[{"data":1,"prerenderedAt":5097},["ShallowReactive",2],{"ki-abhaengigkeitsatlas-repository-opencode-11298":3},{"schemaVersion":4,"dataset":5,"parserVersion":6,"generatedAt":7,"trackingSince":8,"source":9,"coverage":29,"methodology":43,"summary":62,"kind":76,"entity":77,"evidence":252,"related":255},"ki-abhaengigkeitsatlas\u002Fv1","german-public-sector-ai-dependency-atlas","1","2026-09-30T08:36:30.871Z","2026-07-18T21:20:30.334Z",{"codeRadar":10,"openCode":15,"depsDev":18,"osv":21,"spdx":24},{"dataset":11,"generatedAt":12,"parserVersion":13,"url":14},"german-public-sector-ai-code-radar","2026-09-30T08:33:18.305Z","3","https:\u002F\u002Fi6eal.de\u002Ftools\u002Fki-code-radar\u002F",{"label":16,"url":17},"openCode GitLab","https:\u002F\u002Fgitlab.opencode.de\u002F",{"label":19,"url":20},"deps.dev API v3","https:\u002F\u002Fdocs.deps.dev\u002Fapi\u002Fv3\u002F",{"label":22,"url":23},"OSV API","https:\u002F\u002Fgoogle.github.io\u002Fosv.dev\u002Fapi\u002F",{"label":25,"url":26,"version":27,"releaseDate":28},"SPDX License List","https:\u002F\u002Fspdx.org\u002Flicenses\u002F","3.29.0","2026-09-16T00:00:00Z",{"repositoryCount":30,"completeTreeCount":31,"incompleteTreeCount":32,"lockfileRepositoryCount":33,"sbomRepositoryCount":34,"artifactRepositoryCount":35,"resolvedRepositoryCount":36,"resolvedArtifactRepositoryCount":35,"dependencyFileCount":37,"parsedFileCount":38,"parseErrorCount":32,"unsupportedFileCount":39,"evaluatedVersionCount":40,"metadataResolvedCount":41,"metadataNotFoundCount":42,"osvEvaluatedVersionCount":40,"codeRadarRepositoryCount":30},43,42,1,23,4,26,40,38,37,0,4104,4093,11,{"componentParserSchemaVersion":44,"candidateBoundary":45,"resolvedVersionBoundary":46,"manifestRangesResolved":47,"latestVersionSubstitution":47,"containerTagsVulnerabilityChecked":47,"osvClaim":48,"depsDevLicenseSemantics":49,"providerSemantics":50,"generativeAiUsed":47,"scoreUsed":47,"treeEntryCeiling":51,"fileByteCeiling":52,"uniqueVersionCeiling":53,"observedFormats":54},"ki-dependency-atlas-components\u002Fv1","repositories_with_exact_ai_code_evidence","exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin",false,"osv_matched_observed_resolved_package_version_at_collection_time","spdx_expressions_as_reported_without_inferred_compatibility","package_interface_presence_not_api_configuration_procurement_or_use",2500,5242880,8000,[55,56,57,58,59,60,61],"package-lock.json \u002F npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins",{"repositoryCount":30,"packageCount":63,"aiPackageCount":64,"resolvedComponentCount":65,"resolvedVersionCount":40,"providerExposureRepositoryCount":66,"licenseExpressionCount":67,"knownLicensePackageCount":68,"unknownLicensePackageCount":69,"advisoryCount":70,"matchedAdvisoryRepositoryCount":38,"topPackage":71},2460,50,7146,9,55,2426,34,822,{"id":72,"slug":73,"label":74,"repositoryCount":33,"repositoryShare":75},"package:pypi:openai","openai-0dd26ac5","OpenAI SDK",0.5348837209302325,"repository",{"id":78,"slug":79,"gitlabProjectId":80,"name":81,"pathWithNamespace":82,"description":83,"webUrl":84,"commitSha":85,"commitUrl":86,"lastActivityAt":87,"headCommittedAt":88,"tree":89,"files":92,"resolvedComponentCount":100,"artifactResolvedComponentCount":100,"exactManifestPinCount":39,"packageCount":100,"ecosystems":101,"aiPackageCount":103,"licenseExpressionCount":104,"unknownLicensePackageCount":32,"advisoryIds":105,"advisoryCount":250,"providers":251},"opencode:11298","opencode-11298",11298,"URBAN.KI Sovia","vernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia",null,"https:\u002F\u002Fgitlab.opencode.de\u002Fvernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia","b961d043e77a4561b9f77c65c6818627c1f34c22","https:\u002F\u002Fgitlab.opencode.de\u002Fvernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia\u002F-\u002Fcommit\u002Fb961d043e77a4561b9f77c65c6818627c1f34c22","2026-09-15T13:10:29.040Z","2026-09-14T08:20:12.000Z",{"complete":90,"entryCount":91,"truncated":47},true,70,[93],{"path":56,"kind":94,"blobSha":95,"sourceUrl":96,"commitSha":85,"contentSha256":97,"byteCount":98,"state":99,"componentCount":100},"uv-lock","ddc57ad0a634363d7ebefcbde0786b734f6f5f81","https:\u002F\u002Fgitlab.opencode.de\u002Fvernetzte-stadt-gelsenkirchen\u002Furban.ki\u002Furban-ki-sovia\u002F-\u002Fblob\u002Fb961d043e77a4561b9f77c65c6818627c1f34c22\u002Fuv.lock","d444dfad7ad27a1821923a1fc11b3ae40b7e686a1c28dd4b750c45fa1cfa35b8",270188,"parsed",111,[102],"pypi",6,15,[106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249],"GHSA-248v-346w-9cwc","GHSA-284h-m62q-gf8w","GHSA-29pf-2h5f-8g72","GHSA-2f96-g7mh-g2hx","GHSA-2xpw-w6gg-jr37","GHSA-3749-ghw9-m3mg","GHSA-37mw-44qp-f5jm","GHSA-38jv-5279-wg99","GHSA-3f7w-8rr8-f37f","GHSA-3rp5-jjmw-4wv2","GHSA-3wxw-xv34-2frg","GHSA-3x9g-8vmp-wqvf","GHSA-45hq-cxwh-f6vc","GHSA-48p4-8xcf-vxj5","GHSA-4gmw-gg2m-w46p","GHSA-4w7r-h757-3r74","GHSA-4x4j-2g7c-83w6","GHSA-5239-wwwm-4pmq","GHSA-539m-9xh6-q6rr","GHSA-53q9-r3pm-6pq6","GHSA-59p9-h35m-wg4g","GHSA-5rjg-fvgr-3xxf","GHSA-5x94-69rx-g8h2","GHSA-5xmw-vc9v-4wf2","GHSA-5xxx-qhh7-9287","GHSA-62p4-gmf7-7g93","GHSA-6497-prx7-gpmq","GHSA-65pc-fj4g-8rjx","GHSA-69w3-r845-3855","GHSA-6p8h-3wgx-97gf","GHSA-6r8x-57c9-28j4","GHSA-6rvg-6v2m-4j46","GHSA-7545-fcxq-7j24","GHSA-768j-98cg-p3fv","GHSA-7833-fr7j-v32q","GHSA-78cv-mqj4-43f7","GHSA-7cx3-6m66-7c5m","GHSA-7gcm-g887-7qv7","GHSA-7p48-42j8-8846","GHSA-8423-8fgw-73vq","GHSA-887c-mr87-cxwp","GHSA-8mcc-hrx5-hvxc","GHSA-8qvm-5x2c-j2w7","GHSA-8v84-f9pq-wr9x","GHSA-9356-575x-2w9m","GHSA-94p4-4cq8-9g67","GHSA-956x-8gvw-wg5v","GHSA-9hjg-9r4m-mvj7","GHSA-9hw9-ch79-4vh6","GHSA-9rj7-rf2p-w77r","GHSA-9wx4-h78v-vm56","GHSA-c678-jfcj-6jmf","GHSA-c98p-7wgm-6p64","GHSA-cfh3-3jmp-rvhc","GHSA-cpwx-vrp4-4pq7","GHSA-cx3h-4qpv-8hc9","GHSA-cx63-2mw6-8hw5","GHSA-f4hp-rmr7-r7v8","GHSA-fgcw-684q-jj6r","GHSA-fj7v-r99m-22gq","GHSA-fjr4-x663-mwxc","GHSA-fpwr-67px-3qhx","GHSA-g7vv-2v7x-gj9p","GHSA-gc5v-m9x4-r6x2","GHSA-gm62-xv2j-4w53","GHSA-gmj6-6f8f-6699","GHSA-h35f-9h28-mq5c","GHSA-h75v-3vvj-5mfj","GHSA-hh9p-6wh2-4mfc","GHSA-hmq2-w58f-27jc","GHSA-hxxf-235m-72v3","GHSA-jhmp-mqwm-3gq8","GHSA-jjj6-mw9f-p565","GHSA-jjph-296x-mrcr","GHSA-jm78-9fvv-mhgr","GHSA-jw8x-6495-233v","GHSA-mf9v-mfxr-j63j","GHSA-mgf9-4vpg-hj56","GHSA-mpf4-983q-p7j4","GHSA-mv93-w799-cj2w","GHSA-p538-c434-8v24","GHSA-pg7v-jwj7-p798","GHSA-phhr-52qp-3mj4","GHSA-phj9-mv4w-65pm","GHSA-pq67-6m6q-mj2v","GHSA-pr2v-jx2c-wg9f","GHSA-pw6j-qg29-8w7f","GHSA-pwv6-vv43-88gr","GHSA-q2wp-rjmx-x6x9","GHSA-q2x7-8rv6-6q7h","GHSA-qccp-gfcp-xxvc","GHSA-qfhq-4f3w-5fph","GHSA-qjxf-f2mg-c6mc","GHSA-qmgc-5h2g-mvrw","GHSA-qq3j-4f4f-9583","GHSA-qxrp-vhvm-j765","GHSA-r73j-pqj5-w3x7","GHSA-r9mr-m37c-5fr3","GHSA-rcv9-qm8p-9p6j","GHSA-rgxp-2hwp-jwgg","GHSA-rpm5-65cw-6hj4","GHSA-rrmf-rvhw-rf47","GHSA-rwj8-pgh3-r573","GHSA-v87r-6q3f-2j67","GHSA-vgrw-7cvw-pwgx","GHSA-vjc4-5qp5-m44j","GHSA-vqwp-45wm-r9r5","GHSA-w853-jp5j-5j7f","GHSA-whj4-6x5x-4v2j","GHSA-wjx4-4jcj-g98j","GHSA-wrfc-pvp9-mr9g","GHSA-wvpp-8hx9-p66j","GHSA-wwv5-g3v4-889x","GHSA-x2qx-6953-8485","GHSA-x3gm-94wq-g975","GHSA-xg8h-j46f-w952","GHSA-xj96-63gp-2gmr","GHSA-xrqw-3rrv-vx5w","PYSEC-2025-112","PYSEC-2025-198","PYSEC-2025-199","PYSEC-2025-200","PYSEC-2025-201","PYSEC-2025-202","PYSEC-2025-203","PYSEC-2025-204","PYSEC-2025-205","PYSEC-2025-206","PYSEC-2025-207","PYSEC-2025-208","PYSEC-2025-209","PYSEC-2025-211","PYSEC-2025-212","PYSEC-2025-213","PYSEC-2025-214","PYSEC-2025-215","PYSEC-2025-216","PYSEC-2025-217","PYSEC-2025-218","PYSEC-2026-139","PYSEC-2026-2132","PYSEC-2026-2286","PYSEC-2026-3982","PYSEC-2026-3984",144,[],{"files":253,"occurrenceCount":100},[254],{"path":56,"kind":94,"blobSha":95,"sourceUrl":96,"commitSha":85,"contentSha256":97,"byteCount":98,"state":99,"componentCount":100},{"packages":256,"vulnerabilities":1277},[257,270,280,290,300,309,318,328,340,350,361,370,380,389,400,409,418,428,437,446,455,464,473,482,492,502,511,520,529,538,547,556,565,574,583,592,601,610,619,628,637,646,655,664,673,682,691,700,709,718,727,736,745,754,763,772,782,791,800,809,817,826,835,844,853,862,871,880,889,897,906,915,925,934,943,952,961,970,980,989,998,1007,1016,1025,1034,1043,1052,1061,1071,1080,1089,1098,1107,1116,1125,1134,1142,1151,1160,1169,1178,1187,1196,1205,1214,1223,1232,1242,1250,1259,1268],{"id":258,"slug":259,"identity":260,"label":261,"aiRelevant":90,"provider":262,"advisoryCount":35,"licenseExpressions":265,"versions":267,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":269},"package:pypi:transformers","transformers-65289303","pypi:transformers","Transformers",{"id":263,"label":264},"hugging-face","Hugging Face",[266],"Apache-2.0",[268],"4.51.0",[56],{"id":271,"slug":272,"identity":273,"label":274,"aiRelevant":90,"provider":83,"advisoryCount":33,"licenseExpressions":275,"versions":277,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":279},"package:pypi:torch","torch-47a5352a","pypi:torch","PyTorch",[276],"BSD-3-Clause",[278],"2.9.1",[56],{"id":281,"slug":282,"identity":283,"label":284,"aiRelevant":90,"provider":83,"advisoryCount":32,"licenseExpressions":285,"versions":287,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":289},"package:pypi:scikit-learn","scikit-learn-ab0941d9","pypi:scikit-learn","scikit-learn",[276,286],"non-standard",[288],"1.6.1",[56],{"id":291,"slug":292,"identity":293,"label":294,"aiRelevant":90,"provider":295,"advisoryCount":39,"licenseExpressions":296,"versions":297,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":299},"package:pypi:sentence-transformers","sentence-transformers-3f3d7a36","pypi:sentence-transformers","Sentence Transformers",{"id":263,"label":264},[266],[298],"4.0.2",[56],{"id":301,"slug":302,"identity":303,"label":304,"aiRelevant":90,"provider":83,"advisoryCount":39,"licenseExpressions":305,"versions":306,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":308},"package:pypi:tokenizers","tokenizers-7ba00902","pypi:tokenizers","Hugging Face