uba-ki-lab/ressource-efficient-computer-visionThis dossier retains 244 exact component occurrences from 3 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:5ae12d5615c84d40c25d23a8c2e2306ea5f3f1f75a14a27e1c36426ce966c99fsha256:e2f86442aaca182ff71abf8a0d916c515193ed063af29d024bd5365c66c3aa2cpypi:transformers4.57.426 OSV records returnedpypi:torch2.7.1+cpu · 2.9.123 OSV records returnedpypi:scikit-learn1.8.01 OSV record returnedpypi:codecarbon3.2.1pypi:tokenizers0.22.2pypi:opencv-python4.11.0.86pypi:ultralytics8.3.252pypi:gitpython3.1.4629 OSV records returnedpypi:mlflow3.8.126 OSV records returnedpypi:pillow12.1.020 OSV records returnedpypi:tornado6.5.413 OSV records returnedpypi:cryptography46.0.39 OSV records returnedpypi:starlette0.50.08 OSV records returnedpypi:urllib32.6.37 OSV records returnedpypi:sqlparse0.5.56 OSV records returnedpypi:werkzeug3.1.56 OSV records returnedpypi:flask-cors6.0.25 OSV records returnedpypi:pyasn10.6.15 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:pymdown-extensions10.21.23 OSV records returnedpypi:requests2.32.53 OSV records returnedpypi:setuptools80.9.03 OSV records returnedpypi:anyio4.12.12 OSV records returnedpypi:filelock3.20.32 OSV records returnedpypi:mako1.3.102 OSV records returnedpypi:protobuf6.33.42 OSV records returnedpypi:streamlit1.55.02 OSV records returnedpypi:certifi2026.1.41 OSV record returnedpypi:click8.3.11 OSV record returnedpypi:flask3.1.21 OSV record returnedpypi:fonttools4.61.11 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:hydra-core1.3.21 OSV record returnedpypi:idna3.111 OSV record returnedpypi:jupyter-core5.9.11 OSV record returnedpypi:jwcrypto1.5.61 OSV record returnedpypi:marimo0.23.41 OSV record returnedpypi:markdown3.101 OSV record returnedpypi:pyarrow22.0.01 OSV record returnedpypi:pygments2.19.21 OSV record returnedpypi:pytest9.0.21 OSV record returnedpypi:python-dotenv1.2.11 OSV record returnedpypi:tqdm4.67.11 OSV record returnedpypi:absl-py2.3.1pypi:addict2.4.0pypi:albucore0.0.24pypi:albumentations2.0.8pypi:alembic1.18.0pypi:altair6.0.0pypi:annotated-doc0.0.4pypi:annotated-types0.7.0pypi:antlr4-python3-runtime4.9.3pypi:appnope0.1.4pypi:arrow1.4.0pypi:asttokens3.0.1pypi:attrs25.4.0pypi:autograd1.8.0pypi:blinker1.9.0pypi:cachetools6.2.4pypi:cffi2.0.0pypi:charset-normalizer3.4.4pypi:cloudpickle3.1.2pypi:colorama0.4.6pypi:colorlog6.10.1pypi:comm0.2.3pypi:contourpy1.3.3pypi:cycler0.12.1pypi:databricks-sdk0.77.0pypi:debugpy1.8.19pypi:decorator5.2.1pypi:docker7.1.0pypi:docutils0.22.4pypi:escnn1.0.11pypi:executing2.2.1pypi:fastapi0.128.0pypi:fief-client0.20.0pypi:fsspec2026.1.0pypi:gitdb4.0.12pypi:google-auth2.47.0pypi:graphene3.4.3pypi:graphql-core3.2.7pypi:graphql-relay3.2.0pypi:greenlet3.3.0pypi:groundingdino-py0.4.0pypi:grpcio1.76.0pypi:gunicorn23.0.0pypi:hf-xet1.2.0pypi:httpcore1.0.9pypi:httpx0.27.2pypi:huey2.6.0pypi:huggingface-hub0.36.0pypi:imageio2.37.2pypi:importlib-metadata8.7.1pypi:iniconfig2.3.0pypi:ipykernel7.1.0pypi:ipython9.9.0pypi:ipython-pygments-lexers1.1.1pypi:ipywidgets8.1.8pypi:itsdangerous2.2.0pypi:jedi0.19.2pypi:joblib1.5.3pypi:jsonschema4.26.0pypi:jsonschema-specifications2025.9.1pypi:jupyter-client8.8.0pypi:jupyterlab-widgets3.0.16pypi:jwt1.4.0pypi:kiwisolver1.4.9pypi:lazy-loader0.4pypi:lie-learn0.0.2pypi:lightning-utilities0.15.2pypi:loro1.10.3pypi:markdown-it-py4.0.0pypi:markupsafe3.0.3pypi:matplotlib3.10.8pypi:matplotlib-inline0.2.1pypi:mdurl0.1.2pypi:mlflow-skinny3.8.1pypi:mlflow-tracing3.8.1pypi:mpmath1.3.0pypi:msgspec0.21.1This page displays 120 of 227 ordered rows. The machine-readable dossier retains the complete exact projection.
Certifi removes GLOBALTRUST root certificate
10 Sept 2026sqlparse: formatting list of tuples leads to denial of service
10 Sept 2026GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
08 Sept 2026HuggingFace transformers vulnerable to remote code execution
10 Sept 2026Werkzeug safe_join() allows Windows special device names
10 Sept 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10 Sept 2026MLflow: trace API endpoints lack proper authorization validators
19 Aug 2026Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
10 Sept 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
23 Sept 2026Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
10 Sept 2026Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
25 Sept 2026Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
10 Sept 2026sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
10 Sept 2026PyTorch susceptible to local Denial of Service
10 Sept 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
10 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
10 Sept 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
17 Sept 2026GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
23 Sept 2026Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
10 Sept 2026MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
13 Jul 2026Flask-CORS vulnerable to Improper Handling of Case Sensitivity
10 Sept 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10 Sept 2026MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
10 Sept 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
10 Sept 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10 Sept 2026mlflow Creates of Temporary File in Directory with Insecure Permissions
10 Sept 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
10 Sept 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07 Aug 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
10 Sept 2026AnyIO process-pool workers can block indefinitely on undrained stderr
18 Sept 2026MLflow: Deterministic sampling in dataset digest enables predictable collisions
23 Jul 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10 Sept 2026Python-Markdown has an Uncaught Exception
10 Sept 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10 Sept 2026Pillow has a heap buffer overflow with nested list coordinates
10 Sept 2026GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
08 Sept 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10 Sept 2026Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
10 Sept 2026pyasn1 has a DoS vulnerability in decoder
10 Sept 2026MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
13 Jul 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10 Sept 2026Flask session does not add `Vary: Cookie` header when accessed in some ways
10 Sept 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): Ressource Efficient Computer Vision — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-10775/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.