CVE-2026-45409","PYSEC-2026-215",[127,1534],"2026-05-19T14:34:32Z","2026-09-10T03:50:45.700124422Z",[1539,1541],{"type":924,"score":1540},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",{"type":965,"score":1542},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[1544,1546,1548,1550],{"type":928,"url":1545},"https:\u002F\u002Fgithub.com\u002Fkjd\u002Fidna\u002Fsecurity\u002Fadvisories\u002FGHSA-65pc-fj4g-8rjx",{"type":928,"url":1547},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45409",{"type":936,"url":1549},"https:\u002F\u002Fgithub.com\u002Fkjd\u002Fidna",{"type":939,"url":1551},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fidna\u002FPYSEC-2026-215.yaml",[1553,1554,1555,1556],"pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.14","pypi:idna@3.7",21,{"id":128,"slug":1559,"dossier":47,"summary":1560,"aliases":1561,"sourceIds":1564,"published":1565,"modified":1566,"checkedAt":7,"severity":1567,"references":1571,"versionKeys":1583,"packageCount":32,"repositoryCount":985},"ghsa-6p8h-3wgx-97gf-635a010c","GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks",[1562,1563],"CVE-2026-73623","PYSEC-2026-3952",[128,1563],"2026-07-24T16:42:09Z","2026-09-10T13:11:03.995690741Z",[1568,1570],{"type":924,"score":1569},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":924,"score":997},[1572,1574,1576,1578,1579,1581],{"type":971,"url":1573},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-6p8h-3wgx-97gf",{"type":939,"url":1575},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2180",{"type":939,"url":1577},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fffcb5359e87619f4fe4a70a4aff5f08c5580ba97",{"type":936,"url":976},{"type":939,"url":1580},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.54",{"type":928,"url":1582},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-template",[982,983,984],{"id":129,"slug":1585,"dossier":90,"summary":1586,"aliases":1587,"sourceIds":1591,"published":1592,"modified":1593,"checkedAt":7,"severity":1594,"references":1596,"versionKeys":1609,"packageCount":32,"repositoryCount":1260},"ghsa-6r8x-57c9-28j4-3a620dbf","Pillow: Heap out-of-bounds write `Image.paste()` \u002F `Image.crop()` via signed coordinate overflow",[1588,1589,1590],"BIT-pillow-2026-59199","CVE-2026-59199","PYSEC-2026-3451",[129,1590],"2026-07-14T16:17:01.937Z","2026-09-10T03:51:10.822199342Z",[1595],{"type":924,"score":1103},[1597,1599,1601,1603,1605,1607,1608],{"type":971,"url":1598},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-6r8x-57c9-28j4",{"type":928,"url":1600},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59199",{"type":933,"url":1602},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9703",{"type":933,"url":1604},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",{"type":939,"url":1606},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3451.yaml",{"type":936,"url":1247},{"type":928,"url":1523},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":130,"slug":1611,"dossier":47,"summary":1612,"aliases":1613,"sourceIds":1616,"published":1617,"modified":1618,"checkedAt":7,"severity":1619,"references":1624,"versionKeys":1632,"packageCount":32,"repositoryCount":985},"ghsa-7545-fcxq-7j24-84dd19fd","GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository",[1614,1615],"CVE-2026-44243","PYSEC-2026-2162",[130,1615],"2026-05-06T19:38:48Z","2026-09-10T03:50:45.903378498Z",[1620,1622],{"type":924,"score":1621},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",{"type":965,"score":1623},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[1625,1627,1629,1630],{"type":971,"url":1626},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-7545-fcxq-7j24",{"type":928,"url":1628},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44243",{"type":936,"url":976},{"type":933,"url":1631},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.48",[982,983,984],{"id":131,"slug":1634,"dossier":47,"summary":1635,"aliases":1636,"sourceIds":1639,"published":1640,"modified":1641,"checkedAt":7,"severity":1642,"references":1649,"versionKeys":1664,"packageCount":32,"repositoryCount":985},"ghsa-7833-fr7j-v32q-fd003872","GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)",[1637,1638],"CVE-2026-78675","PYSEC-2026-3785",[131,1638],"2026-08-25T02:16:51.887Z","2026-09-08T18:45:10.860686865Z",[1643,1645,1647],{"type":924,"score":1644},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":965,"score":1646},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":924,"score":1648},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[1650,1652,1654,1656,1658,1659,1660,1662],{"type":971,"url":1651},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-7833-fr7j-v32q",{"type":928,"url":1653},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78675",{"type":939,"url":1655},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2211",{"type":939,"url":1657},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fef7568e3b317ce617eacda39b8b54dcdff8c3b5c",{"type":936,"url":976},{"type":939,"url":1189},{"type":939,"url":1661},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3785.yaml",{"type":928,"url":1663},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-local-file-content-disclosure-via-gitmodules",[982,983,984],{"id":132,"slug":1666,"dossier":47,"summary":1667,"aliases":1668,"sourceIds":1672,"published":1673,"modified":1674,"checkedAt":7,"severity":1675,"references":1682,"versionKeys":1694,"packageCount":32,"repositoryCount":66},"ghsa-78cv-mqj4-43f7-2021f695","Tornado has incomplete validation of cookie attributes",[1669,1670,1671],"CVE-2026-35536","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287",[132,1670,1671],"2026-03-11T22:17:00Z","2026-09-10T03:50:44.255695398Z",[1676,1678,1680],{"type":924,"score":1677},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:N",{"type":924,"score":1679},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N",{"type":924,"score":1681},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",[1683,1685,1687,1688,1690,1692],{"type":928,"url":1684},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-78cv-mqj4-43f7",{"type":939,"url":1686},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F24a2d96ea115f663b223887deb0060f13974c104",{"type":936,"url":1212},{"type":939,"url":1689},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.5",{"type":928,"url":1691},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-35536",{"type":928,"url":1693},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fqwm-6jpj-5wxc",[1220,1221,1222,1223],{"id":133,"slug":1696,"dossier":47,"summary":1697,"aliases":1698,"sourceIds":1701,"published":1702,"modified":1703,"checkedAt":7,"severity":1704,"references":1706,"versionKeys":1719,"packageCount":32,"repositoryCount":103},"ghsa-7cx3-6m66-7c5m-cde5125c","Tornado vulnerable to excessive logging caused by malformed multipart form data",[1699,1700],"CVE-2025-47287","PYSEC-2026-1974",[133,1700],"2025-05-16T14:12:40Z","2026-09-10T03:50:24.284224963Z",[1705],{"type":924,"score":1103},[1707,1709,1711,1713,1714,1716,1717],{"type":939,"url":1708},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-7cx3-6m66-7c5m",{"type":928,"url":1710},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-47287",{"type":939,"url":1712},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fb39b892bf78fe8fea01dd45199aa88307e7162f3",{"type":936,"url":1212},{"type":939,"url":1715},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F05\u002Fmsg00038.html",{"type":936,"url":1214},{"type":928,"url":1718},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7cx3-6m66-7c5m",[1220],{"id":134,"slug":1721,"dossier":47,"summary":1722,"aliases":1723,"sourceIds":1726,"published":1727,"modified":1728,"checkedAt":7,"severity":1729,"references":1732,"versionKeys":1749,"packageCount":32,"repositoryCount":272},"ghsa-7gcm-g887-7qv7-55bb9ff1","protobuf affected by a JSON recursion depth bypass",[1724,1725],"CVE-2026-0994","PYSEC-2026-1805",[134,1725],"2026-01-23T15:31:35Z","2026-09-10T03:50:32.795512159Z",[1730],{"type":965,"score":1731},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:L",[1733,1735,1737,1739,1741,1743,1745,1747],{"type":928,"url":1734},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0994",{"type":939,"url":1736},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fissues\u002F25070",{"type":939,"url":1738},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fpull\u002F25239",{"type":939,"url":1740},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002F5ebddcb1bcbe51d1fe323baa145e85f4f23128cf",{"type":939,"url":1742},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002Fd2b001626d137c62dfee6c88c87324102531868b",{"type":936,"url":1744},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf",{"type":936,"url":1746},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fprotobuf",{"type":928,"url":1748},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7gcm-g887-7qv7",[1750,1751,1752,1753,1754,1755,1756,1757,1758,1759],"pypi:protobuf@4.25.7","pypi:protobuf@4.25.8","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4","pypi:protobuf@6.31.1","pypi:protobuf@6.32.0","pypi:protobuf@6.32.1","pypi:protobuf@6.33.0","pypi:protobuf@6.33.1","pypi:protobuf@6.33.4",{"id":135,"slug":1761,"dossier":47,"summary":1762,"aliases":1763,"sourceIds":1766,"published":1767,"modified":1768,"checkedAt":7,"severity":1769,"references":1774,"versionKeys":1785,"packageCount":32,"repositoryCount":303},"ghsa-7p48-42j8-8846-584b0522","Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)",[1764,1765],"CVE-2026-33682","PYSEC-2026-2285",[135,1765],"2026-03-25T21:20:52Z","2026-07-13T07:26:25.253864212Z",[1770,1772],{"type":924,"score":1771},"CVSS:3.1\u002FAV:A\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N",{"type":924,"score":1773},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[1775,1777,1779,1781,1783],{"type":928,"url":1776},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fsecurity\u002Fadvisories\u002FGHSA-7p48-42j8-8846",{"type":928,"url":1778},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33682",{"type":933,"url":1780},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fcommit\u002F23692ca70b2f2ac720c72d1feb4f190c9d6eed76",{"type":936,"url":1782},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit",{"type":928,"url":1784},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Freleases\u002Ftag\u002F1.54.0",[1786,1787,1788],"pypi:streamlit@1.49.0","pypi:streamlit@1.49.1","pypi:streamlit@1.51.0",{"id":136,"slug":1790,"dossier":47,"summary":1791,"aliases":1792,"sourceIds":1794,"published":1795,"modified":1796,"checkedAt":7,"severity":1797,"references":1799,"versionKeys":1811,"packageCount":32,"repositoryCount":42},"ghsa-8423-8fgw-73vq-142b238e","tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)",[1793],"CVE-2026-91990",[136],"2026-09-01T20:17:38Z","2026-09-16T03:56:01.992806508Z",[1798],{"type":965,"score":1542},[1800,1802,1804,1806,1808,1809],{"type":939,"url":1801},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-8423-8fgw-73vq",{"type":939,"url":1803},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fpull\u002F3704",{"type":939,"url":1805},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fde85b3f87446e323e881bbaa3d5a74f4b76e5f05",{"type":939,"url":1807},"https:\u002F\u002Fgist.github.com\u002Fafldl\u002F649861f25d39b53b7edbe0298e171617",{"type":936,"url":1212},{"type":939,"url":1810},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.8",[1220,1221,1222,1223,1224,1812],"pypi:tornado@6.5.7",{"id":137,"slug":1814,"dossier":47,"summary":1815,"aliases":1816,"sourceIds":1820,"published":1821,"modified":1822,"checkedAt":7,"severity":1823,"references":1827,"versionKeys":1849,"packageCount":32,"repositoryCount":1287},"ghsa-887c-mr87-cxwp-233a2961","PyTorch Improper Resource Shutdown or Release vulnerability",[1817,1818,1819],"BIT-pytorch-2025-3730","CVE-2025-3730","PYSEC-2026-1970",[137,1819],"2025-04-16T21:30:59Z","2026-09-10T03:50:23.660138570Z",[1824,1825],{"type":924,"score":1061},{"type":965,"score":1826},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[1828,1830,1832,1834,1836,1838,1839,1841,1843,1845,1847],{"type":928,"url":1829},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3730",{"type":939,"url":1831},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F150835",{"type":939,"url":1833},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F150981",{"type":939,"url":1835},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F01f226bfb8f2c343f5c614a6bbf685d91160f3af",{"type":939,"url":1837},"https:\u002F\u002Fgithub.com\u002Ftimocafe\u002Ftewart-pytorch\u002Fcommit\u002F46fc5d8e360127361211cb237d5f9eef0223e567",{"type":936,"url":1077},{"type":939,"url":1840},"https:\u002F\u002Fvuldb.com\u002F?ctiid.305076",{"type":939,"url":1842},"https:\u002F\u002Fvuldb.com\u002F?id.305076",{"type":939,"url":1844},"https:\u002F\u002Fvuldb.com\u002F?submit.553645",{"type":936,"url":1846},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftorch",{"type":928,"url":1848},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-887c-mr87-cxwp",[1089,1090,1091,1850,1851],"pypi:torch@2.7.1","pypi:torch@2.7.1+cpu",{"id":138,"slug":1853,"dossier":47,"summary":1854,"aliases":1855,"sourceIds":1858,"published":1859,"modified":1860,"checkedAt":7,"severity":1861,"references":1868,"versionKeys":1883,"packageCount":32,"repositoryCount":985},"ghsa-8mcc-hrx5-hvxc-9da62a9f","GitPython: clone_from()\u002Fclone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination",[1856,1857],"CVE-2026-78677","PYSEC-2026-3787",[138,1857],"2026-08-25T02:16:52.173Z","2026-09-08T19:00:06.914140693Z",[1862,1864,1866],{"type":924,"score":1863},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":965,"score":1865},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",{"type":965,"score":1867},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[1869,1871,1873,1875,1877,1878,1879,1881],{"type":971,"url":1870},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-8mcc-hrx5-hvxc",{"type":928,"url":1872},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78677",{"type":939,"url":1874},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2210",{"type":939,"url":1876},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fb68afff45af0f49e79a3e2d2162018986b37ad5d",{"type":936,"url":976},{"type":939,"url":1189},{"type":939,"url":1880},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3787.yaml",{"type":928,"url":1882},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-path-traversal-via-separate-git-dir",[982,983,984],{"id":139,"slug":1885,"dossier":47,"summary":1886,"aliases":1887,"sourceIds":1890,"published":1891,"modified":1892,"checkedAt":7,"severity":1893,"references":1896,"versionKeys":1915,"packageCount":32,"repositoryCount":303},"ghsa-8qvm-5x2c-j2w7-8a075519","protobuf-python has a potential Denial of Service issue",[1888,1889],"CVE-2025-4565","PYSEC-2026-1806",[139,1889],"2025-06-16T16:02:58Z","2026-09-10T03:50:25.255076549Z",[1894],{"type":965,"score":1895},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[1897,1899,1901,1903,1905,1906,1908,1910,1912,1913],{"type":939,"url":1898},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fsecurity\u002Fadvisories\u002FGHSA-735f-pc8j-v9w8",{"type":939,"url":1900},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fsecurity\u002Fadvisories\u002FGHSA-8qvm-5x2c-j2w7",{"type":928,"url":1902},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-4565",{"type":939,"url":1904},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002F17838beda2943d08b8a9d4df5b68f5f04f26d901",{"type":936,"url":1744},{"type":939,"url":1907},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fblob\u002Fmain\u002Fpython\u002Fgoogle\u002Fprotobuf\u002Finternal\u002Fdecoder_test.py#L87-L98",{"type":939,"url":1909},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fblob\u002Fmain\u002Fpython\u002Fgoogle\u002Fprotobuf\u002Finternal\u002Fmessage_test.py#L1436-L1478",{"type":939,"url":1911},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Ftree\u002Fmain\u002Fpython#implementation-backends",{"type":936,"url":1746},{"type":928,"url":1914},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-8qvm-5x2c-j2w7",[1750,1752,1753],{"id":140,"slug":1917,"dossier":90,"summary":1918,"aliases":1919,"sourceIds":1923,"published":1924,"modified":1925,"checkedAt":7,"severity":1926,"references":1928,"versionKeys":1938,"packageCount":32,"repositoryCount":1260},"ghsa-8v84-f9pq-wr9x-6c1b185f","Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading",[1920,1921,1922],"BIT-pillow-2026-54059","CVE-2026-54059","PYSEC-2026-2253",[140,1922],"2026-07-06T19:17:08.127Z","2026-09-10T03:51:11.229114807Z",[1927],{"type":924,"score":1103},[1929,1931,1933,1934,1936,1937],{"type":971,"url":1930},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-8v84-f9pq-wr9x",{"type":928,"url":1932},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54059",{"type":933,"url":1243},{"type":939,"url":1935},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2253.yaml",{"type":936,"url":1247},{"type":928,"url":1249},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":141,"slug":1940,"dossier":47,"summary":1941,"aliases":1942,"sourceIds":1945,"published":1946,"modified":1947,"checkedAt":7,"severity":1948,"references":1951,"versionKeys":1963,"packageCount":32,"repositoryCount":985},"ghsa-94p4-4cq8-9g67-9a288a09","GitPython: Environment-variable exfiltration via Repo.create_remote() \u002F Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)",[1943,1944],"CVE-2026-73622","PYSEC-2026-3951",[141,1944],"2026-07-24T21:45:16Z","2026-09-10T13:10:44.445262446Z",[1949,1950],{"type":924,"score":1863},{"type":965,"score":1867},[1952,1954,1956,1957,1959,1961],{"type":971,"url":1953},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-94p4-4cq8-9g67",{"type":939,"url":1955},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F863417457a0633db7ea5aed4fd01e0b291a41162",{"type":936,"url":976},{"type":939,"url":1958},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.55",{"type":928,"url":1960},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-environment-variable-exfiltration-via-remote-add",{"type":933,"url":1962},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F8ac5a30519b6f4af85398b9b9d7064ff4d452da2",[982,983,984],{"id":142,"slug":1965,"dossier":47,"summary":1966,"aliases":1967,"sourceIds":1970,"published":1971,"modified":1972,"checkedAt":7,"severity":1973,"references":1975,"versionKeys":1991,"packageCount":32,"repositoryCount":985},"ghsa-956x-8gvw-wg5v-f5d32b2d","GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` \u002F `Repo.blame()`",[1968,1969],"CVE-2026-67323","PYSEC-2026-3839",[142,1969],"2026-07-21T20:10:06Z","2026-09-10T12:25:39.217544351Z",[1974],{"type":924,"score":1644},[1976,1978,1980,1982,1984,1985,1986,1988,1989],{"type":939,"url":1977},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-956x-8gvw-wg5v",{"type":928,"url":1979},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-67323",{"type":939,"url":1981},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2163",{"type":939,"url":1983},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F701ce32fe5ba8cb622c0e0342a376a6beb47d738",{"type":936,"url":976},{"type":939,"url":1009},{"type":939,"url":1987},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-command-injection-via-unguarded-git-options",{"type":936,"url":1013},{"type":928,"url":1990},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-956x-8gvw-wg5v",[982,983,984],{"id":143,"slug":1993,"dossier":47,"summary":1994,"aliases":1995,"sourceIds":1998,"published":1999,"modified":2000,"checkedAt":7,"severity":2001,"references":2004,"versionKeys":2023,"packageCount":32,"repositoryCount":1287},"ghsa-9hjg-9r4m-mvj7-32d7b63e","Requests vulnerable to .netrc credentials leak via malicious URLs",[1996,1997],"CVE-2024-47081","PYSEC-2026-1872",[143,1997],"2025-06-09T19:06:08Z","2026-09-10T03:50:25.139398550Z",[2002],{"type":924,"score":2003},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[2005,2007,2009,2011,2013,2015,2017,2019,2021],{"type":939,"url":2006},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-9hjg-9r4m-mvj7",{"type":928,"url":2008},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47081",{"type":939,"url":2010},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fpull\u002F6965",{"type":933,"url":2012},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002F96ba401c1296ab1dda74a2365ef36d88f7d144ef",{"type":936,"url":2014},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests",{"type":939,"url":2016},"https:\u002F\u002Frequests.readthedocs.io\u002Fen\u002Flatest\u002Fapi\u002F#requests.Session.trust_env",{"type":939,"url":2018},"https:\u002F\u002Fseclists.org\u002Ffulldisclosure\u002F2025\u002FJun\u002F2",{"type":936,"url":2020},"https:\u002F\u002Fpypi.org\u002Fproject\u002Frequests",{"type":928,"url":2022},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9hjg-9r4m-mvj7",[2024,2025],"pypi:requests@2.31.0","pypi:requests@2.32.3",{"id":144,"slug":2027,"dossier":90,"summary":2028,"aliases":2029,"sourceIds":2033,"published":2034,"modified":2035,"checkedAt":7,"severity":2036,"references":2038,"versionKeys":2051,"packageCount":32,"repositoryCount":1260},"ghsa-9hw9-ch79-4vh6-1ebda54f","Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch",[2030,2031,2032],"BIT-pillow-2026-59205","CVE-2026-59205","PYSEC-2026-3453",[144,2032],"2026-07-14T16:17:02.370Z","2026-09-10T03:51:11.334365483Z",[2037],{"type":924,"score":1103},[2039,2041,2043,2045,2047,2049,2050],{"type":971,"url":2040},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-9hw9-ch79-4vh6",{"type":928,"url":2042},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59205",{"type":933,"url":2044},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9715",{"type":933,"url":2046},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fa9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721",{"type":939,"url":2048},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3453.yaml",{"type":936,"url":1247},{"type":928,"url":1523},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":145,"slug":2053,"dossier":47,"summary":2054,"aliases":2055,"sourceIds":2058,"published":2059,"modified":2060,"checkedAt":7,"severity":2061,"references":2063,"versionKeys":2078,"packageCount":32,"repositoryCount":985},"ghsa-9rj7-rf2p-w77r-996a0359","GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks",[2056,2057],"CVE-2026-76218","PYSEC-2026-3840",[145,2057],"2026-08-07T15:36:43Z","2026-09-10T12:25:55.324487522Z",[2062],{"type":924,"score":1569},[2064,2066,2068,2069,2071,2072,2073,2075,2076],{"type":939,"url":2065},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-9rj7-rf2p-w77r",{"type":928,"url":2067},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76218",{"type":939,"url":1305},{"type":939,"url":2070},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fd9ddb55bdc66",{"type":936,"url":976},{"type":939,"url":1310},{"type":939,"url":2074},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-repo-init",{"type":936,"url":1013},{"type":928,"url":2077},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9rj7-rf2p-w77r",[982,983,984],{"id":146,"slug":2080,"dossier":47,"summary":2081,"aliases":2082,"sourceIds":2085,"published":2086,"modified":2087,"checkedAt":7,"severity":2088,"references":2091,"versionKeys":2108,"packageCount":32,"repositoryCount":32},"ghsa-9wx4-h78v-vm56-6a334c57","Requests `Session` object does not verify requests after making first request with verify=False",[2083,2084],"CVE-2024-35195","PYSEC-2026-1873",[146,2084],"2024-05-20T20:15:00Z","2026-09-10T03:50:13.740879755Z",[2089],{"type":924,"score":2090},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[2092,2094,2096,2098,2100,2101,2103,2105,2106],{"type":939,"url":2093},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-9wx4-h78v-vm56",{"type":928,"url":2095},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35195",{"type":939,"url":2097},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fpull\u002F6655",{"type":933,"url":2099},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002Fa58d7f2ffb4d00b46dca2d70a3932a0b37e22fac",{"type":936,"url":2014},{"type":939,"url":2102},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FIYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q",{"type":939,"url":2104},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FN7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ",{"type":936,"url":2020},{"type":928,"url":2107},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9wx4-h78v-vm56",[2024],{"id":147,"slug":2110,"dossier":47,"summary":2111,"aliases":2112,"sourceIds":2116,"published":2117,"modified":2118,"checkedAt":7,"severity":2119,"references":2124,"versionKeys":2140,"packageCount":32,"repositoryCount":103},"ghsa-c678-jfcj-6jmf-cd9a8774","PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument",[2113,2114,2115],"BIT-pytorch-2025-2148","CVE-2025-2148","PYSEC-2025-189",[147],"2025-03-10T12:30:55Z","2026-06-09T21:26:06.844649427Z",[2120,2122],{"type":924,"score":2121},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":965,"score":2123},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[2125,2127,2129,2131,2132,2134,2136,2138],{"type":928,"url":2126},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2148",{"type":939,"url":2128},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147722",{"type":939,"url":2130},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-189.yaml",{"type":936,"url":1077},{"type":939,"url":2133},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fblob\u002Fb0a67c7495bb11ecb23e556058db059ba48354af\u002Ftorch\u002Fautograd\u002Fprofiler.py#L990",{"type":939,"url":2135},"https:\u002F\u002Fvuldb.com\u002F?ctiid.299059",{"type":939,"url":2137},"https:\u002F\u002Fvuldb.com\u002F?id.299059",{"type":939,"url":2139},"https:\u002F\u002Fvuldb.com\u002F?submit.505959",[1089,1090],{"id":148,"slug":2142,"dossier":47,"summary":2143,"aliases":2144,"sourceIds":2147,"published":2148,"modified":2149,"checkedAt":7,"severity":2150,"references":2152,"versionKeys":2164,"packageCount":32,"repositoryCount":1287},"ghsa-c98p-7wgm-6p64-ef7ac7e3","Tornado: Quadratic DoS via Repeated Header Coalescing",[2145,2146],"CVE-2025-67725","PYSEC-2025-266",[148,2146],"2025-12-12T06:15:41.380Z","2026-07-20T19:15:27.567094965Z",[2151],{"type":924,"score":1103},[2153,2155,2157,2159,2161,2162],{"type":928,"url":2154},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-c98p-7wgm-6p64",{"type":928,"url":2156},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67725",{"type":933,"url":2158},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F771472cfdaeebc0d89a9cc46e249f8891a6b29cd",{"type":939,"url":2160},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-266.yaml",{"type":936,"url":1212},{"type":928,"url":2163},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.3",[1220,1221,1222],{"id":149,"slug":2166,"dossier":47,"summary":2167,"aliases":2168,"sourceIds":2172,"published":2173,"modified":2174,"checkedAt":7,"severity":2175,"references":2178,"versionKeys":2218,"packageCount":32,"repositoryCount":2219},"ghsa-cfh3-3jmp-rvhc-4e95572c","Pillow affected by out-of-bounds write when loading PSD images",[2169,2170,2171],"BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249",[149,2171],"2026-02-11T14:22:50Z","2026-09-10T03:50:59.393816085Z",[2176,2177],{"type":965,"score":1646},{"type":924,"score":1103},[2179,2181,2183,2185,2187,2189,2190,2192,2194,2196,2198,2200,2202,2204,2206,2208,2210,2212,2214,2216],{"type":939,"url":2180},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-cfh3-3jmp-rvhc",{"type":928,"url":2182},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25990",{"type":939,"url":2184},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9427",{"type":939,"url":2186},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F54ba4db542ad3c7b918812a4e2d69c27735a3199",{"type":939,"url":2188},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F9000313cc5d4a31bdcdd6d7f0781101abab553aa",{"type":936,"url":1247},{"type":939,"url":2191},"https:\u002F\u002Fpillow.readthedocs.io\u002Fen\u002Fstable\u002Freleasenotes\u002F12.1.1.html",{"type":939,"url":2193},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-25990",{"type":939,"url":2195},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-25990.json",{"type":928,"url":2197},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:10184",{"type":928,"url":2199},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:14873",{"type":928,"url":2201},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:14874",{"type":928,"url":2203},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16174",{"type":928,"url":2205},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:19712",{"type":928,"url":2207},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:28385",{"type":928,"url":2209},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:3461",{"type":928,"url":2211},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:3462",{"type":928,"url":2213},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4128",{"type":928,"url":2215},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4942",{"type":928,"url":2217},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:5168",[1251,1252,1253,1254,1255,1256,1257],15,{"id":150,"slug":2221,"dossier":47,"summary":2222,"aliases":2223,"sourceIds":2226,"published":2227,"modified":2228,"checkedAt":7,"severity":2229,"references":2232,"versionKeys":2249,"packageCount":32,"repositoryCount":103},"ghsa-cpwx-vrp4-4pq7-799bdc98","Jinja2 vulnerable to sandbox breakout through attr filter selecting format method",[2224,2225],"CVE-2025-27516","PYSEC-2026-1471",[150,2225],"2025-03-05T20:40:14Z","2026-09-10T03:49:48.526758681Z",[2230],{"type":965,"score":2231},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:P\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[2233,2235,2237,2239,2241,2243,2245,2247],{"type":939,"url":2234},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-cpwx-vrp4-4pq7",{"type":928,"url":2236},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-27516",{"type":933,"url":2238},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F90457bbf33b8662926ae65cdde4c4c32e756e403",{"type":936,"url":2240},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja",{"type":939,"url":2242},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F04\u002Fmsg00022.html",{"type":939,"url":2244},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F04\u002Fmsg00045.html",{"type":936,"url":2246},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fjinja2",{"type":928,"url":2248},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cpwx-vrp4-4pq7",[2250,2251],"pypi:jinja2@3.1.3","pypi:jinja2@3.1.5",{"id":151,"slug":2253,"dossier":47,"summary":2254,"aliases":2255,"sourceIds":2258,"published":2259,"modified":2260,"checkedAt":7,"severity":2261,"references":2264,"versionKeys":2275,"packageCount":32,"repositoryCount":66},"ghsa-cx3h-4qpv-8hc9-3078b6fa","Tornado has out-of-bounds memory access via C extension",[2256,2257],"CVE-2026-49854","PYSEC-2026-3388",[151,2257],"2026-06-12T18:30:19Z","2026-09-10T03:50:49.232529305Z",[2262],{"type":924,"score":2263},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[2265,2267,2268,2270,2271,2273],{"type":939,"url":2266},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-cx3h-4qpv-8hc9",{"type":936,"url":1212},{"type":939,"url":2269},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.6",{"type":936,"url":1214},{"type":928,"url":2272},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cx3h-4qpv-8hc9",{"type":928,"url":2274},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49854",[1220,1221,1222,1223,1224],{"id":152,"slug":2277,"dossier":47,"summary":2278,"aliases":2279,"sourceIds":2283,"published":2284,"modified":2285,"checkedAt":7,"severity":2286,"references":2291,"versionKeys":2307,"packageCount":32,"repositoryCount":32},"ghsa-cx63-2mw6-8hw5-1754ad59","setuptools vulnerable to Command Injection via package URL",[2280,2281,2282],"BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918",[152,2282],"2024-07-15T03:30:57Z","2026-09-10T03:50:16.663495061Z",[2287,2289],{"type":924,"score":2288},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":965,"score":2290},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:A\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[2292,2294,2296,2298,2299,2301,2303,2305],{"type":928,"url":2293},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-6345",{"type":939,"url":2295},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fpull\u002F4332",{"type":939,"url":2297},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002F88807c7062788254f654ea8c03427adc859321f0",{"type":936,"url":1420},{"type":939,"url":2300},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fd6362117-ad57-4e83-951f-b8141c6e7ca5",{"type":939,"url":2302},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2024\u002F09\u002Fmsg00018.html",{"type":936,"url":2304},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fsetuptools",{"type":928,"url":2306},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cx63-2mw6-8hw5",[1426],{"id":153,"slug":2309,"dossier":47,"summary":2310,"aliases":2311,"sourceIds":2315,"published":2316,"modified":2317,"checkedAt":7,"severity":2318,"references":2323,"versionKeys":2341,"packageCount":32,"repositoryCount":103},"ghsa-f4hp-rmr7-r7v8-fe038cb7","PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function",[2312,2313,2314],"BIT-pytorch-2025-2998","CVE-2025-2998","PYSEC-2025-192",[153],"2025-03-31T15:30:48Z","2026-06-09T22:11:09.050788278Z",[2319,2321],{"type":924,"score":2320},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":965,"score":2322},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[2324,2326,2328,2330,2332,2334,2335,2337,2339],{"type":928,"url":2325},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2998",{"type":939,"url":2327},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149622",{"type":939,"url":2329},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149622#issue-2935495265",{"type":939,"url":2331},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F494518046816d29099b7d056a74ffa5c244fdcdd",{"type":939,"url":2333},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-192.yaml",{"type":936,"url":1077},{"type":939,"url":2336},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302047",{"type":939,"url":2338},"https:\u002F\u002Fvuldb.com\u002F?id.302047",{"type":939,"url":2340},"https:\u002F\u002Fvuldb.com\u002F?submit.524151",[1089,1090],{"id":154,"slug":2343,"dossier":90,"summary":2344,"aliases":2345,"sourceIds":2349,"published":2350,"modified":2351,"checkedAt":7,"severity":2352,"references":2355,"versionKeys":2369,"packageCount":32,"repositoryCount":1260},"ghsa-fj7v-r99m-22gq-e36cfebd","Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images",[2346,2347,2348],"BIT-pillow-2026-59198","CVE-2026-59198","PYSEC-2026-3494",[154,2348],"2026-07-20T23:09:36Z","2026-09-10T03:50:51.891240357Z",[2353],{"type":924,"score":2354},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:L",[2356,2358,2360,2362,2364,2365,2366,2367],{"type":939,"url":2357},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-fj7v-r99m-22gq",{"type":928,"url":2359},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59198",{"type":939,"url":2361},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9709",{"type":939,"url":2363},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Feada3cbd7fb9963ee90673fb7b5270124a0d5f4b",{"type":936,"url":1247},{"type":939,"url":1523},{"type":936,"url":1525},{"type":928,"url":2368},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fj7v-r99m-22gq",[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":155,"slug":2371,"dossier":47,"summary":2372,"aliases":2373,"sourceIds":2375,"published":2376,"modified":2377,"checkedAt":7,"severity":2378,"references":2380,"versionKeys":2388,"packageCount":32,"repositoryCount":985},"ghsa-fjr4-x663-mwxc-324b7aa5","GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)",[2374],"CVE-2026-73624",[155],"2026-07-24T16:41:20Z","2026-09-10T03:50:51.919825118Z",[2379],{"type":924,"score":1130},[2381,2383,2384,2386,2387],{"type":939,"url":2382},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-fjr4-x663-mwxc",{"type":939,"url":1575},{"type":939,"url":2385},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1d51b891d7f236044a6aa17498ec682b63dad6e6",{"type":936,"url":976},{"type":939,"url":1580},[982,983,984],{"id":156,"slug":2390,"dossier":90,"summary":2391,"aliases":2392,"sourceIds":2395,"published":2396,"modified":2397,"checkedAt":7,"severity":2398,"references":2403,"versionKeys":2413,"packageCount":32,"repositoryCount":2416},"ghsa-gc5v-m9x4-r6x2-b9828ad8","Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function",[2393,2394],"CVE-2026-25645","PYSEC-2026-2275",[156,2394],"2026-03-25T16:56:28Z","2026-09-10T03:50:39.207922076Z",[2399,2401],{"type":924,"score":2400},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:N",{"type":924,"score":2402},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[2404,2406,2408,2410,2411],{"type":928,"url":2405},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-gc5v-m9x4-r6x2",{"type":928,"url":2407},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25645",{"type":933,"url":2409},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002F66d21cb07bd6255b1280291c4fafb71803cdb3b7",{"type":936,"url":2014},{"type":928,"url":2412},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Freleases\u002Ftag\u002Fv2.33.0",[2024,2025,2414,2415],"pypi:requests@2.32.4","pypi:requests@2.32.5",18,{"id":157,"slug":2418,"dossier":90,"summary":2419,"aliases":2420,"sourceIds":2423,"published":2424,"modified":2425,"checkedAt":7,"severity":2426,"references":2428,"versionKeys":2439,"packageCount":32,"repositoryCount":1048},"ghsa-gm62-xv2j-4w53-5befa184","urllib3 