Tokenizers",[286],[307],"0.21.1",[56],{"id":310,"slug":311,"identity":312,"label":313,"aiRelevant":90,"provider":83,"advisoryCount":39,"licenseExpressions":314,"versions":315,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":317},"package:pypi:opencv-python","opencv-python-bfa06e24","pypi:opencv-python","OpenCV",[266],[316],"4.11.0.86",[56],{"id":319,"slug":320,"identity":321,"label":322,"aiRelevant":47,"provider":83,"advisoryCount":323,"licenseExpressions":324,"versions":325,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":327},"package:pypi:gitpython","gitpython-dcd13009","pypi:gitpython","gitpython",29,[276],[326],"3.1.45",[56],{"id":329,"slug":330,"identity":331,"label":332,"aiRelevant":47,"provider":83,"advisoryCount":333,"licenseExpressions":334,"versions":337,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":339},"package:pypi:pillow","pillow-834347dd","pypi:pillow","pillow",20,[335,336],"HPND","MIT-CMU",[338],"11.1.0",[56],{"id":341,"slug":342,"identity":343,"label":344,"aiRelevant":47,"provider":83,"advisoryCount":345,"licenseExpressions":346,"versions":347,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":349},"package:pypi:tornado","tornado-ab0f364e","pypi:tornado","tornado",13,[266],[348],"6.5.2",[56],{"id":351,"slug":352,"identity":353,"label":354,"aiRelevant":47,"provider":83,"advisoryCount":355,"licenseExpressions":356,"versions":358,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":360},"package:pypi:urllib3","urllib3-fa68f32c","pypi:urllib3","urllib3",7,[357],"MIT",[359],"2.3.0",[56],{"id":362,"slug":363,"identity":364,"label":365,"aiRelevant":47,"provider":83,"advisoryCount":34,"licenseExpressions":366,"versions":367,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":369},"package:pypi:jinja2","jinja2-f7d34747","pypi:jinja2","jinja2",[276,286],[368],"3.1.6",[56],{"id":371,"slug":372,"identity":373,"label":374,"aiRelevant":47,"provider":83,"advisoryCount":375,"licenseExpressions":376,"versions":377,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":379},"package:pypi:requests","requests-53653f76","pypi:requests","requests",3,[266],[378],"2.32.3",[56],{"id":381,"slug":382,"identity":383,"label":384,"aiRelevant":47,"provider":83,"advisoryCount":375,"licenseExpressions":385,"versions":386,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":388},"package:pypi:setuptools","setuptools-fe37c31a","pypi:setuptools","setuptools",[357],[387],"78.1.0",[56],{"id":390,"slug":391,"identity":392,"label":393,"aiRelevant":47,"provider":83,"advisoryCount":394,"licenseExpressions":395,"versions":397,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":399},"package:pypi:filelock","filelock-b1c63968","pypi:filelock","filelock",2,[357,396],"Unlicense",[398],"3.18.0",[56],{"id":401,"slug":402,"identity":403,"label":404,"aiRelevant":47,"provider":83,"advisoryCount":394,"licenseExpressions":405,"versions":406,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":408},"package:pypi:protobuf","protobuf-6e30009a","pypi:protobuf","protobuf",[276],[407],"6.32.1",[56],{"id":410,"slug":411,"identity":412,"label":413,"aiRelevant":47,"provider":83,"advisoryCount":394,"licenseExpressions":414,"versions":415,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":417},"package:pypi:streamlit","streamlit-b61aa01e","pypi:streamlit","streamlit",[266],[416],"1.49.1",[56],{"id":419,"slug":420,"identity":421,"label":422,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":423,"versions":425,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":427},"package:pypi:certifi","certifi-d4f0c37e","pypi:certifi","certifi",[424],"MPL-2.0",[426],"2025.1.31",[56],{"id":429,"slug":430,"identity":431,"label":432,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":433,"versions":434,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":436},"package:pypi:click","click-ef97f731","pypi:click","click",[276,286],[435],"8.2.1",[56],{"id":438,"slug":439,"identity":440,"label":441,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":442,"versions":443,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":445},"package:pypi:duckdb","duckdb-8c0332c9","pypi:duckdb","duckdb",[357],[444],"1.3.2",[56],{"id":447,"slug":448,"identity":449,"label":450,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":451,"versions":452,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":454},"package:pypi:fonttools","fonttools-d2488ea8","pypi:fonttools","fonttools",[357],[453],"4.55.8",[56],{"id":456,"slug":457,"identity":458,"label":459,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":460,"versions":461,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":463},"package:pypi:geopandas","geopandas-968b51b0","pypi:geopandas","geopandas",[276],[462],"1.0.1",[56],{"id":465,"slug":466,"identity":467,"label":468,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":469,"versions":470,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":472},"package:pypi:idna","idna-994c9929","pypi:idna","idna",[276,286],[471],"3.10",[56],{"id":474,"slug":475,"identity":476,"label":477,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":478,"versions":479,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":481},"package:pypi:pyarrow","pyarrow-facb8516","pypi:pyarrow","pyarrow",[266,286],[480],"21.0.0",[56],{"id":483,"slug":484,"identity":485,"label":486,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":487,"versions":489,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":491},"package:pypi:pygments","pygments-ad71bc11","pypi:pygments","pygments",[488],"BSD-2-Clause",[490],"2.19.1",[56],{"id":493,"slug":494,"identity":495,"label":496,"aiRelevant":47,"provider":83,"advisoryCount":32,"licenseExpressions":497,"versions":499,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":501},"package:pypi:tqdm","tqdm-04b01f90","pypi:tqdm","tqdm",[498],"MIT AND MPL-2.0",[500],"4.67.1",[56],{"id":503,"slug":504,"identity":505,"label":506,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":507,"versions":508,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":510},"package:pypi:altair","altair-01b7f976","pypi:altair","altair",[286],[509],"5.5.0",[56],{"id":512,"slug":513,"identity":514,"label":515,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":516,"versions":517,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":519},"package:pypi:asttokens","asttokens-c349c5f9","pypi:asttokens","asttokens",[266],[518],"3.0.0",[56],{"id":521,"slug":522,"identity":523,"label":524,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":525,"versions":526,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":528},"package:pypi:attrs","attrs-2e7954ac","pypi:attrs","attrs",[357],[527],"25.3.0",[56],{"id":530,"slug":531,"identity":532,"label":533,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":534,"versions":535,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":537},"package:pypi:blinker","blinker-409e1445","pypi:blinker","blinker",[357],[536],"1.9.0",[56],{"id":539,"slug":540,"identity":541,"label":542,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":543,"versions":544,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":546},"package:pypi:branca","branca-e1a3550c","pypi:branca","branca",[357],[545],"0.8.1",[56],{"id":548,"slug":549,"identity":550,"label":551,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":552,"versions":553,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":555},"package:pypi:cachetools","cachetools-84fe6563","pypi:cachetools","cachetools",[357],[554],"6.2.0",[56],{"id":557,"slug":558,"identity":559,"label":560,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":561,"versions":562,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":564},"package:pypi:charset-normalizer","charset-normalizer-74ccb20a","pypi:charset-normalizer","charset-normalizer",[357],[563],"3.4.1",[56],{"id":566,"slug":567,"identity":568,"label":569,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":570,"versions":571,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":573},"package:pypi:colorama","colorama-abaf57c3","pypi:colorama","colorama",[286],[572],"0.4.6",[56],{"id":575,"slug":576,"identity":577,"label":578,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":579,"versions":580,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":582},"package:pypi:contourpy","contourpy-f86f9e10","pypi:contourpy","contourpy",[286],[581],"1.3.1",[56],{"id":584,"slug":585,"identity":586,"label":587,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":588,"versions":589,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":591},"package:pypi:cycler","cycler-3e14883d","pypi:cycler","cycler",[286],[590],"0.12.1",[56],{"id":593,"slug":594,"identity":595,"label":596,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":597,"versions":598,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":600},"package:pypi:decorator","decorator-500c1fb8","pypi:decorator","decorator",[488,286],[599],"5.2.1",[56],{"id":602,"slug":603,"identity":604,"label":605,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":606,"versions":607,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":609},"package:pypi:executing","executing-36845a5b","pypi:executing","executing",[357],[608],"2.2.0",[56],{"id":611,"slug":612,"identity":613,"label":614,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":615,"versions":616,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":618},"package:pypi:folium","folium-6e89a148","pypi:folium","folium",[357],[617],"0.20.0",[56],{"id":620,"slug":621,"identity":622,"label":623,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":624,"versions":625,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":627},"package:pypi:fsspec","fsspec-b1a7c311","pypi:fsspec","fsspec",[276,286],[626],"2025.3.2",[56],{"id":629,"slug":630,"identity":631,"label":632,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":633,"versions":634,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":636},"package:pypi:ftfy","ftfy-b3100e16","pypi:ftfy","ftfy",[266],[635],"6.3.1",[56],{"id":638,"slug":639,"identity":640,"label":641,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":642,"versions":643,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":645},"package:pypi:gitdb","gitdb-dac4580b","pypi:gitdb","gitdb",[286],[644],"4.0.12",[56],{"id":647,"slug":648,"identity":649,"label":650,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":