uba-ki-lab/llm-questionnaire-benchmarking-frameworkThis dossier retains 241 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:e0cfb7dbb1f83b9adb3c422816068eefba3a17e5146d084022722da579e14760pypi:vllm0.10.1.139 OSV records returnedpypi:transformers4.57.625 OSV records returnedpypi:torch2.7.123 OSV records returnedpypi:openai1.104.2pypi:tokenizers0.22.0pypi:scikit-learn1.7.1pypi:tiktoken0.11.0pypi:aiohttp3.12.1533 OSV records returnedpypi:mlflow3.4.023 OSV records returnedpypi:gitpython3.1.4522 OSV records returnedpypi:pillow11.3.020 OSV records returnedpypi:authlib1.6.49 OSV records returnedpypi:cryptography45.0.79 OSV records returnedpypi:fastmcp2.12.38 OSV records returnedpypi:python-multipart0.0.208 OSV records returnedpypi:starlette0.47.38 OSV records returnedpypi:urllib32.5.07 OSV records returnedpypi:ray2.49.16 OSV records returnedpypi:werkzeug3.1.16 OSV records returnedpypi:pyasn10.6.15 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:cbor25.7.03 OSV records returnedpypi:mcp1.14.13 OSV records returnedpypi:requests2.32.53 OSV records returnedpypi:setuptools79.0.13 OSV records returnedpypi:filelock3.19.12 OSV records returnedpypi:mako1.3.102 OSV records returnedpypi:mlx0.29.02 OSV records returnedpypi:protobuf6.32.02 OSV records returnedpypi:xgrammar0.1.212 OSV records returnedpypi:certifi2025.8.31 OSV record returnedpypi:click8.2.11 OSV record returnedpypi:diskcache5.6.31 OSV record returnedpypi:flask3.1.21 OSV record returnedpypi:fonttools4.59.21 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.101 OSV record returnedpypi:msgpack1.1.11 OSV record returnedpypi:pyarrow21.0.01 OSV record returnedpypi:pydantic-settings2.10.11 OSV record returnedpypi:pygments2.19.21 OSV record returnedpypi:python-dotenv1.1.11 OSV record returnedpypi:sentencepiece0.2.11 OSV record returnedpypi:sqlparse0.5.31 OSV record returnedpypi:tqdm4.67.11 OSV record returnedpypi:virtualenv20.34.01 OSV record returnedpypi:aiohappyeyeballs2.6.1pypi:aiohttp-cors0.8.1pypi:aiosignal1.4.0pypi:alembic1.16.5pypi:annotated-types0.7.0pypi:antlr4-python3-runtime4.9.3pypi:anyio4.10.0pypi:astor0.8.1pypi:attrs25.3.0pypi:blake31.0.5pypi:blinker1.9.0pypi:cachetools5.5.2pypi:cffi1.17.1pypi:charset-normalizer3.4.3pypi:cloudpickle3.1.1pypi:colorama0.4.6pypi:colorful0.5.7pypi:compressed-tensors0.10.2pypi:contourpy1.3.3pypi:cupy-cuda12x13.6.0pypi:cycler0.12.1pypi:cyclopts3.24.0pypi:databricks-sdk0.65.0pypi:depyf0.19.0pypi:dill0.4.0pypi:distlib0.4.0pypi:distro1.9.0pypi:dnspython2.7.0pypi:docker7.1.0pypi:docstring-parser0.17.0pypi:docutils0.22.1pypi:einops0.8.1pypi:email-validator2.3.0pypi:et-xmlfile2.0.0pypi:exceptiongroup1.3.0pypi:fastapi0.116.1pypi:fastapi-cli0.0.10pypi:fastapi-cloud-cli0.1.5pypi:fastrlock0.8.3pypi:frozenlist1.7.0pypi:fsspec2025.9.0pypi:gguf0.17.1pypi:gitdb4.0.12pypi:google-api-core2.25.1pypi:google-auth2.40.3pypi:googleapis-common-protos1.70.0pypi:graphene3.4.3pypi:graphql-core3.2.6pypi:graphql-relay3.2.0pypi:greenlet3.2.4pypi:grpcio1.74.0pypi:gunicorn23.0.0pypi:hf-xet1.1.9pypi:httpcore1.0.9pypi:httptools0.6.4pypi:httpx0.28.1pypi:httpx-sse0.4.1pypi:huggingface-hub0.34.4pypi:hydra-core1.3.2pypi:importlib-metadata8.7.0pypi:inquirerpy0.3.4pypi:interegular0.3.3pypi:isodate0.7.2pypi:itsdangerous2.2.0pypi:jiter0.10.0pypi:joblib1.5.2pypi:jsonschema4.25.1pypi:jsonschema-path0.3.4pypi:jsonschema-specifications2025.4.1pypi:kiwisolver1.4.9pypi:lark1.2.2pypi:lazy-object-proxy1.12.0pypi:llguidance0.7.30pypi:llvmlite0.44.0This page displays 120 of 241 ordered rows. The machine-readable dossier retains the complete exact projection.
Certifi removes GLOBALTRUST root certificate
10 Jun 2026sqlparse: formatting list of tuples leads to denial of service
19 Feb 2026HuggingFace transformers vulnerable to remote code execution
13 Jul 2026Werkzeug safe_join() allows Windows special device names
13 Jul 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
07 Jul 2026GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
02 Aug 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
13 Jul 2026Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
07 Jul 2026Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
13 Jul 2026vLLM affected by RCE via auto_map dynamic module loading during model initialization
07 Aug 2026AIOHTTP has CRLF injection through multipart part content type header construction
13 Jul 2026urllib3 streaming API improperly handles highly compressed data
07 Jul 2026PyTorch susceptible to local Denial of Service
10 Jun 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
07 Jul 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul 2026Sentencepiece has a a heap overflow issue
07 Jul 2026cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads
13 Jul 2026vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
07 Jul 2026GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
08 Aug 2026vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
17 Jul 2026GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
04 Aug 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
13 Jul 2026vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
17 Jul 2026MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
13 Jul 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22 Jul 2026MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
10 Jun 2026urllib3 does not control redirects in browsers and Node.js
07 Jul 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
13 Jul 2026GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
09 Aug 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
27 Jun 2026Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
07 Aug 2026vLLM has RCE In Video Processing
17 Jul 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
07 Jul 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22 Jul 2026mlflow Creates of Temporary File in Directory with Insecure Permissions
07 Jul 2026pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
08 Jul 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
13 Jul 2026Vulnerable OpenSSL included in cryptography wheels
16 Jun 2026GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
08 Aug 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07 Aug 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
07 Jul 2026virtualenv Has TOCTOU Vulnerabilities in Directory Creation
07 Jul 2026Denial of service (DoS) via deformation `multipart/form-data` boundary
07 Jul 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
07 Jul 2026XGrammar affected by Denial of Service by infinite recursion grammars
07 Aug 2026FastMCP OAuth Proxy token reuse across MCP servers
13 Jul 2026vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
17 Jul 2026MLflow: Deterministic sampling in dataset digest enables predictable collisions
23 Jul 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): LLM Questionnaire Benchmarking Framework — exact AI dependency evidence dossier, data state 12 Aug 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-10787/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.