allows an unbounded number of links in the decompression chain",[2421,2422],"CVE-2025-66418","PYSEC-2026-1998",[157,2422],"2025-12-05T18:15:19Z","2026-09-10T03:50:58.741847479Z",[2427],{"type":965,"score":1028},[2429,2431,2433,2435,2436,2437],{"type":939,"url":2430},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-gm62-xv2j-4w53",{"type":928,"url":2432},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66418",{"type":933,"url":2434},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F24d7b67eac89f94e11003424bcf0d8f7b72222a8",{"type":936,"url":1037},{"type":936,"url":1039},{"type":928,"url":2438},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gm62-xv2j-4w53",[1043,1044,1045,1046,1047],{"id":158,"slug":2441,"dossier":47,"summary":2442,"aliases":2443,"sourceIds":2446,"published":2447,"modified":2448,"checkedAt":7,"severity":2449,"references":2452,"versionKeys":2467,"packageCount":32,"repositoryCount":32},"ghsa-gmj6-6f8f-6699-e3e02f35","Jinja has a sandbox breakout through malicious filenames",[2444,2445],"CVE-2024-56201","PYSEC-2026-1472",[158,2445],"2024-12-23T17:54:12Z","2026-09-10T03:50:56.152882717Z",[2450,2451],{"type":924,"score":997},{"type":965,"score":2231},[2453,2455,2457,2459,2461,2462,2464,2465],{"type":939,"url":2454},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-gmj6-6f8f-6699",{"type":928,"url":2456},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56201",{"type":939,"url":2458},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fissues\u002F1792",{"type":933,"url":2460},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F767b23617628419ae3709ccfb02f9602ae9fe51f",{"type":936,"url":2240},{"type":939,"url":2463},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Freleases\u002Ftag\u002F3.1.5",{"type":936,"url":2246},{"type":928,"url":2466},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gmj6-6f8f-6699",[2250],{"id":159,"slug":2469,"dossier":90,"summary":2470,"aliases":2471,"sourceIds":2475,"published":2476,"modified":2477,"checkedAt":7,"severity":2478,"references":2481,"versionKeys":2493,"packageCount":32,"repositoryCount":2416},"ghsa-h35f-9h28-mq5c-f3238ba1","setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC\u002FNFD) on macOS APFS\u002FHFS+",[2472,2473,2474],"BIT-setuptools-2026-59890","CVE-2026-59890","PYSEC-2026-3447",[159,2474],"2026-07-08T17:17:27.020Z","2026-09-10T03:50:52.323347787Z",[2479],{"type":924,"score":2480},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[2482,2484,2486,2488,2490,2491],{"type":971,"url":2483},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fsecurity\u002Fadvisories\u002FGHSA-h35f-9h28-mq5c",{"type":928,"url":2485},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59890",{"type":933,"url":2487},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002Fdd9f436a36486b4cb8a4c70a2321548b0be09b8f",{"type":939,"url":2489},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fsetuptools\u002FPYSEC-2026-3447.yaml",{"type":936,"url":1420},{"type":928,"url":2492},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Freleases\u002Ftag\u002Fv83.0.0",[1426,1427,1428,1429,2494,2495,2496,2497,2498,2499,2500,2501],"pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@81.0.0","pypi:setuptools@82.0.1",{"id":160,"slug":2503,"dossier":47,"summary":2504,"aliases":2505,"sourceIds":2508,"published":2509,"modified":2510,"checkedAt":7,"severity":2511,"references":2513,"versionKeys":2534,"packageCount":32,"repositoryCount":32},"ghsa-h75v-3vvj-5mfj-d8fc6bb7","Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter",[2506,2507],"CVE-2024-34064","PYSEC-2026-1474",[160,2507],"2024-05-06T14:20:59Z","2026-09-10T03:50:13.786450101Z",[2512],{"type":924,"score":1677},[2514,2516,2518,2520,2521,2523,2525,2527,2529,2531,2532],{"type":939,"url":2515},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-h75v-3vvj-5mfj",{"type":928,"url":2517},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-34064",{"type":933,"url":2519},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F0668239dc6b44ef38e7a6c9f91f312fd4ca581cb",{"type":936,"url":2240},{"type":939,"url":2522},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2024\u002F12\u002Fmsg00009.html",{"type":939,"url":2524},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002F567XIGSZMABG6TSMYWD7MIYNJSUQQRUC",{"type":939,"url":2526},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FGCLF44KY43BSVMTE6S53B4V5WP3FRRSE",{"type":939,"url":2528},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FSSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS",{"type":939,"url":2530},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS",{"type":936,"url":2246},{"type":928,"url":2533},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-h75v-3vvj-5mfj",[2250],{"id":161,"slug":2536,"dossier":47,"summary":2537,"aliases":2538,"sourceIds":2541,"published":2542,"modified":2543,"checkedAt":7,"severity":2544,"references":2546,"versionKeys":2561,"packageCount":32,"repositoryCount":985},"ghsa-hh9p-6wh2-4mfc-8e33cff1","GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()",[2539,2540],"CVE-2026-76217","PYSEC-2026-3841",[161,2540],"2026-08-07T15:43:56Z","2026-09-10T12:26:07.095223621Z",[2545],{"type":924,"score":1177},[2547,2549,2551,2552,2554,2555,2556,2558,2559],{"type":939,"url":2548},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-hh9p-6wh2-4mfc",{"type":928,"url":2550},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76217",{"type":939,"url":1305},{"type":939,"url":2553},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Ff2550b65bf60ca087190981e2c7b6865e201f40c",{"type":936,"url":976},{"type":939,"url":1310},{"type":939,"url":2557},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-pathspec-from-file",{"type":936,"url":1013},{"type":928,"url":2560},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-hh9p-6wh2-4mfc",[982,983,984],{"id":162,"slug":2563,"dossier":47,"summary":2564,"aliases":2565,"sourceIds":2568,"published":2569,"modified":2570,"checkedAt":7,"severity":2571,"references":2576,"versionKeys":2593,"packageCount":32,"repositoryCount":985},"ghsa-hmq2-w58f-27jc-f0b0fe70","GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython",[2566,2567],"CVE-2026-76222","PYSEC-2026-3784",[162,2567],"2026-08-07T15:45:39Z","2026-09-08T21:00:05.149418166Z",[2572,2574],{"type":924,"score":2573},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:N\u002FI:H\u002FA:L",{"type":965,"score":2575},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:N\u002FVI:H\u002FVA:L\u002FSC:N\u002FSI:H\u002FSA:L\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[2577,2579,2581,2583,2585,2587,2588,2589,2591],{"type":971,"url":2578},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-hmq2-w58f-27jc",{"type":928,"url":2580},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76222",{"type":939,"url":2582},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2202",{"type":939,"url":2584},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F4299c990e1ca21896f9485277caf7bb0ae5b404c",{"type":939,"url":2586},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fe4b8e7d026ca6abb4cf604f8e77093432ce23c06",{"type":936,"url":976},{"type":939,"url":1310},{"type":939,"url":2590},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3784.yaml",{"type":928,"url":2592},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-path-traversal-via-gitmodules-submodule-name",[982,983,984],{"id":163,"slug":2595,"dossier":47,"summary":2596,"aliases":2597,"sourceIds":2600,"published":2601,"modified":2602,"checkedAt":7,"severity":2603,"references":2605,"versionKeys":2615,"packageCount":32,"repositoryCount":1287},"ghsa-jhmp-mqwm-3gq8-3b1c10a9","Tornado: Quadratic DoS via Crafted Multipart Parameters",[2598,2599],"CVE-2025-67726","PYSEC-2025-267",[163,2599],"2025-12-12T07:15:44.920Z","2026-07-20T19:15:27.583657512Z",[2604],{"type":924,"score":1103},[2606,2608,2610,2611,2613,2614],{"type":928,"url":2607},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-jhmp-mqwm-3gq8",{"type":928,"url":2609},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67726",{"type":933,"url":2158},{"type":939,"url":2612},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-267.yaml",{"type":936,"url":1212},{"type":928,"url":2163},[1220,1221,1222],{"id":164,"slug":2617,"dossier":90,"summary":2618,"aliases":2619,"sourceIds":2623,"published":2624,"modified":2625,"checkedAt":7,"severity":2626,"references":2628,"versionKeys":2642,"packageCount":32,"repositoryCount":1260},"ghsa-jjj6-mw9f-p565-ed2d1f46","Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()",[2620,2621,2622],"BIT-pillow-2026-59200","CVE-2026-59200","PYSEC-2026-3495",[164,2622],"2026-07-20T23:11:29Z","2026-09-10T03:50:12.341825852Z",[2627],{"type":924,"score":1103},[2629,2631,2633,2635,2637,2638,2639,2640],{"type":939,"url":2630},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-jjj6-mw9f-p565",{"type":928,"url":2632},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59200",{"type":939,"url":2634},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9718",{"type":939,"url":2636},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Ff7a31ea75e460e108c37126da1f47812f21f6b09",{"type":936,"url":1247},{"type":939,"url":1523},{"type":936,"url":1525},{"type":928,"url":2641},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jjj6-mw9f-p565",[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":165,"slug":2644,"dossier":47,"summary":2645,"aliases":2646,"sourceIds":2649,"published":2650,"modified":2651,"checkedAt":7,"severity":2652,"references":2656,"versionKeys":2666,"packageCount":32,"repositoryCount":985},"ghsa-jm78-9fvv-mhgr-2c167ddc","GitPython: git-config OPTION-name injection via =\u002F#\u002Fwhitespace bypasses name validator, enabling forged core.sshCommand\u002FhooksPath (RCE)",[2647,2648],"CVE-2026-76221","PYSEC-2026-3783",[165,2648],"2026-08-07T15:46:35Z","2026-09-10T03:51:14.296736368Z",[2653,2654],{"type":924,"score":997},{"type":965,"score":2655},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[2657,2659,2660,2662,2663,2664],{"type":971,"url":2658},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-jm78-9fvv-mhgr",{"type":939,"url":1305},{"type":939,"url":2661},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fa495ccd3b547ccd60b2187215823b72a9c0188bf",{"type":936,"url":976},{"type":939,"url":1310},{"type":928,"url":2665},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-config-injection-via-option-name",[982,983,984],{"id":166,"slug":2668,"dossier":47,"summary":2669,"aliases":2670,"sourceIds":2673,"published":2674,"modified":2675,"checkedAt":7,"severity":2676,"references":2679,"versionKeys":2687,"packageCount":32,"repositoryCount":303},"ghsa-mf9v-mfxr-j63j-1a7db6d4","urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API",[2671,2672],"CVE-2026-44432","PYSEC-2026-142",[166,2672],"2026-05-11T14:51:45Z","2026-09-10T03:51:06.409994465Z",[2677,2678],{"type":924,"score":1103},{"type":965,"score":1028},[2680,2682,2684,2686],{"type":928,"url":2681},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-mf9v-mfxr-j63j",{"type":928,"url":2683},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44432",{"type":939,"url":2685},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Furllib3\u002FPYSEC-2026-142.yaml",{"type":936,"url":1037},[2688],"pypi:urllib3@2.6.3",{"id":167,"slug":2690,"dossier":47,"summary":2691,"aliases":2692,"sourceIds":2695,"published":2696,"modified":2697,"checkedAt":7,"severity":2698,"references":2700,"versionKeys":2709,"packageCount":32,"repositoryCount":66},"ghsa-mgf9-4vpg-hj56-00729355","tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)",[2693,2694],"CVE-2026-49855","PYSEC-2026-3389",[167,2694],"2026-06-15T20:19:28Z","2026-09-10T03:51:09.080081033Z",[2699],{"type":924,"score":1103},[2701,2703,2704,2705,2707],{"type":939,"url":2702},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-mgf9-4vpg-hj56",{"type":936,"url":1212},{"type":936,"url":1214},{"type":928,"url":2706},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mgf9-4vpg-hj56",{"type":928,"url":2708},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49855",[1220,1221,1222,1223,1224],{"id":168,"slug":2711,"dossier":47,"summary":2712,"aliases":2713,"sourceIds":2716,"published":2717,"modified":2718,"checkedAt":7,"severity":2719,"references":2721,"versionKeys":2734,"packageCount":32,"repositoryCount":42},"ghsa-mpf4-983q-p7j4-9fb72bc8","Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop",[2714,2715],"CVE-2026-82397","PYSEC-2026-3928",[168,2715],"2026-09-02T14:38:43Z","2026-09-10T12:25:33.492830390Z",[2720],{"type":924,"score":1103