651,"versions":652,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":654},"package:pypi:huggingface-hub","huggingface-hub-443ec6ef","pypi:huggingface-hub","huggingface-hub",[266,286],[653],"0.30.1",[56],{"id":656,"slug":657,"identity":658,"label":659,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":660,"versions":661,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":663},"package:pypi:ipython","ipython-7a140323","pypi:ipython","ipython",[276],[662],"9.2.0",[56],{"id":665,"slug":666,"identity":667,"label":668,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":669,"versions":670,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":672},"package:pypi:ipython-pygments-lexers","ipython-pygments-lexers-6216051e","pypi:ipython-pygments-lexers","ipython-pygments-lexers",[286],[671],"1.1.1",[56],{"id":674,"slug":675,"identity":676,"label":677,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":678,"versions":679,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":681},"package:pypi:jedi","jedi-9eb0c211","pypi:jedi","jedi",[357],[680],"0.19.2",[56],{"id":683,"slug":684,"identity":685,"label":686,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":687,"versions":688,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":690},"package:pypi:joblib","joblib-8cbb7872","pypi:joblib","joblib",[276],[689],"1.4.2",[56],{"id":692,"slug":693,"identity":694,"label":695,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":696,"versions":697,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":699},"package:pypi:jsonschema","jsonschema-df23f5cd","pypi:jsonschema","jsonschema",[357],[698],"4.25.1",[56],{"id":701,"slug":702,"identity":703,"label":704,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":705,"versions":706,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":708},"package:pypi:jsonschema-specifications","jsonschema-specifications-5d87863a","pypi:jsonschema-specifications","jsonschema-specifications",[357],[707],"2025.9.1",[56],{"id":710,"slug":711,"identity":712,"label":713,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":714,"versions":715,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":717},"package:pypi:kiwisolver","kiwisolver-41b47c33","pypi:kiwisolver","kiwisolver",[286],[716],"1.4.8",[56],{"id":719,"slug":720,"identity":721,"label":722,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":723,"versions":724,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":726},"package:pypi:markupsafe","markupsafe-1bdd4c7f","pypi:markupsafe","markupsafe",[276,286],[725],"3.0.2",[56],{"id":728,"slug":729,"identity":730,"label":731,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":732,"versions":733,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":735},"package:pypi:matplotlib","matplotlib-9dc72309","pypi:matplotlib","matplotlib",[286],[734],"3.10.0",[56],{"id":737,"slug":738,"identity":739,"label":740,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":741,"versions":742,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":744},"package:pypi:matplotlib-inline","matplotlib-inline-50f95e0d","pypi:matplotlib-inline","matplotlib-inline",[276,286],[743],"0.1.7",[56],{"id":746,"slug":747,"identity":748,"label":749,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":750,"versions":751,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":753},"package:pypi:mpmath","mpmath-4ccb7a41","pypi:mpmath","mpmath",[286],[752],"1.3.0",[56],{"id":755,"slug":756,"identity":757,"label":758,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":759,"versions":760,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":762},"package:pypi:narwhals","narwhals-24e2f721","pypi:narwhals","narwhals",[357,286],[761],"2.4.0",[56],{"id":764,"slug":765,"identity":766,"label":767,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":768,"versions":769,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":771},"package:pypi:networkx","networkx-c2336a8d","pypi:networkx","networkx",[276,286],[770],"3.4.2",[56],{"id":773,"slug":774,"identity":775,"label":776,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":777,"versions":779,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":781},"package:pypi:numpy","numpy-ba79b98d","pypi:numpy","numpy",[778,286],"0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib",[780],"2.3.2",[56],{"id":783,"slug":784,"identity":785,"label":786,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":787,"versions":788,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":790},"package:pypi:nvidia-cublas-cu12","nvidia-cublas-cu12-1d052261","pypi:nvidia-cublas-cu12","nvidia-cublas-cu12",[286],[789],"12.8.3.14",[56],{"id":792,"slug":793,"identity":794,"label":795,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":796,"versions":797,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":799},"package:pypi:nvidia-cuda-cupti-cu12","nvidia-cuda-cupti-cu12-973480f1","pypi:nvidia-cuda-cupti-cu12","nvidia-cuda-cupti-cu12",[286],[798],"12.8.57",[56],{"id":801,"slug":802,"identity":803,"label":804,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":805,"versions":806,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":808},"package:pypi:nvidia-cuda-nvrtc-cu12","nvidia-cuda-nvrtc-cu12-e32b7f38","pypi:nvidia-cuda-nvrtc-cu12","nvidia-cuda-nvrtc-cu12",[286],[807],"12.8.61",[56],{"id":810,"slug":811,"identity":812,"label":813,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":814,"versions":815,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":816},"package:pypi:nvidia-cuda-runtime-cu12","nvidia-cuda-runtime-cu12-2b875d2a","pypi:nvidia-cuda-runtime-cu12","nvidia-cuda-runtime-cu12",[286],[798],[56],{"id":818,"slug":819,"identity":820,"label":821,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":822,"versions":823,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":825},"package:pypi:nvidia-cudnn-cu12","nvidia-cudnn-cu12-a21dce6d","pypi:nvidia-cudnn-cu12","nvidia-cudnn-cu12",[286],[824],"9.7.1.26",[56],{"id":827,"slug":828,"identity":829,"label":830,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":831,"versions":832,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":834},"package:pypi:nvidia-cufft-cu12","nvidia-cufft-cu12-21ff54dd","pypi:nvidia-cufft-cu12","nvidia-cufft-cu12",[286],[833],"11.3.3.41",[56],{"id":836,"slug":837,"identity":838,"label":839,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":840,"versions":841,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":843},"package:pypi:nvidia-cufile-cu12","nvidia-cufile-cu12-14048140","pypi:nvidia-cufile-cu12","nvidia-cufile-cu12",[286],[842],"1.13.0.11",[56],{"id":845,"slug":846,"identity":847,"label":848,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":849,"versions":850,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":852},"package:pypi:nvidia-curand-cu12","nvidia-curand-cu12-2fed778b","pypi:nvidia-curand-cu12","nvidia-curand-cu12",[286],[851],"10.3.9.55",[56],{"id":854,"slug":855,"identity":856,"label":857,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":858,"versions":859,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":861},"package:pypi:nvidia-cusolver-cu12","nvidia-cusolver-cu12-7db0a33a","pypi:nvidia-cusolver-cu12","nvidia-cusolver-cu12",[286],[860],"11.7.2.55",[56],{"id":863,"slug":864,"identity":865,"label":866,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":867,"versions":868,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":870},"package:pypi:nvidia-cusparse-cu12","nvidia-cusparse-cu12-d7e6a309","pypi:nvidia-cusparse-cu12","nvidia-cusparse-cu12",[286],[869],"12.5.7.53",[56],{"id":872,"slug":873,"identity":874,"label":875,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":876,"versions":877,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":879},"package:pypi:nvidia-cusparselt-cu12","nvidia-cusparselt-cu12-97587f50","pypi:nvidia-cusparselt-cu12","nvidia-cusparselt-cu12",[286],[878],"0.6.3",[56],{"id":881,"slug":882,"identity":883,"label":884,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":885,"versions":886,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":888},"package:pypi:nvidia-nccl-cu12","nvidia-nccl-cu12-90361558","pypi:nvidia-nccl-cu12","nvidia-nccl-cu12",[276,286],[887],"2.26.2",[56],{"id":890,"slug":891,"identity":892,"label":893,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":894,"versions":895,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":896},"package:pypi:nvidia-nvjitlink-cu12","nvidia-nvjitlink-cu12-6d08af75","pypi:nvidia-nvjitlink-cu12","nvidia-nvjitlink-cu12",[286],[807],[56],{"id":898,"slug":899,"identity":900,"label":901,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":902,"versions":903,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":905},"package:pypi:nvidia-nvtx-cu12","nvidia-nvtx-cu12-9a2d0378","pypi:nvidia-nvtx-cu12","nvidia-nvtx-cu12",[266,286],[904],"12.8.55",[56],{"id":907,"slug":908,"identity":909,"label":910,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":911,"versions":912,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":914},"package:pypi:open-clip-torch","open-clip-torch-1f82ec28","pypi:open-clip-torch","open-clip-torch",[357],[913],"2.32.0",[56],{"id":916,"slug":917,"identity":918,"label":919,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":920,"versions":922,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":924},"package:pypi:packaging","packaging-78ee1f47","pypi:packaging","packaging",[921,286],"Apache-2.0 OR