},[2722,2724,2726,2727,2729,2730,2731,2732],{"type":939,"url":2723},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-mpf4-983q-p7j4",{"type":928,"url":2725},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-82397",{"type":939,"url":1803},{"type":939,"url":2728},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F8d6363ed7b69d5f0da806efe34d256627a2191de",{"type":936,"url":1212},{"type":939,"url":1810},{"type":936,"url":1214},{"type":928,"url":2733},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mpf4-983q-p7j4",[1220,1221,1222,1223,1224,1812],{"id":169,"slug":2736,"dossier":47,"summary":2737,"aliases":2738,"sourceIds":2740,"published":2741,"modified":2742,"checkedAt":7,"severity":2743,"references":2745,"versionKeys":2751,"packageCount":32,"repositoryCount":985},"ghsa-mv93-w799-cj2w-4413137a","GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath",[2739],"CVE-2026-67326",[169],"2026-05-08T23:19:02Z","2026-09-10T03:51:06.521467170Z",[2744],{"type":924,"score":1156},[2746,2748,2750],{"type":939,"url":2747},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-mv93-w799-cj2w",{"type":928,"url":2749},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rpm5-65cw-6hj4",{"type":936,"url":976},[982,983,984],{"id":170,"slug":2753,"dossier":47,"summary":2754,"aliases":2755,"sourceIds":2758,"published":2759,"modified":2760,"checkedAt":7,"severity":2761,"references":2766,"versionKeys":2778,"packageCount":32,"repositoryCount":985},"ghsa-p538-c434-8v24-c303e516","GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count",[2756,2757],"CVE-2026-73621","PYSEC-2026-3950",[170,2757],"2026-08-03T20:23:17Z","2026-09-10T13:10:55.177009469Z",[2762,2764],{"type":924,"score":2763},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:L",{"type":965,"score":2765},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[2767,2769,2771,2773,2774,2776],{"type":971,"url":2768},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-p538-c434-8v24",{"type":939,"url":2770},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2184",{"type":939,"url":2772},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F38553b6fddc7f6a667cdb45a6762343a08fc72b2",{"type":936,"url":976},{"type":939,"url":2775},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.56",{"type":928,"url":2777},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-truncation-via-commit-count",[982,983,984],{"id":171,"slug":2780,"dossier":47,"summary":2781,"aliases":2782,"sourceIds":2786,"published":2787,"modified":2788,"checkedAt":7,"severity":2789,"references":2792,"versionKeys":2805,"packageCount":32,"repositoryCount":985},"ghsa-pg7v-jwj7-p798-7c77aab5","Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service",[2783,2784,2785],"BIT-pillow-2026-59203","CVE-2026-59203","PYSEC-2026-3452",[171,2785],"2026-07-14T16:17:02.063Z","2026-09-10T03:50:52.876709782Z",[2790,2791],{"type":924,"score":1540},{"type":924,"score":1103},[2793,2795,2797,2799,2801,2803,2804],{"type":971,"url":2794},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-pg7v-jwj7-p798",{"type":928,"url":2796},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59203",{"type":933,"url":2798},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9708",{"type":933,"url":2800},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F03992618118b4a76b6163cd72ab5ecd684133b83",{"type":939,"url":2802},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3452.yaml",{"type":936,"url":1247},{"type":928,"url":1523},[1256,1257,1258,1259],{"id":172,"slug":2807,"dossier":90,"summary":2808,"aliases":2809,"sourceIds":2813,"published":2814,"modified":2815,"checkedAt":7,"severity":2816,"references":2818,"versionKeys":2829,"packageCount":32,"repositoryCount":1260},"ghsa-phj9-mv4w-65pm-481e7dc3","Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`",[2810,2811,2812],"BIT-pillow-2026-55380","CVE-2026-55380","PYSEC-2026-2256",[172,2812],"2026-07-06T19:17:08.703Z","2026-09-10T03:51:11.734605509Z",[2817],{"type":924,"score":1103},[2819,2821,2823,2825,2827,2828],{"type":971,"url":2820},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-phj9-mv4w-65pm",{"type":928,"url":2822},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55380",{"type":933,"url":2824},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Ff39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675",{"type":939,"url":2826},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2256.yaml",{"type":936,"url":1247},{"type":928,"url":1249},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":173,"slug":2831,"dossier":47,"summary":2832,"aliases":2833,"sourceIds":2836,"published":2837,"modified":2838,"checkedAt":7,"severity":2839,"references":2841,"versionKeys":2853,"packageCount":32,"repositoryCount":1287},"ghsa-pq67-6m6q-mj2v-3522d1d4","urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation",[2834,2835],"CVE-2025-50181","PYSEC-2026-1999",[173,2835],"2025-06-18T17:50:00Z","2026-09-10T03:50:25.299291456Z",[2840],{"type":924,"score":1272},[2842,2844,2846,2848,2849,2850,2851],{"type":939,"url":2843},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-pq67-6m6q-mj2v",{"type":928,"url":2845},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-50181",{"type":933,"url":2847},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Ff05b1329126d5be6de501f9d1e3e36738bc08857",{"type":936,"url":1037},{"type":939,"url":1282},{"type":936,"url":1039},{"type":928,"url":2852},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pq67-6m6q-mj2v",[1043,1044,1045,1046],{"id":174,"slug":2855,"dossier":47,"summary":2856,"aliases":2857,"sourceIds":2860,"published":2861,"modified":2862,"checkedAt":7,"severity":2863,"references":2867,"versionKeys":2878,"packageCount":32,"repositoryCount":1287},"ghsa-pr2v-jx2c-wg9f-1ca6d67c","Tornado vulnerable to Header Injection and XSS via reason argument",[2858,2859],"CVE-2025-67724","PYSEC-2025-265",[174,2859],"2025-12-12T06:15:41.213Z","2026-07-20T19:00:24.953994999Z",[2864,2865],{"type":924,"score":1677},{"type":924,"score":2866},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N",[2868,2870,2872,2874,2876,2877],{"type":928,"url":2869},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-pr2v-jx2c-wg9f",{"type":928,"url":2871},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67724",{"type":933,"url":2873},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F9c163aebeaad9e6e7d28bac1f33580eb00b0e421",{"type":939,"url":2875},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-265.yaml",{"type":936,"url":1212},{"type":928,"url":2163},[1220,1221,1222],{"id":175,"slug":2880,"dossier":47,"summary":2881,"aliases":2882,"sourceIds":2884,"published":2885,"modified":2886,"checkedAt":7,"severity":2887,"references":2890,"versionKeys":2894,"packageCount":32,"repositoryCount":66},"ghsa-pw6j-qg29-8w7f-fb4d7ed6","Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse",[2883],"CVE-2026-91992",[175],"2026-06-15T20:37:24Z","2026-09-16T03:56:01.290461498Z",[2888],{"type":924,"score":2889},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[2891,2893],{"type":939,"url":2892},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-pw6j-qg29-8w7f",{"type":936,"url":1212},[1220,1221,1222,1223,1224],{"id":176,"slug":2896,"dossier":47,"summary":2897,"aliases":2898,"sourceIds":2902,"published":2903,"modified":2904,"checkedAt":7,"severity":2905,"references":2909,"versionKeys":2921,"packageCount":32,"repositoryCount":1048},"ghsa-pwv6-vv43-88gr-c5f811d0","Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)",[2899,2900,2901],"BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252",[176,2901],"2026-05-04T20:20:31Z","2026-09-10T03:50:47.242104143Z",[2906,2907],{"type":965,"score":1646},{"type":924,"score":2908},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2910,2911,2913,2915,2917,2919,2920],{"type":939,"url":2180},{"type":933,"url":2912},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-pwv6-vv43-88gr",{"type":928,"url":2914},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42311",{"type":933,"url":2916},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9520",{"type":933,"url":2918},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F58f9a1d166dcb0c274807d4423522d205b0c35ea",{"type":936,"url":1247},{"type":928,"url":1474},[1251,1252,1253,1254,1255,1256,1257,1258],{"id":177,"slug":2923,"dossier":47,"summary":2924,"aliases":2925,"sourceIds":2928,"published":2929,"modified":2930,"checkedAt":7,"severity":2931,"references":2934,"versionKeys":2947,"packageCount":32,"repositoryCount":32},"ghsa-q2x7-8rv6-6q7h-1113a288","Jinja has a sandbox breakout through indirect reference to format method",[2926,2927],"CVE-2024-56326","PYSEC-2026-1475",[177,2927],"2024-12-23T17:56:08Z","2026-09-10T03:50:21.662855250Z",[2932,2933],{"type":924,"score":1648},{"type":965,"score":2231},[2935,2937,2939,2941,2942,2943,2944,2945],{"type":939,"url":2936},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-q2x7-8rv6-6q7h",{"type":928,"url":2938},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56326",{"type":933,"url":2940},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F48b0687e05a5466a91cd5812d604fa37ad0943b4",{"type":936,"url":2240},{"type":939,"url":2463},{"type":939,"url":2242},{"type":936,"url":2246},{"type":928,"url":2946},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q2x7-8rv6-6q7h",[2250],{"id":178,"slug":2949,"dossier":90,"summary":2950,"aliases":2951,"sourceIds":2954,"published":2955,"modified":2956,"checkedAt":7,"severity":2957,"references":2962,"versionKeys":2968,"packageCount":32,"repositoryCount":2416},"ghsa-qccp-gfcp-xxvc-0d988969","urllib3: Sensitive headers forwarded across origins in proxied low-level redirects",[2952,2953],"CVE-2026-44431","PYSEC-2026-141",[178,2953],"2026-05-11T14:51:20Z","2026-09-10T03:50:47.272765640Z",[2958,2960],{"type":924,"score":2959},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",{"type":965,"score":2961},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[2963,2965,2967],{"type":928,"url":2964},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-qccp-gfcp-xxvc",{"type":928,"url":2966},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44431",{"type":936,"url":1037},[1043,1044,1045,1046,1047,2688],{"id":179,"slug":2970,"dossier":47,"summary":2971,"aliases":2972,"sourceIds":2976,"published":2977,"modified":2978,"checkedAt":7,"severity":2979,"references":2983,"versionKeys":3001,"packageCount":32,"repositoryCount":272},"ghsa-qfhq-4f3w-5fph-33bc3f14","PyTorch is vulnerable to memory corruption through its torch.lstm_cell function",[2973,2974,2975],"BIT-pytorch-2025-3001","CVE-2025-3001","PYSEC-2025-195",[179],"2025-03-31T18:31:08Z","2026-06-10T18:26:26.736808954Z",[2980,2981],{"type":924,"score":2320},{"type":965,"score":2982},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[2984,2986,2988,2990,2992,2994,2995,2997,2999],{"type":928,"url":2985},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3001",{"type":939,"url":2987},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149626",{"type":939,"url":2989},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149626#issue-2935860995",{"type":939,"url":2991},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F999d94b5ede5f4ec111ba7dd144129e2c2725b03",{"type":939,"url":2993},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-195.yaml",{"type":936,"url":1077},{"type":939,"url":2996},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302050",{"type":939,"url":2998},"https:\u002F\u002Fvuldb.com\u002F?id.302050",{"type":939,"url":3000},"https:\u002F\u002Fvuldb.com\u002F?submit.524212",[1089,1090,1091,1850,1851,3002,3003,3004,3005],"pypi:torch@2.8.0","pypi:torch@2.9.