BSD-2-Clause",[923],"24.2",[56],{"id":926,"slug":927,"identity":928,"label":929,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":930,"versions":931,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":933},"package:pypi:pandas","pandas-e8d52445","pypi:pandas","pandas",[286],[932],"2.2.3",[56],{"id":935,"slug":936,"identity":937,"label":938,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":939,"versions":940,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":942},"package:pypi:pandas-stubs","pandas-stubs-b4eaabf3","pypi:pandas-stubs","pandas-stubs",[276],[941],"2.3.2.250827",[56],{"id":944,"slug":945,"identity":946,"label":947,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":948,"versions":949,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":951},"package:pypi:parso","parso-fa59fdde","pypi:parso","parso",[357],[950],"0.8.4",[56],{"id":953,"slug":954,"identity":955,"label":956,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":957,"versions":958,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":960},"package:pypi:pexpect","pexpect-9ad65a0c","pypi:pexpect","pexpect",[286],[959],"4.9.0",[56],{"id":962,"slug":963,"identity":964,"label":965,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":966,"versions":967,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":969},"package:pypi:prompt-toolkit","prompt-toolkit-e6f4118a","pypi:prompt-toolkit","prompt-toolkit",[276,286],[968],"3.0.51",[56],{"id":971,"slug":972,"identity":973,"label":974,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":975,"versions":977,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":979},"package:pypi:ptyprocess","ptyprocess-ec2650c7","pypi:ptyprocess","ptyprocess",[976],"ISC",[978],"0.7.0",[56],{"id":981,"slug":982,"identity":983,"label":984,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":985,"versions":986,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":988},"package:pypi:pure-eval","pure-eval-24d2bc1c","pypi:pure-eval","pure-eval",[357],[987],"0.2.3",[56],{"id":990,"slug":991,"identity":992,"label":993,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":994,"versions":995,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":997},"package:pypi:pydeck","pydeck-75380c92","pypi:pydeck","pydeck",[266],[996],"0.9.1",[56],{"id":999,"slug":1000,"identity":1001,"label":1002,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1003,"versions":1004,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1006},"package:pypi:pyogrio","pyogrio-ff34272a","pypi:pyogrio","pyogrio",[286],[1005],"0.10.0",[56],{"id":1008,"slug":1009,"identity":1010,"label":1011,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1012,"versions":1013,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1015},"package:pypi:pyparsing","pyparsing-a28b9b62","pypi:pyparsing","pyparsing",[357],[1014],"3.2.1",[56],{"id":1017,"slug":1018,"identity":1019,"label":1020,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1021,"versions":1022,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1024},"package:pypi:pyproj","pyproj-cd69d38f","pypi:pyproj","pyproj",[357],[1023],"3.7.0",[56],{"id":1026,"slug":1027,"identity":1028,"label":1029,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1030,"versions":1031,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1033},"package:pypi:python-dateutil","python-dateutil-8eac96b7","pypi:python-dateutil","python-dateutil",[286],[1032],"2.9.0.post0",[56],{"id":1035,"slug":1036,"identity":1037,"label":1038,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1039,"versions":1040,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1042},"package:pypi:pytz","pytz-cbf1d95c","pypi:pytz","pytz",[357],[1041],"2025.1",[56],{"id":1044,"slug":1045,"identity":1046,"label":1047,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1048,"versions":1049,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1051},"package:pypi:pyyaml","pyyaml-16000901","pypi:pyyaml","pyyaml",[357],[1050],"6.0.2",[56],{"id":1053,"slug":1054,"identity":1055,"label":1056,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1057,"versions":1058,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1060},"package:pypi:referencing","referencing-b8d98ce1","pypi:referencing","referencing",[357],[1059],"0.36.2",[56],{"id":1062,"slug":1063,"identity":1064,"label":1065,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1066,"versions":1068,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1070},"package:pypi:regex","regex-5e8be65e","pypi:regex","regex",[1067,286],"Apache-2.0 AND CNRI-Python",[1069],"2024.11.6",[56],{"id":1072,"slug":1073,"identity":1074,"label":1075,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1076,"versions":1077,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1079},"package:pypi:rpds-py","rpds-py-67c64be8","pypi:rpds-py","rpds-py",[357],[1078],"0.27.1",[56],{"id":1081,"slug":1082,"identity":1083,"label":1084,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1085,"versions":1086,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1088},"package:pypi:safetensors","safetensors-2a32c77a","pypi:safetensors","safetensors",[286],[1087],"0.5.3",[56],{"id":1090,"slug":1091,"identity":1092,"label":1093,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1094,"versions":1095,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1097},"package:pypi:scipy","scipy-215f884d","pypi:scipy","scipy",[286],[1096],"1.15.2",[56],{"id":1099,"slug":1100,"identity":1101,"label":1102,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1103,"versions":1104,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1106},"package:pypi:seaborn","seaborn-1018de9a","pypi:seaborn","seaborn",[286],[1105],"0.13.2",[56],{"id":1108,"slug":1109,"identity":1110,"label":1111,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1112,"versions":1113,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1115},"package:pypi:shapely","shapely-1cd2f2ba","pypi:shapely","shapely",[276],[1114],"2.0.7",[56],{"id":1117,"slug":1118,"identity":1119,"label":1120,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1121,"versions":1122,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1124},"package:pypi:six","six-3c3888bd","pypi:six","six",[357],[1123],"1.17.0",[56],{"id":1126,"slug":1127,"identity":1128,"label":1129,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1130,"versions":1131,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1133},"package:pypi:smmap","smmap-943fc5aa","pypi:smmap","smmap",[276],[1132],"5.0.2",[56],{"id":1135,"slug":1136,"identity":1137,"label":1138,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1139,"versions":1140,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1141},"package:pypi:stack-data","stack-data-d640fe0e","pypi:stack-data","stack-data",[357],[878],[56],{"id":1143,"slug":1144,"identity":1145,"label":1146,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1147,"versions":1148,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1150},"package:pypi:streamlit-folium","streamlit-folium-e76fb4ea","pypi:streamlit-folium","streamlit-folium",[],[1149],"0.25.1",[56],{"id":1152,"slug":1153,"identity":1154,"label":1155,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1156,"versions":1157,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1159},"package:pypi:sympy","sympy-b30cb89e","pypi:sympy","sympy",[286],[1158],"1.14.0",[56],{"id":1161,"slug":1162,"identity":1163,"label":1164,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1165,"versions":1166,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1168},"package:pypi:tenacity","tenacity-415454f8","pypi:tenacity","tenacity",[266],[1167],"9.1.2",[56],{"id":1170,"slug":1171,"identity":1172,"label":1173,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1174,"versions":1175,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1177},"package:pypi:threadpoolctl","threadpoolctl-e94f6300","pypi:threadpoolctl","threadpoolctl",[276],[1176],"3.6.0",[56],{"id":1179,"slug":1180,"identity":1181,"label":1182,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1183,"versions":1184,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1186},"package:pypi:timm","timm-4594fb75","pypi:timm","timm",[266],[1185],"1.0.15",[56],{"id":1188,"slug":1189,"identity":1190,"label":1191,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1192,"versions":1193,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1195},"package:pypi:toml","toml-490ac3c8","pypi:toml","toml",[357],[1194],"0.10.2",[56],{"id":1197,"slug":1198,"identity":1199,"label":1200,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1201,"versions":1202,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1204},"package:pypi:torchvision","torchvision-7f85cafa","pypi:torchvision","torchvision",[286],[1203],"0.24.1",[56],{"id":1206,"slug":1207,"identity":1208,"label":1209,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1210,"versions":1211,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1213},"package:pypi:traitlets","traitlets-52bd6ddb","pypi:traitlets","traitlets",[286],[1212],"5.14.3",[56],{"id":1215,"slug":1216,"identity":1217,"label":1218,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1219,"versions":1220,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1222},"package:pypi:triton","triton-601ea838","pypi:triton","triton",[357],[1221],"3.3.0",[56],{"id":1224,"slug":1225,"identity":1226,"label":1227,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1228,"versions":1229,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1231},"package:pypi:types-pytz","types-pytz-327ed57f","pypi:types-pytz","types-pytz",[266],[1230],"2025.2.0.20250809",[56],{"id":1233,"slug":1234,"identity":1235,"label":1236,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1237,"versions":1239,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1241},"package:pypi:typing-extensions","typing-extensions-87d153eb","pypi:typing-extensions","typing-extensions",[1238,286],"PSF-2.0",[1240],"4.13.1",[56],{"id":1243,"slug":1244,"identity":1245,"label":1246,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1247,"versions":1248,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1249},"package:pypi:tzdata","tzdata-f80b3bb7","pypi:tzdata","tzdata",[266],[1041],[56],{"id":1251,"slug":1252,"identity":1253,"label":1254,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1255,"versions":1256,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1258},"package:pypi:watchdog","watchdog-55ddb444","pypi:watchdog","watchdog",[266],[1257],"6.0.0",[56],{"id":1260,"slug":1261,"identity":1262,"label":1263,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1264,"versions":1265,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1267},"package:pypi:wcwidth","wcwidth-038a8957","pypi:wcwidth","wcwidth",[357],[1266],"0.2.13",[56],{"id":1269,"slug":1270,"identity":1271,"label":1272,"aiRelevant":47,"provider":83,"advisoryCount":39,"licenseExpressions":1273,"versions":1274,"dossier":47,"occurrenceCount":32,"directOccurrenceCount":39,"evidenceFiles":1276},"package:pypi:xyzservices","xyzservices-a1955a18","pypi:xyzservices","xyzservices",[276],[1275],"2025.4.0",[56],[1278,1317,1350,1383,1414,1450,1493,1520,1547,1574,1599,1629,1658,1694,1721,1750,1776,1805,1843,1867,1891,1914,1950,1973,1997,2020,2050,2087,2115,2142,2168,2194,2217,2240,2272,2304,2334,2359,2399,2428,2453,2492,2524,2556,2579,2604,2631,2659,2693,2719,2746,2776,2808,2832,2886,2918,2942,2974,3008,3047,3075,3098,3121,3154,3182,3205,3233,3267,3300,3327,3359,3389,3411,3438,3463,3487,3516,3538,3559,3584,3605,3632,3659,3684,3708,3732,3757,3773,3799,3821,3847,3868,3905,3932,3964,3991,4018,4046,4069,4096,4126,4146,4180,4210,4230,4258,4285,4328,4358,4410,4433,4458,4485,4509,4532,4564,4591,4616,4643,4665,4685,4702,4721,4738,4759,4775,4790,4807,4822,4839,4856,4873,4887,4900,4913,4926,4939,4952,4965,4978,5001,5034,5064,5081],{"id":106,"slug":1279,"dossier":47,"summary":1280,"aliases":1281,"sourceIds":1284,"published":1285,"modified":1286,"checkedAt":7,"severity":1287,"references":1291,"versionKeys":1315,"packageCount":32,"repositoryCount":32},"ghsa-248v-346w-9cwc-8a7dbdf1","Certifi