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu",{"id":180,"slug":3007,"dossier":47,"summary":3008,"aliases":3009,"sourceIds":3012,"published":3013,"modified":3014,"checkedAt":7,"severity":3015,"references":3019,"versionKeys":3032,"packageCount":32,"repositoryCount":66},"ghsa-qjxf-f2mg-c6mc-58d52008","Tornado is vulnerable to DoS due to too many multipart parts",[3010,3011],"CVE-2026-31958","PYSEC-2026-140",[180,3011],"2026-03-11T20:16:16.617Z","2026-09-10T03:50:40.522968763Z",[3016,3017],{"type":924,"score":1103},{"type":965,"score":3018},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[3020,3022,3024,3026,3028,3029,3030],{"type":928,"url":3021},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-qjxf-f2mg-c6mc",{"type":928,"url":3023},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31958",{"type":939,"url":3025},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F119a195e290c43ad2d63a2cf012c29d43d6ed839",{"type":939,"url":3027},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2026-140.yaml",{"type":936,"url":1212},{"type":939,"url":1689},{"type":939,"url":3031},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F04\u002Fmsg00000.html",[1220,1221,1222,1223],{"id":181,"slug":3034,"dossier":47,"summary":3035,"aliases":3036,"sourceIds":3039,"published":3040,"modified":3041,"checkedAt":7,"severity":3042,"references":3045,"versionKeys":3060,"packageCount":32,"repositoryCount":272},"ghsa-qmgc-5h2g-mvrw-199eacc8","filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock",[3037,3038],"CVE-2026-22701","PYSEC-2026-1374",[181,3038],"2026-01-13T18:44:55Z","2026-09-10T03:50:33.702580779Z",[3043],{"type":924,"score":3044},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:H",[3046,3048,3050,3052,3054,3056,3058],{"type":939,"url":3047},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fsecurity\u002Fadvisories\u002FGHSA-qmgc-5h2g-mvrw",{"type":928,"url":3049},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22701",{"type":939,"url":3051},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F255ed068bc85d1ef406e50a135e1459170dd1bf0",{"type":939,"url":3053},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F41b42dd2c72aecf7da83dbda5903b8087dddc4d5",{"type":936,"url":3055},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock",{"type":936,"url":3057},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ffilelock",{"type":928,"url":3059},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qmgc-5h2g-mvrw",[3061,3062,3063,3064],"pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0",{"id":182,"slug":3066,"dossier":47,"summary":3067,"aliases":3068,"sourceIds":3072,"published":3073,"modified":3074,"checkedAt":7,"severity":3075,"references":3078,"versionKeys":3092,"packageCount":32,"repositoryCount":1048},"ghsa-r73j-pqj5-w3x7-8d4d543f","Pillow has a PDF Parsing Trailer Infinite Loop (DoS)",[3069,3070,3071],"BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874",[182,3071],"2026-05-04T20:19:30Z","2026-09-10T03:50:55.309086884Z",[3076,3077],{"type":924,"score":1065},{"type":965,"score":1466},[3079,3081,3083,3085,3087,3088,3089,3090],{"type":939,"url":3080},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-r73j-pqj5-w3x7",{"type":928,"url":3082},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42310",{"type":939,"url":3084},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9519",{"type":939,"url":3086},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F3bf614e4b8615d0ce1d5039efaf6db447fe7c468",{"type":936,"url":1247},{"type":939,"url":1474},{"type":936,"url":1525},{"type":928,"url":3091},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-r73j-pqj5-w3x7",[1251,1252,1253,1254,1255,1256,1257,1258],{"id":183,"slug":3094,"dossier":47,"summary":3095,"aliases":3096,"sourceIds":3099,"published":3100,"modified":3101,"checkedAt":7,"severity":3102,"references":3105,"versionKeys":3115,"packageCount":32,"repositoryCount":985},"ghsa-r9mr-m37c-5fr3-d43000fc","GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution",[3097,3098],"CVE-2026-73625","PYSEC-2026-3953",[183,3098],"2026-07-24T16:42:57Z","2026-09-10T13:10:47.448946391Z",[3103,3104],{"type":924,"score":997},{"type":965,"score":2655},[3106,3108,3109,3111,3112,3113],{"type":971,"url":3107},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-r9mr-m37c-5fr3",{"type":939,"url":1575},{"type":939,"url":3110},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fe8d0fbf774d1f6baa3b481adfe48bd262e43b453",{"type":936,"url":976},{"type":939,"url":1580},{"type":928,"url":3114},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-kwarg-value-smuggling",[982,983,984],{"id":184,"slug":3117,"dossier":47,"summary":3118,"aliases":3119,"sourceIds":3122,"published":3123,"modified":3124,"checkedAt":7,"severity":3125,"references":3128,"versionKeys":3141,"packageCount":32,"repositoryCount":272},"ghsa-rgxp-2hwp-jwgg-76cdda06","Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering",[3120,3121],"CVE-2026-25087","PYSEC-2026-113",[184,3121],"2026-02-17T14:16:01.947Z","2026-09-10T03:50:35.750182003Z",[3126],{"type":924,"score":3127},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:H",[3129,3131,3133,3135,3137,3139],{"type":928,"url":3130},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25087",{"type":933,"url":3132},"https:\u002F\u002Fgithub.com\u002Fapache\u002Farrow\u002Fpull\u002F48925",{"type":936,"url":3134},"https:\u002F\u002Fgithub.com\u002Fapache\u002Farrow",{"type":939,"url":3136},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpyarrow\u002FPYSEC-2026-113.yaml",{"type":928,"url":3138},"https:\u002F\u002Flists.apache.org\u002Fthread\u002Fmpm4ld1qony30tchfpjtk5b11tcyvmwh",{"type":928,"url":3140},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rgxp-2hwp-jwgg",[3142,3143,3144,3145],"pypi:pyarrow@18.1.0","pypi:pyarrow@20.0.0","pypi:pyarrow@21.0.0","pypi:pyarrow@22.0.0",{"id":185,"slug":3147,"dossier":47,"summary":3148,"aliases":3149,"sourceIds":3152,"published":3153,"modified":3154,"checkedAt":7,"severity":3155,"references":3157,"versionKeys":3165,"packageCount":32,"repositoryCount":985},"ghsa-rpm5-65cw-6hj4-6c97dd77","GitPython has Command Injection via Git options bypass",[3150,3151],"CVE-2026-42215","PYSEC-2026-2160",[185,3151],"2026-04-25T23:42:16Z","2026-09-10T03:51:03.167884784Z",[3156],{"type":924,"score":997},[3158,3160,3162,3163],{"type":971,"url":3159},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-rpm5-65cw-6hj4",{"type":928,"url":3161},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42215",{"type":936,"url":976},{"type":933,"url":3164},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.47",[982,983,984],{"id":186,"slug":3167,"dossier":47,"summary":3168,"aliases":3169,"sourceIds":3173,"published":2316,"modified":3174,"checkedAt":7,"severity":3175,"references":3178,"versionKeys":3196,"packageCount":32,"repositoryCount":1048},"ghsa-rrmf-rvhw-rf47-389d8330","PyTorch is vulnerable to memory corruption through its torch.jit.script function",[3170,3171,3172],"BIT-pytorch-2025-3000","CVE-2025-3000","PYSEC-2025-194",[186],"2026-09-10T03:49:48.419046410Z",[3176,3177],{"type":924,"score":2320},{"type":965,"score":2982},[3179,3181,3183,3185,3187,3189,3190,3192,3194],{"type":928,"url":3180},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3000",{"type":939,"url":3182},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149623",{"type":939,"url":3184},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149623#issue-2935703015",{"type":939,"url":3186},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002Fb90c94991cdf8b87c8f7439f79518e0ef2c4ca4f",{"type":939,"url":3188},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-194.yaml",{"type":936,"url":1077},{"type":939,"url":3191},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302049",{"type":939,"url":3193},"https:\u002F\u002Fvuldb.com\u002F?id.302049",{"type":939,"url":3195},"https:\u002F\u002Fvuldb.com\u002F?submit.524197",[3197,3198,3199,1089,1090,1091,1850,1851,3002,3003,3004,3005],"pypi:torch@2.10.0","pypi:torch@2.11.0","pypi:torch@2.12.1",{"id":187,"slug":3201,"dossier":47,"summary":3202,"aliases":3203,"sourceIds":3206,"published":3207,"modified":3208,"checkedAt":7,"severity":3209,"references":3211,"versionKeys":3227,"packageCount":32,"repositoryCount":985},"ghsa-rwj8-pgh3-r573-0bf779f8","GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL",[3204,3205],"CVE-2026-67322","PYSEC-2026-3842",[187,3205],"2026-07-21T22:06:09Z","2026-09-10T12:25:44.904800513Z",[3210],{"type":924,"score":1863},[3212,3214,3216,3218,3219,3220,3222,3224,3225],{"type":939,"url":3213},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-rwj8-pgh3-r573",{"type":928,"url":3215},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-67322",{"type":939,"url":3217},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2172",{"type":939,"url":1962},{"type":936,"url":976},{"type":939,"url":3221},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.52",{"type":939,"url":3223},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-environment-variable-exfiltration-via-clone-from",{"type":936,"url":1013},{"type":928,"url":3226},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rwj8-pgh3-r573",[982,983,984],{"id":188,"slug":3229,"dossier":47,"summary":3230,"aliases":3231,"sourceIds":3234,"published":3235,"modified":3236,"checkedAt":7,"severity":3237,"references":3239,"versionKeys":3247,"packageCount":32,"repositoryCount":985},"ghsa-v87r-6q3f-2j67-81913ca6","GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath",[3232,3233],"CVE-2026-44244","PYSEC-2026-2163",[188,3233],"2026-05-06T21:58:00Z","2026-09-10T03:50:47.691444343Z",[3238],{"type":924,"score":1648},[3240,3242,3244,3245],{"type":971,"url":3241},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-v87r-6q3f-2j67",{"type":928,"url":3243},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44244",{"type":936,"url":976},{"type":933,"url":3246},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.49",[982,983,984],{"id":189,"slug":3249,"dossier":47,"summary":3250,"aliases":3251,"sourceIds":3255,"published":2316,"modified":3256,"checkedAt":7,"severity":3257,"references":3260,"versionKeys":3275,"packageCount":32,"repositoryCount":42},"ghsa-vgrw-7cvw-pwgx-766c6098","PyTorch is vulnerable to memory corruption through its unpack_sequence function",[3252,3253,3254],"BIT-pytorch-2025-2999","CVE-2025-2999","PYSEC-2025-193",[189],"2026-06-10T17:41:15.774477397Z",[3258,3259],{"type":924,"score":2320},{"type":965,"score":2322},[3261,3263,3264,3265,3266,3268,3269,3271,3273],{"type":928,"url":3262},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2999",{"type":939,"url":2327},{"type":939,"url":2329},{"type":939,"url":2331},{"type":939,"url":3267},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-193.yaml",{"type":936,"url":1077},{"type":939,"url":3270},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302048",{"type":939,"url":3272},"https:\u002F\u002Fvuldb.com\u002F?id.302048",{"type":939,"url":3274},"https:\u002F\u002Fvuldb.com\u002F?submit.524198",[1089,1090,1091,1850,1851,3002,3003],{"id":190,"slug":3277,"dossier":90,"summary":3278,"aliases":3279,"sourceIds":3283,"published":3284,"modified":3285,"checkedAt":7,"severity":3286,"references":3288,"versionKeys":3302,"packageCount":32,"repositoryCount":1260},"ghsa-vjc4-5qp5-m44j-08063b19","Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service",[3280,3281,3282],"BIT-pillow-2026-59204","CVE-2026-59204","PYSEC-2026-3496",[190,3282],"2026-07-20T23:18:32Z","2026-09-10T03:50:53.107920034Z",[3287],{"type":965,"score":3018},[3289,3291,3293,3295,3297,3298,3299,3300],{"type":939,"url":3290},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-vjc4-5qp5-m44j",{"type":928,"url":3292},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59204",{"type":939,"url":3294},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9704",{"type":939,"url":3296},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F13ada41172142f2fd9f0906f615a00ea623a11ca",{"type":936,"url":1247},{"type":939,"url":1523},{"type":936,"url":1525},{"type":928,"url":3301},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vjc4-5qp5-m44j",[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":191,"slug":3304,"dossier":47,"summary":3305,"aliases":3306,"sourceIds":3309,"published":3310,"modified":3311,"checkedAt":7,"severity":3312,"references":3315,"versionKeys":3328,"packageCount":32,"repositoryCount":303},"ghsa-vqfr-h8mv-ghfj-49515033","h11 accepts some malformed Chunked-Encoding bodies",[3307,3308],"CVE-2025-43859","PYSEC-2026-348",[191,3308],"2025-04-24T16:07:56Z","2026-09-10T03:50:24.086696793Z",[3313],{"type":924,"score":3314},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[3316,3318,3320,3322,3324,3326],{"type":939,"url":3317},"https:\u002F\u002Fgithub.com\u002Fpython-hyper\u002Fh11\u002Fsecurity\u002Fadvisories\u002FGHSA-vqfr-h8mv-ghfj",{"type":928,"url":3319},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-43859",{"type":939,"url":3321},"https:\u002F\u002Fgithub.com\u002Fpython-hyper\u002Fh11\u002Fcommit\u002F114803a29ce50116dc47951c690ad4892b1a36ed",{"type":936,"url":3323},"https:\u002F\u002Fgithub.com\u002Fpython-hyper\u002Fh11",{"type":936,"url":3325},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fh11",{"type":928,"url":3327},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vqfr-h8mv-ghfj",[3329],"pypi:h11@0.14.0",{"id":192,"slug":3331,"dossier":47,"summary":3332,"aliases":3333,"sourceIds":3336,"published":3337,"modified":3338,"checkedAt":7,"severity":3339,"references":3346,"versionKeys":3372,"packageCount":32,"repositoryCount":303},"ghsa-vqwp-45wm-r9r5-eaa960a2","Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission",[3334,3335],"CVE-2026-10804","PYSEC-2026-212",[192,3335],"2026-06-04T12:16:24.620Z","2026-07-23T15:00:23.893493649Z",[3340,3342,3344],{"type":924,"score":3341},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:L",{"type":965,"score":3343},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":924,"score":3345},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[3347,3349,3351,3353,3355,3357,3359,3360,3362,3364,3366,3368,3370],{"type":928,"url":3348},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-10804",{"type":933,"url":3350},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fissues\u002F14622",{"type":933,"url":3352},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fpull\u002F14635",{"type":939,"url":3354},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fpull\u002F15397",{"type":939,"url":3356},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fcommit\u002Ffec0f584dae9261abed16cad35b32922104bb933",{"type":939,"url":3358},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fstreamlit\u002FPYSEC-2026-212.yaml",{"type":936,"url":1782},{"type":928,"url":3361},"https:\u002F\u002Fvuldb.com\u002Fcve\u002FCVE-2026-10804",{"type":928,"url":3363},"https:\u002F\u002Fvuldb.com\u002Fsubmit\u002F831508",{"type":928,"url":3365},"https:\u002F\u002Fvuldb.com\u002Fvuln\u002F368253",{"type":1070,"url":3367},"https:\u002F\u002Fvuldb.com\u002Fvuln\u002F368253\u002Fcti",{"type":939,"url":3369},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002F",{"type":928,"url":3371},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vqwp-45wm-r9r5",[1786,1787,1788],{"id":193,"slug":3374,"dossier":47,"summary":3375,"aliases":3376,"sourceIds":3379,"published":3380,"modified":3381,"checkedAt":7,"severity":3382,"references":3385,"versionKeys":3402,"packageCount":32,"repositoryCount":272},"ghsa-w853-jp5j-5j7f-2786386f","filelock has a TOCTOU race condition which allows symlink attacks during lock file creation",[3377,3378],"CVE-2025-68146","PYSEC-2026-1375",[193,3378],"2025-12-16T20:52:55Z","2026-09-10T03:50:32.252960082Z",[3383],{"type":924,"score":3384},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",[3386,3388,3390,3391,3393,3395,3397,3398,3400],{"type":939,"url":3387},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fsecurity\u002Fadvisories\u002FGHSA-w853-jp5j-5j7f",{"type":939,"url":3389},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F4724d7f8c3393ec1f048c93933e6e3e6ec321f0e",{"type":936,"url":3055},{"type":939,"url":3392},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Freleases\u002Ftag\u002F3.20.1",{"type":939,"url":3394},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Ffileio\u002Ffile-attribute-constants",{"type":939,"url":3396},"https:\u002F\u002Fpubs.opengroup.org\u002Fonlinepubs\u002F9699919799\u002Ffunctions\u002Fopen.html",{"type":936,"url":3057},{"type":928,"url":3399},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-w853-jp5j-5j7f",{"type":928,"url":3401},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68146",[3061,3062,3063,3064],{"id":194,"slug":3404,"dossier":47,"summary":3405,"aliases":3406,"sourceIds":3410,"published":3411,"modified":3412,"checkedAt":7,"severity":3413,"references":3416,"versionKeys":3454,"packageCount":32,"repositoryCount":1048},"ghsa-whj4-6x5x-4v2j-eb5fc6a1","FITS GZIP decompression bomb in Pillow",[3407,3408,3409],"BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250",[194,3409],"2026-04-13T19:22:35Z","2026-09-10T03:51:03.847830288Z",[3414,3415],{"type":924,"score":1103},{"type":965,"score":3018},[3417,3419,3421,3423,3425,3426,3428,3430,3432,3434,3436,3438,3439,3441,3443,3445,3446,3448,3450,3452],{"type":939,"url":3418},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-whj4-6x5x-4v2j",{"type":928,"url":3420},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40192",{"type":939,"url":3422},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9521",{"type":939,"url":3424},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F3cb854e8b2bab43f40e342e665f9340d861aa628",{"type":936,"url":1247},{"type":939,"url":3427},"https:\u002F\u002Fpillow.readthedocs.io\u002Fen\u002Fstable\u002Freleasenotes\u002F12.2.0.html#prevent-fits-decompression-bomb",{"type":939,"url":3429},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-40192",{"type":939,"url":3431},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-40192.json",{"type":928,"url":3433},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16008",{"type":928,"url":3435},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16009",{"type":928,"url":3437},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16030",{"type":928,"url":2203},{"type":928,"url":3440},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:17609",{"type":928,"url":3442},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:17611",{"type":928,"url":3444},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:19375",{"type":928,"url":2205},{"type":928,"url":3447},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:21017",{"type":928,"url":3449},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22465",{"type":928,"url":3451},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22629",{"type":928,"url":3453},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22840",[1251,1252,1253,1254,1255,1256,1257,1258],{"id":195,"slug":3456,"dossier":47,"summary":3457,"aliases":3458,"sourceIds":3462,"published":3463,"modified":3464,"checkedAt":7,"severity":3465,"references":3468,"versionKeys":3477,"packageCount":32,"repositoryCount":1048},"ghsa-wjx4-4jcj-g98j-e937161b","Pillow has an integer overflow when processing fonts",[3459,3460,3461],"BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165",[195,3461],"2026-05-04T20:18:45Z","2026-09-10T03:50:47.950262681Z",[3466,3467],{"type":924,"score":1065},{"type":965,"score":1466},[3469,3471,3473,3475,3476],{"type":928,"url":3470},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-wjx4-4jcj-g98j",{"type":928,"url":3472},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42308",{"type":939,"url":3474},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-165.yaml",{"type":936,"url":1247},{"type":928,"url":1474},[1251,1252,1253,1254,1255,1256,1257,1258],{"id":196,"slug":3479,"dossier":47,"summary":3480,"aliases":3481,"sourceIds":3484,"published":3485,"modified":3486,"checkedAt":7,"severity":3487,"references":3489,"versionKeys":3504,"packageCount":32,"repositoryCount":985},"ghsa-wvpp-8hx9-p66j-188b3951","GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution",[3482,3483],"CVE-2026-76220","PYSEC-2026-3843",[196,3483],"2026-08-07T15:49:07Z","2026-09-10T12:26:01.792035310Z",[3488],{"type":924,"score":997},[3490,3492,3494,3495,3497,3498,3499,3501,3502],{"type":939,"url":3491},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-wvpp-8hx9-p66j",{"type":928,"url":3493},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76220",{"type":939,"url":1305},{"type":939,"url":3496},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F96a888f4d782cb2f80452148e48e60ce4af6d541",{"type":936,"url":976},{"type":939,"url":1310},{"type":939,"url":3500},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-command-execution-via-split-single-char-options",{"type":936,"url":1013},{"type":928,"url":3503},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wvpp-8hx9-p66j",[982,983,984],{"id":197,"slug":3506,"dossier":47,"summary":3507,"aliases":3508,"sourceIds":3509,"published":3510,"modified":3511,"checkedAt":7,"severity":3512,"references":3515,"versionKeys":3527,"packageCount":32,"repositoryCount":303},"ghsa-wwv5-g3v4-889x-b37c7c95","Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`",[],[197],"2026-09-01T20:17:23Z","2026-09-10T03:50:54.582059531Z",[3513],{"type":965,"score":3514},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:P\u002FVC:L\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3516,3518,3519,3521,3523,3525,3526],{"type":939,"url":3517},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-wwv5-g3v4-889x",{"type":939,"url":1803},{"type":939,"url":3520},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fpull\u002F3706",{"type":939,"url":3522},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F6ef836e43e1278530041376adb32504daa977b91",{"type":939,"url":3524},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fda284767eae8e1f0484f123b8c3225f6465b09c7",{"type":936,"url":1212},{"type":939,"url":1810},[1224,1812],{"id":198,"slug":3529,"dossier":47,"summary":3530,"aliases":3531,"sourceIds":3534,"published":3535,"modified":3536,"checkedAt":7,"severity":3537,"references":3541,"versionKeys":3550,"packageCount":32,"repositoryCount":985},"ghsa-x2qx-6953-8485-107f8fe2","GitPython: Unsafe option check validates multi_options before shlex.split transformation",[3532,3533],"CVE-2026-42284","PYSEC-2026-2161",[198,3533],"2026-04-25T23:41:49Z","2026-09-10T03:51:03.787491179Z",[3538,3540],{"type":924,"score":3539},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":924,"score":963},[3542,3544,3546,3547,3548],{"type":971,"url":3543},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-x2qx-6953-8485",{"type":928,"url":3545},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42284",{"type":936,"url":976},{"type":933,"url":3164},{"type":939,"url":3549},"https:\u002F\u002Fwww.tenable.com\u002Fcve\u002FCVE-2026-32686",[982,983,984],{"id":199,"slug":3552,"dossier":47,"summary":3553,"aliases":3554,"sourceIds":3558,"published":3559,"modified":3560,"checkedAt":7,"severity":3561,"references":3566,"versionKeys":3582,"packageCount":32,"repositoryCount":103},"ghsa-x3gm-94wq-g975-a197ba31","PyTorch: Manipulation of the argument scale\u002Fzero_point leads to improper initialization via Quantized Sigmoid Module",[3555,3556,3557],"BIT-pytorch-2025-2149","CVE-2025-2149","PYSEC-2025-190",[199],"2025-03-10T15:30:47Z","2026-06-09T22:11:08.734544854Z",[3562,3564],{"type":924,"score":3563},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",{"type":965,"score":3565},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3567,3569,3571,3573,3575,3576,3578,3580],{"type":928,"url":3568},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2149",{"type":939,"url":3570},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147818",{"type":939,"url":3572},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147818#issue-2877301660",{"type":939,"url":3574},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-190.yaml",{"type":936,"url":1077},{"type":939,"url":3577},"https:\u002F\u002Fvuldb.com\u002F?ctiid.299060",{"type":939,"url":3579},"https:\u002F\u002Fvuldb.com\u002F?id.299060",{"type":939,"url":3581},"https:\u002F\u002Fvuldb.com\u002F?submit.506563",[1089,1090],{"id":200,"slug":3584,"dossier":47,"summary":3585,"aliases":3586,"sourceIds":3590,"published":3591,"modified":3592,"checkedAt":7,"severity":3593,"references":3595,"versionKeys":3609,"packageCount":32,"repositoryCount":34},"ghsa-xg8h-j46f-w952-da36a616","Pillow vulnerability can cause write buffer overflow on BCn