removes GLOBALTRUST root certificate",[1282,1283],"CVE-2024-39689","PYSEC-2024-230",[106,1283],"2024-07-05T19:15:10Z","2026-09-10T03:50:15.994602411Z",[1288],{"type":1289,"score":1290},"CVSS_V3","CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[1292,1295,1297,1300,1303,1306,1309,1311,1313],{"type":1293,"url":1294},"ADVISORY","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi\u002Fsecurity\u002Fadvisories\u002FGHSA-248v-346w-9cwc",{"type":1293,"url":1296},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39689",{"type":1298,"url":1299},"FIX","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi\u002Fcommit\u002Fbd8153872e9c6fc98f4023df9c2deaffea2fa463",{"type":1301,"url":1302},"PACKAGE","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi",{"type":1304,"url":1305},"WEB","https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fcertifi\u002FPYSEC-2024-230.yaml",{"type":1307,"url":1308},"ARTICLE","https:\u002F\u002Fgroups.google.com\u002Fa\u002Fmozilla.org\u002Fg\u002Fdev-security-policy\u002Fc\u002FXpknYMPO8dI",{"type":1304,"url":1310},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20241206-0001",{"type":1293,"url":1312},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20241206-0001\u002F",{"type":1293,"url":1314},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-248v-346w-9cwc",[1316],"pypi:certifi@2024.6.2",{"id":107,"slug":1318,"dossier":47,"summary":1319,"aliases":1320,"sourceIds":1323,"published":1324,"modified":1325,"checkedAt":7,"severity":1326,"references":1334,"versionKeys":1346,"packageCount":32,"repositoryCount":103},"ghsa-284h-m62q-gf8w-da9acb0c","GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE",[1321,1322],"CVE-2026-78676","PYSEC-2026-3786",[107,1322],"2026-08-25T02:16:52.030Z","2026-09-08T19:00:06.885837775Z",[1327,1329,1332],{"type":1289,"score":1328},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1330,"score":1331},"CVSS_V4","CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":1330,"score":1333},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[1335,1338,1340,1342,1344],{"type":1336,"url":1337},"EVIDENCE","https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-284h-m62q-gf8w",{"type":1293,"url":1339},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78676",{"type":1301,"url":1341},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython",{"type":1304,"url":1343},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3786.yaml",{"type":1293,"url":1345},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-config-injection",[1347,1348,1349],"pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46",{"id":108,"slug":1351,"dossier":47,"summary":1352,"aliases":1353,"sourceIds":1356,"published":1357,"modified":1358,"checkedAt":7,"severity":1359,"references":1362,"versionKeys":1373,"packageCount":32,"repositoryCount":42},"ghsa-29pf-2h5f-8g72-1d83ebb4","HuggingFace transformers vulnerable to remote code execution",[1354,1355],"CVE-2026-4372","PYSEC-2026-2289",[108,1355],"2026-05-24T14:16:16.917Z","2026-09-10T03:50:45.254378086Z",[1360],{"type":1289,"score":1361},"CVSS:3.0\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[1363,1365,1367,1369,1371],{"type":1293,"url":1364},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-4372",{"type":1298,"url":1366},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fa7f8e7ff37d87d1a1a0c8cf607971c607741452f",{"type":1301,"url":1368},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers",{"type":1336,"url":1370},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F1f693a6e-6836-4b8b-a0bd-ca036fba8884",{"type":1293,"url":1372},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-29pf-2h5f-8g72",[1374,1375,1376,1377,1378,1379,1380,1381,1382],"pypi:transformers@4.47.1","pypi:transformers@4.51.0","pypi:transformers@4.51.3","pypi:transformers@4.52.4","pypi:transformers@4.53.1","pypi:transformers@4.57.1","pypi:transformers@4.57.3","pypi:transformers@4.57.4","pypi:transformers@4.57.6",{"id":109,"slug":1384,"dossier":47,"summary":1385,"aliases":1386,"sourceIds":1389,"published":1390,"modified":1391,"checkedAt":7,"severity":1392,"references":1395,"versionKeys":1413,"packageCount":32,"repositoryCount":103},"ghsa-2f96-g7mh-g2hx-dd7ec02d","GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist",[1387,1388],"CVE-2026-67325","PYSEC-2026-3836",[109,1388],"2026-07-21T19:43:43Z","2026-09-23T05:15:05.950374846Z",[1393],{"type":1289,"score":1394},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[1396,1398,1400,1402,1404,1405,1407,1409,1411],{"type":1304,"url":1397},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-2f96-g7mh-g2hx",{"type":1293,"url":1399},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-67325",{"type":1304,"url":1401},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2161",{"type":1304,"url":1403},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F56806080c1348749b07daa4a2024ce47b3cad285",{"type":1301,"url":1341},{"type":1304,"url":1406},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.51",{"type":1304,"url":1408},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-command-injection-via-option-prefix-abbreviation",{"type":1301,"url":1410},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fgitpython",{"type":1293,"url":1412},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2f96-g7mh-g2hx",[1347,1348,1349],{"id":110,"slug":1415,"dossier":90,"summary":1416,"aliases":1417,"sourceIds":1420,"published":1421,"modified":1422,"checkedAt":7,"severity":1423,"references":1426,"versionKeys":1443,"packageCount":32,"repositoryCount":1449},"ghsa-2xpw-w6gg-jr37-91cead57","urllib3 streaming API improperly handles highly compressed data",[1418,1419],"CVE-2025-66471","PYSEC-2026-1994",[110,1419],"2025-12-05T18:15:54Z","2026-09-25T17:15:05.968189421Z",[1424],{"type":1330,"score":1425},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:H",[1427,1429,1431,1433,1435,1437,1439,1441],{"type":1304,"url":1428},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-2xpw-w6gg-jr37",{"type":1293,"url":1430},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66471",{"type":1298,"url":1432},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Fc19571de34c47de3a766541b041637ba5f716ed7",{"type":1304,"url":1434},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Fd0fde3672e4a4093f7587858dccfc298eb66e46c",{"type":1293,"url":1436},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2xpw-w6gg-jr37",{"type":1304,"url":1438},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Furllib3\u002FPYSEC-2026-1994.yaml",{"type":1301,"url":1440},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3",{"type":1301,"url":1442},"https:\u002F\u002Fpypi.org\u002Fproject\u002Furllib3",[1444,1445,1446,1447,1448],"pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0",16,{"id":111,"slug":1451,"dossier":47,"summary":1452,"aliases":1453,"sourceIds":1457,"published":1458,"modified":1459,"checkedAt":7,"severity":1460,"references":1467,"versionKeys":1489,"packageCount":32,"repositoryCount":375},"ghsa-3749-ghw9-m3mg-fadf4a32","PyTorch susceptible to local Denial of Service",[1454,1455,1456],"BIT-pytorch-2025-2953","CVE-2025-2953","PYSEC-2025-191",[111,1456],"2025-03-30T16:15:14.380Z","2026-09-10T03:50:22.781448235Z",[1461,1463,1465],{"type":1289,"score":1462},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",{"type":1330,"score":1464},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":1289,"score":1466},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",[1468,1470,1473,1475,1477,1479,1481,1483,1485,1487],{"type":1293,"url":1469},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2953",{"type":1471,"url":1472},"REPORT","https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149274",{"type":1471,"url":1474},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149274#issue-2923122269",{"type":1304,"url":1476},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-191.yaml",{"type":1301,"url":1478},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch",{"type":1304,"url":1480},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fblob\u002Fmain\u002FSECURITY.md#untrusted-models",{"type":1471,"url":1482},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302006",{"type":1293,"url":1484},"https:\u002F\u002Fvuldb.com\u002F?id.302006",{"type":1293,"url":1486},"https:\u002F\u002Fvuldb.com\u002F?submit.521279",{"type":1293,"url":1488},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3749-ghw9-m3mg",[1490,1491,1492],"pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0",{"id":112,"slug":1494,"dossier":47,"summary":1495,"aliases":1496,"sourceIds":1499,"published":1500,"modified":1501,"checkedAt":7,"severity":1502,"references":1505,"versionKeys":1519,"packageCount":32,"repositoryCount":375},"ghsa-37mw-44qp-f5jm-fb05555e","Transformers is vulnerable to ReDoS attack through its DonutProcessor