encoding",[3587,3588,3589],"BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61",[200,3589],"2025-07-01T17:29:37Z","2026-09-10T03:50:26.431657121Z",[3594],{"type":924,"score":1621},[3596,3598,3600,3602,3604,3606,3607],{"type":928,"url":3597},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-xg8h-j46f-w952",{"type":928,"url":3599},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-48379",{"type":939,"url":3601},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9041",{"type":933,"url":3603},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fef98b3510e3e4f14b547762764813d7e5ca3c5a4",{"type":939,"url":3605},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2025-61.yaml",{"type":936,"url":1247},{"type":939,"url":3608},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F11.3.0",[1254],{"id":201,"slug":3611,"dossier":90,"summary":3612,"aliases":3613,"sourceIds":3617,"published":3618,"modified":3619,"checkedAt":7,"severity":3620,"references":3623,"versionKeys":3634,"packageCount":32,"repositoryCount":1260},"ghsa-xj96-63gp-2gmr-85e1cf15","Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`",[3614,3615,3616],"BIT-pillow-2026-59197","CVE-2026-59197","PYSEC-2026-3454",[201,3616],"2026-07-14T17:17:14.487Z","2026-09-10T03:50:53.192759645Z",[3621],{"type":924,"score":3622},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:H",[3624,3626,3628,3630,3632,3633],{"type":971,"url":3625},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-xj96-63gp-2gmr",{"type":928,"url":3627},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59197",{"type":933,"url":3629},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9695",{"type":933,"url":3631},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fcce3bdb867c77a3420261ed1bfdb6b0787ec8fc1",{"type":936,"url":1247},{"type":928,"url":1523},[1251,1252,1253,1254,1255,1256,1257,1258,1259],{"id":202,"slug":3636,"dossier":47,"summary":83,"aliases":3637,"sourceIds":3640,"published":3641,"modified":3642,"checkedAt":7,"severity":3643,"references":3646,"versionKeys":3655,"packageCount":32,"repositoryCount":32},"pysec-2025-112-653e8a7c",[3638,3639],"CVE-2025-64429","GHSA-vmp8-hg63-v2hp",[202],"2025-11-12T22:15:49.813Z","2026-05-20T09:18:59.601738Z",[3644],{"type":924,"score":3645},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[3647,3649,3651,3653],{"type":939,"url":3648},"https:\u002F\u002Fgithub.com\u002Fduckdb\u002Fduckdb\u002Fblob\u002F029a5b87ff5b1cd22f7f9717d48cd8830d00807c\u002Fsrc\u002Fcommon\u002Frandom_engine.cpp#L20",{"type":928,"url":3650},"https:\u002F\u002Fduckdb.org\u002F2025\u002F09\u002F16\u002Fannouncing-duckdb-140.html",{"type":928,"url":3652},"https:\u002F\u002Fgithub.com\u002Fduckdb\u002Fduckdb\u002Fsecurity\u002Fadvisories\u002FGHSA-vmp8-hg63-v2hp",{"type":933,"url":3654},"https:\u002F\u002Fgithub.com\u002Fduckdb\u002Fduckdb\u002Fpull\u002F17275",[3656],"pypi:duckdb@1.4.1",{"id":203,"slug":3658,"dossier":47,"summary":83,"aliases":3659,"sourceIds":3662,"published":3663,"modified":3664,"checkedAt":7,"severity":3665,"references":3667,"versionKeys":3676,"packageCount":32,"repositoryCount":103},"pysec-2025-198-62b25ed4",[3660,3661],"BIT-pytorch-2025-46148","CVE-2025-46148",[203],"2025-09-25T15:16:12.007Z","2026-05-20T09:19:19.437232Z",[3666],{"type":924,"score":2959},[3668,3670,3672,3674],{"type":928,"url":3669},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F4bcefba4004f8271e64b5185c95a248a",{"type":928,"url":3671},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F65a587a579dfdff887b9b35bb79b9093",{"type":1070,"url":3673},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151198",{"type":933,"url":3675},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F152993",[1089,1090],{"id":204,"slug":3678,"dossier":47,"summary":83,"aliases":3679,"sourceIds":3682,"published":3683,"modified":3684,"checkedAt":7,"severity":3685,"references":3687,"versionKeys":3693,"packageCount":32,"repositoryCount":32},"pysec-2025-199-c528cb5a",[3680,3681],"BIT-pytorch-2025-46149","CVE-2025-46149",[204],"2025-09-25T15:16:12.153Z","2026-05-20T09:19:19.498677Z",[3686],{"type":924,"score":2959},[3688,3689,3691],{"type":928,"url":3669},{"type":1070,"url":3690},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147848",{"type":933,"url":3692},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F147961",[1090],{"id":205,"slug":3695,"dossier":47,"summary":83,"aliases":3696,"sourceIds":3699,"published":3700,"modified":3701,"checkedAt":7,"severity":3702,"references":3704,"versionKeys":3712,"packageCount":32,"repositoryCount":32},"pysec-2025-200-d11172cd",[3697,3698],"BIT-pytorch-2025-46150","CVE-2025-46150",[205],"2025-09-25T15:16:12.303Z","2026-05-20T09:19:19.559970Z",[3703],{"type":924,"score":2959},[3705,3706,3708,3710],{"type":928,"url":3669},{"type":1070,"url":3707},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F141538",{"type":1070,"url":3709},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F141538#issuecomment-2537424658",{"type":933,"url":3711},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F144395",[1090],{"id":206,"slug":3714,"dossier":47,"summary":83,"aliases":3715,"sourceIds":3718,"published":3719,"modified":3720,"checkedAt":7,"severity":3721,"references":3723,"versionKeys":3729,"packageCount":32,"repositoryCount":32},"pysec-2025-201-c002b022",[3716,3717],"BIT-pytorch-2025-46152","CVE-2025-46152",[206],"2025-09-25T15:16:12.470Z","2026-05-20T09:19:19.618679Z",[3722],{"type":924,"score":1540},[3724,3725,3727],{"type":928,"url":3669},{"type":1070,"url":3726},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F143555",{"type":933,"url":3728},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F143635",[1090],{"id":207,"slug":3731,"dossier":47,"summary":83,"aliases":3732,"sourceIds":3735,"published":3736,"modified":3737,"checkedAt":7,"severity":3738,"references":3740,"versionKeys":3750,"packageCount":32,"repositoryCount":32},"pysec-2025-202-f0ff1751",[3733,3734],"BIT-pytorch-2025-46153","CVE-2025-46153",[207],"2025-09-25T15:16:12.603Z","2026-05-20T09:19:19.678555Z",[3739],{"type":924,"score":2959},[3741,3743,3744,3746,3748],{"type":939,"url":3742},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcompare\u002Fv2.6.0...v2.7.0",{"type":928,"url":3669},{"type":928,"url":3745},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002Fe636f2e7a306105b7e96809e2b85c28a",{"type":1070,"url":3747},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F142853",{"type":933,"url":3749},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F143460",[1090],{"id":208,"slug":3752,"dossier":47,"summary":83,"aliases":3753,"sourceIds":3756,"published":3757,"modified":3758,"checkedAt":7,"severity":3759,"references":3761,"versionKeys":3766,"packageCount":32,"repositoryCount":66},"pysec-2025-203-2febb201",[3754,3755],"BIT-pytorch-2025-55551","CVE-2025-55551",[208],"2025-09-25T15:16:12.887Z","2026-05-20T09:19:19.739357Z",[3760],{"type":924,"score":1103},[3762,3764],{"type":928,"url":3763},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F0e7d2a586297ae9c8ed14d8706749efc",{"type":1070,"url":3765},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151401",[1089,1090,1091,1850,1851,3002],{"id":209,"slug":3768,"dossier":47,"summary":83,"aliases":3769,"sourceIds":3772,"published":3773,"modified":3774,"checkedAt":7,"severity":3775,"references":3777,"versionKeys":3781,"packageCount":32,"repositoryCount":66},"pysec-2025-204-cdae47da",[3770,3771],"BIT-pytorch-2025-55552","CVE-2025-55552",[209],"2025-09-25T16:15:34.320Z","2026-05-20T09:19:19.802802Z",[3776],{"type":924,"score":1103},[3778,3779],{"type":928,"url":3763},{"type":1070,"url":3780},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147847",[1089,1090,1091,1850,1851,3002],{"id":210,"slug":3783,"dossier":47,"summary":83,"aliases":3784,"sourceIds":3787,"published":3788,"modified":3789,"checkedAt":7,"severity":3790,"references":3792,"versionKeys":3798,"packageCount":32,"repositoryCount":303},"pysec-2025-205-fd5e58fd",[3785,3786],"BIT-pytorch-2025-55553","CVE-2025-55553",[210],"2025-09-25T16:15:34.460Z","2026-05-20T09:19:19.866970Z",[3791],{"type":924,"score":1103},[3793,3794,3796],{"type":928,"url":3763},{"type":1070,"url":3795},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151432",{"type":933,"url":3797},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F154645",[1089,1090,1091],{"id":211,"slug":3800,"dossier":47,"summary":83,"aliases":3801,"sourceIds":3804,"published":3805,"modified":3806,"checkedAt":7,"severity":3807,"references":3809,"versionKeys":3813,"packageCount":32,"repositoryCount":66},"pysec-2025-206-58322476",[3802,3803],"BIT-pytorch-2025-55554","CVE-2025-55554",[211],"2025-09-25T16:15:34.593Z","2026-05-20T09:19:19.928295Z",[3808],{"type":924,"score":1540},[3810,3811],{"type":928,"url":3763},{"type":1070,"url":3812},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151510",[1089,1090,1091,1850,1851,3002],{"id":212,"slug":3815,"dossier":47,"summary":83,"aliases":3816,"sourceIds":3819,"published":3820,"modified":3821,"checkedAt":7,"severity":3822,"references":3824,"versionKeys":3830,"packageCount":32,"repositoryCount":303},"pysec-2025-207-2abef3fc",[3817,3818],"BIT-pytorch-2025-55557","CVE-2025-55557",[212],"2025-09-25T16:15:34.833Z","2026-05-20T09:19:19.989717Z",[3823],{"type":924,"score":1103},[3825,3826,3828],{"type":928,"url":3763},{"type":1070,"url":3827},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151738",{"type":933,"url":3829},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151931",[1089,1090,1091],{"id":213,"slug":3832,"dossier":47,"summary":83,"aliases":3833,"sourceIds":3836,"published":3837,"modified":3838,"checkedAt":7,"severity":3839,"references":3841,"versionKeys":3847,"packageCount":32,"repositoryCount":303},"pysec-2025-208-6e93fe9d",[3834,3835],"BIT-pytorch-2025-55558","CVE-2025-55558",[213],"2025-09-25T16:15:34.960Z","2026-05-20T09:19:20.054109Z",[3840],{"type":924,"score":1103},[3842,3843,3845],{"type":928,"url":3763},{"type":1070,"url":3844},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151523",{"type":933,"url":3846},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151887",[1089,1090,1091],{"id":214,"slug":3849,"dossier":47,"summary":83,"aliases":3850,"sourceIds":3853,"published":3854,"modified":3855,"checkedAt":7,"severity":3856,"references":3858,"versionKeys":3864,"packageCount":32,"repositoryCount":303},"pysec-2025-209-e6f352b0",[3851,3852],"BIT-pytorch-2025-55560","CVE-2025-55560",[214],"2025-09-25T16:15:35.197Z","2026-05-20T09:19:20.117285Z",[3857],{"type":924,"score":1103},[3859,3860,3862],{"type":928,"url":3763},{"type":1070,"url":3861},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151522",{"type":933,"url":3863},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151897",[1089,1090,1091],{"id":215,"slug":3866,"dossier":47,"summary":83,"aliases":3867,"sourceIds":3870,"published":3871,"modified":3872,"checkedAt":7,"severity":3873,"references":3875,"versionKeys":3886,"packageCount":32,"repositoryCount":3887},"pysec-2026-139-96951ff6",[3868,3869],"BIT-pytorch-2026-4538","CVE-2026-4538",[215],"2026-03-22T05:16:20.273Z","2026-05-21T15:00:31.962442644Z",[3874],{"type":924,"score":1648},[3876,3878,3880,3882,3884],{"type":939,"url":3877},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002F",{"type":928,"url":3879},"https:\u002F\u002Fvuldb.com\u002F?id.352326",{"type":928,"url":3881},"https:\u002F\u002Fvuldb.com\u002F?submit.774681",{"type":1070,"url":3883},"https:\u002F\u002Fvuldb.com\u002F?ctiid.352326",{"type":933,"url":3885},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F176791",[3197,1089,1090,1091,1850,1851,3002,3003,3004,3005],14,{"id":216,"slug":3889,"dossier":90,"summary":83,"aliases":3890,"sourceIds":3893,"published":3894,"modified":3895,"checkedAt":7,"severity":3896,"references":3899,"versionKeys":3914,"packageCount":32,"repositoryCount":1260},"pysec-2026-2132-627bf7c7",[3891,3892],"CVE-2026-7246","GHSA-47fr-3ffg-hgmw",[216],"2026-04-30T14:16:36.433Z","2026-07-13T07:15:21.899333658Z",[3897],{"type":924,"score":3898},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[3900,3902,3904,3906,3908,3910,3912],{"type":939,"url":3901},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-7246",{"type":939,"url":3903},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-7246.json",{"type":928,"url":3905},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24761",{"type":928,"url":3907},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24762",{"type":1070,"url":3909},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2464121",{"type":933,"url":3911},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fclick\u002Freleases\u002Ftag\u002F8.3.3",{"type":971,"url":3913},"https:\u002F\u002Fgithub.com\u002Ftsigouris007\u002Fsecurity-advisories\u002Fsecurity\u002Fadvisories\u002FGHSA-47fr-3ffg-hgmw",[3915,3916,3917,3918,3919,3920],"pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1",{"id":217,"slug":3922,"dossier":47,"summary":83,"aliases":3923,"sourceIds":3928,"published":3929,"modified":3930,"checkedAt":7,"severity":3931,"references":3933,"versionKeys":3950,"packageCount":32,"repositoryCount":272},"pysec-2026-2286-8795b007",[3924,3925,3926,3927],"BIT-pytorch-2026-24747","CVE-2026-24747","GHSA-63cw-57p8-fm3p","PYSEC-2026-1856",[217],"2026-01-27T22:15:56.470Z","2026-07-13T07:26:23.701611780Z",[3932],{"type":924,"score":2288},[3934,3936,3938,3940,3942,3944,3946,3948],{"type":939,"url":3935},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-24747",{"type":939,"url":3937},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-24747.json",{"type":928,"url":3939},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24977",{"type":928,"url":3941},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Freleases\u002Ftag\u002Fv2.10.0",{"type":928,"url":3943},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fsecurity\u002Fadvisories\u002FGHSA-63cw-57p8-fm3p",{"type":1070,"url":3945},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2433612",{"type":1070,"url":3947},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F163105",{"type":933,"url":3949},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002F163122\u002Fcommit\u002F954dc5183ee9205cbe79876ad05dd2d9ae752139",[1089,1090,1091,1850,1851,3002,3003,3004,3005],1789534491841]