class",[1497,1498],"CVE-2025-3933","PYSEC-2026-1977",[112,1498],"2025-07-11T12:30:32Z","2026-09-10T03:50:57.888142744Z",[1503],{"type":1289,"score":1504},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[1506,1508,1510,1512,1513,1515,1517],{"type":1293,"url":1507},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3933",{"type":1304,"url":1509},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F37788",{"type":1304,"url":1511},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Febbe9b12dd75b69f92100d684c47f923ee262a93",{"type":1301,"url":1368},{"type":1304,"url":1514},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F25282953-5827-4384-bb6f-5790d275721b",{"type":1301,"url":1516},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftransformers",{"type":1293,"url":1518},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-37mw-44qp-f5jm",[1374,1375,1376],{"id":113,"slug":1521,"dossier":90,"summary":1522,"aliases":1523,"sourceIds":1526,"published":1527,"modified":1528,"checkedAt":7,"severity":1529,"references":1533,"versionKeys":1546,"packageCount":32,"repositoryCount":1449},"ghsa-38jv-5279-wg99-c9df8f7b","Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)",[1524,1525],"CVE-2026-21441","PYSEC-2026-1996",[113,1525],"2026-01-07T19:18:14Z","2026-09-10T03:50:32.562010895Z",[1530,1532],{"type":1289,"score":1531},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",{"type":1330,"score":1425},[1534,1536,1538,1540,1541,1543,1544],{"type":1304,"url":1535},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-38jv-5279-wg99",{"type":1293,"url":1537},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-21441",{"type":1298,"url":1539},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F8864ac407bba8607950025e0979c4c69bc7abc7b",{"type":1301,"url":1440},{"type":1304,"url":1542},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F01\u002Fmsg00017.html",{"type":1301,"url":1442},{"type":1293,"url":1545},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-38jv-5279-wg99",[1444,1445,1446,1447,1448],{"id":114,"slug":1548,"dossier":47,"summary":1549,"aliases":1550,"sourceIds":1553,"published":1554,"modified":1555,"checkedAt":7,"severity":1556,"references":1561,"versionKeys":1573,"packageCount":32,"repositoryCount":103},"ghsa-3f7w-8rr8-f37f-9cab61a6","GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read",[1551,1552],"CVE-2026-73620","PYSEC-2026-3949",[114,1552],"2026-08-03T20:09:56Z","2026-09-10T13:10:44.075529324Z",[1557,1559],{"type":1289,"score":1558},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",{"type":1330,"score":1560},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[1562,1564,1566,1568,1569,1571],{"type":1336,"url":1563},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3f7w-8rr8-f37f",{"type":1304,"url":1565},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2193",{"type":1304,"url":1567},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F3af0c2516c5e18c829da30338614688f6b69b49c",{"type":1301,"url":1341},{"type":1304,"url":1570},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.57",{"type":1293,"url":1572},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-overwrite-and-read",[1347,1348,1349],{"id":115,"slug":1575,"dossier":47,"summary":1576,"aliases":1577,"sourceIds":1580,"published":1581,"modified":1582,"checkedAt":7,"severity":1583,"references":1588,"versionKeys":1598,"packageCount":32,"repositoryCount":103},"ghsa-3rp5-jjmw-4wv2-6d7352e6","GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)",[1578,1579],"CVE-2026-69097","PYSEC-2026-3981",[115,1579],"2026-07-24T16:22:02Z","2026-09-17T09:10:35.253135365Z",[1584,1586],{"type":1289,"score":1585},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1289,"score":1587},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[1589,1591,1593,1594,1596],{"type":1336,"url":1590},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3rp5-jjmw-4wv2",{"type":1304,"url":1592},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1ed1b924f4e2d2ee7bab296df77b978af21853f1",{"type":1301,"url":1341},{"type":1304,"url":1595},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.53",{"type":1293,"url":1597},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-config-injection-via-submodule-names",[1347,1348,1349],{"id":116,"slug":1600,"dossier":47,"summary":1601,"aliases":1602,"sourceIds":1605,"published":1606,"modified":1607,"checkedAt":7,"severity":1608,"references":1611,"versionKeys":1628,"packageCount":32,"repositoryCount":103},"ghsa-3wxw-xv34-2frg-c013ae2d","GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)",[1603,1604],"CVE-2026-78679","PYSEC-2026-3837",[116,1604],"2026-09-08T19:42:22Z","2026-09-23T05:15:05.925079070Z",[1609],{"type":1289,"score":1610},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[1612,1614,1616,1618,1620,1621,1623,1625,1626],{"type":1304,"url":1613},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3wxw-xv34-2frg",{"type":1293,"url":1615},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78679",{"type":1304,"url":1617},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2208",{"type":1304,"url":1619},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6",{"type":1301,"url":1341},{"type":1304,"url":1622},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.59",{"type":1304,"url":1624},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-tagreference-create",{"type":1301,"url":1410},{"type":1293,"url":1627},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3wxw-xv34-2frg",[1347,1348,1349],{"id":117,"slug":1630,"dossier":47,"summary":1631,"aliases":1632,"sourceIds":1635,"published":1636,"modified":1637,"checkedAt":7,"severity":1638,"references":1641,"versionKeys":1652,"packageCount":32,"repositoryCount":66},"ghsa-3x9g-8vmp-wqvf-6d03bf5f","Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient",[1633,1634],"CVE-2026-49853","PYSEC-2026-3387",[117,1634],"2026-06-15T20:20:00Z","2026-09-10T03:50:55.306087854Z",[1639],{"type":1289,"score":1640},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[1642,1644,1646,1648,1650],{"type":1304,"url":1643},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-3x9g-8vmp-wqvf",{"type":1301,"url":1645},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado",{"type":1301,"url":1647},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftornado",{"type":1293,"url":1649},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3x9g-8vmp-wqvf",{"type":1293,"url":1651},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49853",[1653,1654,1655,1656,1657],"pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5",{"id":118,"slug":1659,"dossier":90,"summary":1660,"aliases":1661,"sourceIds":1665,"published":1666,"modified":1667,"checkedAt":7,"severity":1668,"references":1670,"versionKeys":1683,"packageCount":32,"repositoryCount":1693},"ghsa-45hq-cxwh-f6vc-d18d2872","Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading",[1662,1663,1664],"BIT-pillow-2026-55379","CVE-2026-55379","PYSEC-2026-2255",[118,1664],"2026-07-06T19:17:08.577Z","2026-09-10T03:50:51.372929814Z",[1669],{"type":1289,"score":1531},[1671,1673,1675,1677,1679,1681],{"type":1336,"url":1672},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-45hq-cxwh-f6vc",{"type":1293,"url":1674},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55379",{"type":1298,"url":1676},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F0a263e6264aa5399988d9acd3bbfbca2ca3ec77d",{"type":1304,"url":1678},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2255.yaml",{"type":1301,"url":1680},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow",{"type":1293,"url":1682},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fblob\u002Fmain\u002Fdocs\u002Freleasenotes\u002F12.3.0.rst",[1684,1685,1686,1687,1688,1689,1690,1691,1692],"pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1","pypi:pillow@12.2.0",17,{"id":119,"slug":1695,"dossier":47,"summary":1696,"aliases":1697,"sourceIds":1700,"published":1701,"modified":1702,"checkedAt":7,"severity":1703,"references":1706,"versionKeys":1719,"packageCount":32,"repositoryCount":1720},"ghsa-48p4-8xcf-vxj5-13f12656","urllib3 does not control redirects in browsers and Node.js",[1698,1699],"CVE-2025-50182","PYSEC-2026-1997",[119,1699],"2025-06-18T17:50:11Z","2026-09-10T03:50:24.821170285Z",[1704],{"type":1289,"score":1705},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[1707,1709,1711,1713,1714,1716,1717],{"type":1304,"url":1708},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-48p4-8xcf-vxj5",{"type":1293,"url":1710},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-50182",{"type":1298,"url":1712},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f",{"type":1301,"url":1440},{"type":1304,"url":1715},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Freleases\u002Ftag\u002F2.5.0",{"type":1301,"url":1442},{"type":1293,"url":1718},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-48p4-8xcf-vxj5",[1444,1445,1446,1447],8,{"id":120,"slug":1722,"dossier":47,"summary":1723,"aliases":1724,"sourceIds":1727,"published":1728,"modified":1729,"checkedAt":7,"severity":1730,"references":1732,"versionKeys":1749,"packageCount":32,"repositoryCount":103},"ghsa-4gmw-gg2m-w46p-58f27cb8","GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree\u002Freset\u002Fmerge_tree enables arbitrary file overwrite",[1725,1726],"CVE-2026-76219","PYSEC-2026-3838",[120,1726],"2026-08-07T15:33:57Z","2026-09-10T12:25:42.767166279Z",[1731],{"type":1289,"score":1558},[1733,1735,1737,1739,1741,1742,1744,1746,1747],{"type":1304,"url":1734},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-4gmw-gg2m-w46p",{"type":1293,"url":1736},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76219",{"type":1304,"url":1738},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2204",{"type":1304,"url":1740},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F9b5dcaf85da5946dbf69dcd53f9edba08f760b32",{"type":1301,"url":1341},{"type":1304,"url":1743},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.58",{"type":1304,"url":1745},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-overwrite-via-read-tree",{"type":1301,"url":1410},{"type":1293,"url":1748},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4gmw-gg2m-w46p",[1347,1348,1349],{"id":121,"slug":1751,"dossier":47,"summary":1752,"aliases":1753,"sourceIds":1756,"published":1757,"modified":1758,"checkedAt":7,"severity":1759,"references":1762,"versionKeys":1775,"packageCount":32,"repositoryCount":34},"ghsa-4w7r-h757-3r74-ca8973bc","Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer",[1754,1755],"CVE-2025-6921","PYSEC-2026-1980",[121,1755],"2025-09-23T15:31:09Z","2026-09-10T03:50:27.867584538Z",[1760],{"type":1289,"score":1761},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[1763,1765,1767,1769,1770,1772,1773],{"type":1293,"url":1764},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6921",{"type":1304,"url":1766},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F47c34fba5c303576560cb29767efb452ff12b8be",{"type":1304,"url":1768},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fd37f7517972f67e3f2194c000ed0f87f064e5099",{"type":1301,"url":1368},{"type":1304,"url":1771},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F287d15a7-6e7c-45d2-8c05-11e305776f1f",{"type":1301,"url":1516},{"type":1293,"url":1774},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4w7r-h757-3r74",[1374,1375,1376,1377],{"id":122,"slug":1777,"dossier":90,"summary":1778,"aliases":1779,"sourceIds":1783,"published":1784,"modified":1785,"checkedAt":7,"severity":1786,"references":1789,"versionKeys":1804,"packageCount":32,"repositoryCount":1693},"ghsa-4x4j-2g7c-83w6-326c14d2","Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path",[1780,1781,1782],"BIT-pillow-2026-55798","CVE-2026-55798","PYSEC-2026-2257",[122,1782],"2026-07-06T19:17:08.830Z","2026-09-10T03:51:10.324377232Z",[1787],{"type":1289,"score":1788},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:L",[1790,1792,1794,1796,1798,1800,1802,1803],{"type":1336,"url":1791},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-4x4j-2g7c-83w6",{"type":1293,"url":1793},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55798",{"type":1298,"url":1795},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F8404ea5fe5df40fc34aa1e51403dd6fce0778b8a",{"type":1298,"url":1797},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F88194166691b7b603529b8b036ab3ab9cedd2de4",{"type":1298,"url":1799},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fb0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f",{"type":1304,"url":1801},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2257.yaml",{"type":1301,"url":1680},{"type":1293,"url":1682},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":123,"slug":1806,"dossier":47,"summary":1807,"aliases":1808,"sourceIds":1811,"published":1812,"modified":1813,"checkedAt":7,"severity":1814,"references":1817,"versionKeys":1840,"packageCount":32,"repositoryCount":104},"ghsa-5239-wwwm-4pmq-228840e4","Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching",[1809,1810],"CVE-2026-4539","PYSEC-2026-2987",[123,1810],"2026-03-22T06:30:15Z","2026-09-10T03:50:59.780634752Z",[1815,1816],{"type":1289,"score":1462},{"type":1330,"score":1464},[1818,1820,1822,1824,1826,1828,1830,1832,1834,1836,1838],{"type":1293,"url":1819},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-4539",{"type":1304,"url":1821},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Fissues\u002F3058",{"type":1304,"url":1823},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Fpull\u002F3064",{"type":1304,"url":1825},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Fcommit\u002F24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc",{"type":1301,"url":1827},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments",{"type":1304,"url":1829},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Freleases\u002Ftag\u002F2.20.0",{"type":1304,"url":1831},"https:\u002F\u002Fvuldb.com\u002F?ctiid.352327",{"type":1304,"url":1833},"https:\u002F\u002Fvuldb.com\u002F?id.352327",{"type":1304,"url":1835},"https:\u002F\u002Fvuldb.com\u002F?submit.774685",{"type":1301,"url":1837},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fpygments",{"type":1293,"url":1839},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5239-wwwm-4pmq",[1841,1842],"pypi:pygments@2.19.1","pypi:pygments@2.19.2",{"id":124,"slug":1844,"dossier":47,"summary":1845,"aliases":1846,"sourceIds":1849,"published":1850,"modified":1851,"checkedAt":7,"severity":1852,"references":1856,"versionKeys":1866,"packageCount":32,"repositoryCount":103},"ghsa-539m-9xh6-q6rr-c4575e3c","GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file \u002F --add-virtual-file, enabling arbitrary file read via Repo.archive()",[1847,1848],"CVE-2026-73619","PYSEC-2026-3948",[124,1848],"2026-08-03T20:14:28Z","2026-09-10T13:11:01.695990206Z",[1853,1854],{"type":1289,"score":1610},{"type":1330,"score":1855},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[1857,1859,1860,1862,1863,1864],{"type":1336,"url":1858},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-539m-9xh6-q6rr",{"type":1304,"url":1565},{"type":1304,"url":1861},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F7a4f5dcb7bf3cbcbf6e438017efcdfe0bc0d36ca",{"type":1301,"url":1341},{"type":1304,"url":1570},{"type":1293,"url":1865},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-repo-archive",[1347,1348,1349],{"id":125,"slug":1868,"dossier":47,"summary":1869,"aliases":1870,"sourceIds":1874,"published":1875,"modified":1876,"checkedAt":7,"severity":1877,"references":1880,"versionKeys":1890,"packageCount":32,"repositoryCount":32},"ghsa-53q9-r3pm-6pq6-6fbb0149","PyTorch: `torch.load` with `weights_only=True` leads to remote code execution",[1871,1872,1873],"BIT-pytorch-2025-32434","CVE-2025-32434","PYSEC-2025-41",[125,1873],"2025-04-18T15:19:28Z","2026-08-07T08:12:20.395044060Z",[1878,1879],{"type":1330,"score":1331},{"type":1289,"score":1328},[1881,1883,1885,1887,1889],{"type":1293,"url":1882},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fsecurity\u002Fadvisories\u002FGHSA-53q9-r3pm-6pq6",{"type":1293,"url":1884},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-32434",{"type":1304,"url":1886},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F8d4b8a920a2172523deb95bf20e8e52d50649c04",{"type":1304,"url":1888},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-41.yaml",{"type":1301,"url":1478},[1490],{"id":126,"slug":1892,"dossier":47,"summary":1893,"aliases":1894,"sourceIds":1897,"published":1898,"modified":1899,"checkedAt":7,"severity":1900,"references":1902,"versionKeys":1913,"packageCount":32,"repositoryCount":34},"ghsa-59p9-h35m-wg4g-68657c65","Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer",[1895,1896],"CVE-2025-6638","PYSEC-2026-1981",[126,1896],"2025-09-12T12:30:23Z","2026-09-10T03:50:58.113501288Z",[1901],{"type":1289,"score":1761},[1903,1905,1906,1907,1908,1910,1911],{"type":1293,"url":1904},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6638",{"type":1304,"url":1766},{"type":1304,"url":1768},{"type":1301,"url":1368},{"type":1304,"url":1909},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F6a6c933f-9ce8-4ded-8b3b-2c1444c61f36",{"type":1301,"url":1516},{"type":1293,"url":1912},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-59p9-h35m-wg4g",[1374,1375,1376,1377],{"id":127,"slug":1915,"dossier":47,"summary":1916,"aliases":1917,"sourceIds":1921,"published":1922,"modified":1923,"checkedAt":7,"severity":1924,"references":1928,"versionKeys":1945,"packageCount":32,"repositoryCount":34},"ghsa-5rjg-fvgr-3xxf-79d39e6b","setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write",[1918,1919,1920],"BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49",[127,1920],"2025-05-17T16:15:19Z","2026-09-10T03:50:24.253527717Z",[1925,1927],{"type":1330,"score":1926},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":1289,"score":1394},[1929,1931,1933,1935,1937,1939,1941,1943],{"type":1336,"url":1930},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fsecurity\u002Fadvisories\u002FGHSA-5rjg-fvgr-3xxf",{"type":1293,"url":1932},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-47273",{"type":1471,"url":1934},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fissues\u002F4946",{"type":1298,"url":1936},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002F250a6d17978f9f6ac3ac887091f2d32886fbbb0b",{"type":1304,"url":1938},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fsetuptools\u002FPYSEC-2025-49.yaml",{"type":1301,"url":1940},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools",{"type":1304,"url":1942},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fblob\u002F6ead555c5fb29bc57fe6105b1bffc163f56fd558\u002Fsetuptools\u002Fpackage_index.py#L810C1-L825C88",{"type":1307,"url":1944},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F05\u002Fmsg00035.html",[1946,1947,1948,1949],"pypi:setuptools@69.2.0","pypi:setuptools@72.2.0","pypi:setuptools@75.8.0","pypi:setuptools@78.1.0",{"id":128,"slug":1951,"dossier":90,"summary":1952,"aliases":1953,"sourceIds":1957,"published":1958,"modified":1959,"checkedAt":7,"severity":1960,"references":1962,"versionKeys":1972,"packageCount":32,"repositoryCount":1693},"ghsa-5x94-69rx-g8h2-0bc05f88","Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`",[1954,1955,1956],"BIT-pillow-2026-54060","CVE-2026-54060","PYSEC-2026-2254",[128,1956],"2026-07-06T19:17:08.270Z","2026-09-10T03:51:10.514604451Z",[1961],{"type":1289,"score":1531},[1963,1965,1967,1968,1970,1971],{"type":1336,"url":1964},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-5x94-69rx-g8h2",{"type":1293,"url":1966},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54060",{"type":1298,"url":1676},{"type":1304,"url":1969},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2254.yaml",{"type":1301,"url":1680},{"type":1293,"url":1682},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":129,"slug":1974,"dossier":47,"summary":1975,"aliases":1976,"sourceIds":1980,"published":1981,"modified":1982,"checkedAt":7,"severity":1983,"references":1987,"versionKeys":1995,"packageCount":32,"repositoryCount":1996},"ghsa-5xmw-vc9v-4wf2-86a8861a","Pillow has a heap buffer overflow with nested list coordinates",[1977,1978,1979],"BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251",[129,1979],"2026-05-04T20:18:27Z","2026-09-10T03:51:04.701007027Z",[1984,1985],{"type":1289,"score":1466},{"type":1330,"score":1986},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[1988,1990,1992,1993],{"type":1293,"url":1989},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-5xmw-vc9v-4wf2",{"type":1293,"url":1991},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42309",{"type":1301,"url":1680},{"type":1293,"url":1994},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F12.2.0",[1687,1688,1689,1690,1691],12,{"id":130,"slug":1998,"dossier":47,"summary":1999,"aliases":2000,"sourceIds":2003,"published":2004,"modified":2005,"checkedAt":7,"severity":2006,"references":2009,"versionKeys":2019,"packageCount":32,"repositoryCount":103},"ghsa-5xxx-qhh7-9287-87d91b3e","GitPython: Incomplete unsafe_git_revision_options denylist omits --contents\u002F-S, enabling arbitrary file read via Repo.blame()",[2001,2002],"CVE-2026-78678","PYSEC-2026-3788",[130,2002],"2026-08-25T02:16:52.313Z","2026-09-08T19:00:06.904435463Z",[2007,2008],{"type":1289,"score":1610},{"type":1330,"score":1855},[2010,2012,2014,2015,2017],{"type":1336,"url":2011},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-5xxx-qhh7-9287",{"type":1293,"url":2013},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78678",{"type":1301,"url":1341},{"type":1304,"url":2016},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3788.yaml",{"type":1293,"url":2018},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-repo-blame",[1347,1348,1349],{"id":131,"slug":2021,"dossier":90,"summary":2022,"aliases":2023,"sourceIds":2027,"published":2028,"modified":2029,"checkedAt":7,"severity":2030,"references":2033,"versionKeys":2049,"packageCount":32,"repositoryCount":1693},"ghsa-62p4-gmf7-7g93-cb81341c","Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)",[2024,2025,2026],"BIT-pillow-2026-54058","CVE-2026-54058","PYSEC-2026-3493",[131,2026],"2026-07-20T21:08:13Z","2026-09-10T03:51:10.632149522Z",[2031],{"type":1330,"score":2032},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[2034,2036,2038,2040,2042,2043,2045,2047],{"type":1304,"url":2035},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-62p4-gmf7-7g93",{"type":1293,"url":2037},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54058",{"type":1304,"url":2039},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9719",{"type":1304,"url":2041},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F6a8de891fb00968e5ea79bfa84368ed90b3cfc1d",{"type":1301,"url":1680},{"type":1304,"url":2044},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F12.3.0",{"type":1301,"url":2046},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fpillow",{"type":1293,"url":2048},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-62p4-gmf7-7g93",[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":132,"slug":2051,"dossier":47,"summary":2052,"aliases":2053,"sourceIds":2056,"published":2057,"modified":2058,"checkedAt":7,"severity":2059,"references":2062,"versionKeys":2085,"packageCount":32,"repositoryCount":394},"ghsa-6497-prx7-gpmq-2b8ee85d","geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure",[2054,2055],"CVE-2025-69662","PYSEC-2026-62",[132,2055],"2026-01-30T19:16:11.967Z","2026-06-10T17:01:18.172032507Z",[2060],{"type":1289,"score":2061},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[2063,2065,2067,2069,2071,2073,2075,2077,2079,2081,2083],{"type":1293,"url":2064},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69662",{"type":1304,"url":2066},"https:\u002F\u002Fgithub.com\u002Fgeopandas\u002Fgeopandas\u002Fissues\u002F3679",{"type":1298,"url":2068},"https:\u002F\u002Fgithub.com\u002Fgeopandas\u002Fgeopandas\u002Fpull\u002F3681",{"type":1304,"url":2070},"https:\u002F\u002Fgithub.com\u002Fgeopandas\u002Fgeopandas\u002Fcommit\u002F6aa8ef14ffdee4ba1044349ab948e1a1fbfaf419",{"type":1304,"url":2072},"https:\u002F\u002Faydinnyunus.github.io\u002F2025\u002F12\u002F27\u002Fsql-injection-geopandas",{"type":1301,"url":2074},"https:\u002F\u002Fgithub.com\u002Fgeopandas\u002Fgeopandas",{"type":1304,"url":2076},"https:\u002F\u002Fgithub.com\u002Fgeopandas\u002Fgeopandas\u002Freleases\u002Ftag\u002Fv1.1.2",{"type":1304,"url":2078},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgeopandas\u002FPYSEC-2026-62.yaml",{"type":1304,"url":2080},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F04\u002Fmsg00025.html",{"type":1336,"url":2082},"https:\u002F\u002Faydinnyunus.github.io\u002F2025\u002F12\u002F27\u002Fsql-injection-geopandas\u002F",{"type":1293,"url":2084},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6497-prx7-gpmq",[2086],"pypi:geopandas@1.0.1",{"id":133,"slug":2088,"dossier":90,"summary":2089,"aliases":2090,"sourceIds":2093,"published":2094,"modified":2095,"checkedAt":7,"severity":2096,"references":2100,"versionKeys":2109,"packageCount":32,"repositoryCount":2114},"ghsa-65pc-fj4g-8rjx-9fe9e88a","Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix",[2091,2092],"CVE-2026-45409","PYSEC-2026-215",[133,2092],"2026-05-19T14:34:32Z","2026-09-10T03:50:45.700124422Z",[2097,2098],{"type":1289,"score":1504},{"type":1330,"score":2099},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[2101,2103,2105,2107],{"type":1293,"url":2102},"https:\u002F\u002Fgithub.com\u002Fkjd\u002Fidna\u002Fsecurity\u002Fadvisories\u002FGHSA-65pc-fj4g-8rjx",{"type":1293,"url":2104},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45409",{"type":1301,"url":2106},"https:\u002F\u002Fgithub.com\u002Fkjd\u002Fidna",{"type":1304,"url":2108},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fidna\u002FPYSEC-2026-215.yaml",[2110,2111,2112,2113],"pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.14","pypi:idna@3.7",21,{"id":134,"slug":2116,"dossier":47,"summary":2117,"aliases":2118,"sourceIds":2121,"published":2122,"modified":2123,"checkedAt":7,"severity":2124,"references":2129,"versionKeys":2141,"packageCount":32,"repositoryCount":42},"ghsa-69w3-r845-3855-1b4edc28","HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class",[2119,2120],"CVE-2026-1839","PYSEC-2026-2288",[134,2120],"2026-04-07T06:16:41.490Z","2026-09-10T03:50:43.300048881Z",[2125,2127],{"type":1289,"score":2126},"CVSS:3.0\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:H",{"type":1289,"score":2128},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2130,2132,2134,2135,2137,2139],{"type":1293,"url":2131},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-1839",{"type":1298,"url":2133},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F03c8082ba4594c9b8d6fe190ca9bed0e5f8ca396",{"type":1301,"url":1368},{"type":1304,"url":2136},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Freleases\u002Ftag\u002Fv5.0.0rc3",{"type":1336,"url":2138},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F3c77bb97-e493-493d-9a88-c57f5c536485",{"type":1293,"url":2140},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-69w3-r845-3855",[1374,1375,1376,1377,1378,1379,1380,1381,1382],{"id":135,"slug":2143,"dossier":47,"summary":2144,"aliases":2145,"sourceIds":2148,"published":2149,"modified":2150,"checkedAt":7,"severity":2151,"references":2155,"versionKeys":2167,"packageCount":32,"repositoryCount":103},"ghsa-6p8h-3wgx-97gf-635a010c","GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks",[2146,2147],"CVE-2026-73623","PYSEC-2026-3952",[135,2147],"2026-07-24T16:42:09Z","2026-09-10T13:11:03.995690741Z",[2152,2154],{"type":1289,"score":2153},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1289,"score":1394},[2156,2158,2160,2162,2163,2165],{"type":1336,"url":2157},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-6p8h-3wgx-97gf",{"type":1304,"url":2159},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2180",{"type":1304,"url":2161},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fffcb5359e87619f4fe4a70a4aff5f08c5580ba97",{"type":1301,"url":1341},{"type":1304,"url":2164},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.54",{"type":1293,"url":2166},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-template",[1347,1348,1349],{"id":136,"slug":2169,"dossier":90,"summary":2170,"aliases":2171,"sourceIds":2175,"published":2176,"modified":2177,"checkedAt":7,"severity":2178,"references":2180,"versionKeys":2193,"packageCount":32,"repositoryCount":1693},"ghsa-6r8x-57c9-28j4-3a620dbf","Pillow: Heap out-of-bounds write `Image.paste()` \u002F `Image.crop()` via signed coordinate overflow",[2172,2173,2174],"BIT-pillow-2026-59199","CVE-2026-59199","PYSEC-2026-3451",[136,2174],"2026-07-14T16:17:01.937Z","2026-09-10T03:51:10.822199342Z",[2179],{"type":1289,"score":1531},[2181,2183,2185,2187,2189,2191,2192],{"type":1336,"url":2182},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-6r8x-57c9-28j4",{"type":1293,"url":2184},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59199",{"type":1298,"url":2186},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9703",{"type":1298,"url":2188},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",{"type":1304,"url":2190},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3451.yaml",{"type":1301,"url":1680},{"type":1293,"url":2044},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":137,"slug":2195,"dossier":47,"summary":2196,"aliases":2197,"sourceIds":2200,"published":2201,"modified":2202,"checkedAt":7,"severity":2203,"references":2205,"versionKeys":2216,"packageCount":32,"repositoryCount":32},"ghsa-6rvg-6v2m-4j46-e04ee614","Transformers Regular Expression Denial of Service (ReDoS) vulnerability",[2198,2199],"CVE-2024-12720","PYSEC-2026-1982",[137,2199],"2025-03-20T12:32:43Z","2026-08-13T20:11:58.209202163Z",[2204],{"type":1289,"score":1761},[2206,2208,2210,2211,2213,2214],{"type":1293,"url":2207},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-12720",{"type":1304,"url":2209},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fdeac971c469bcbb182c2e52da0b82fb3bf54cccf",{"type":1301,"url":1368},{"type":1304,"url":2212},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F4bed1214-7835-4252-a853-22bbad891f98",{"type":1301,"url":1516},{"type":1293,"url":2215},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6rvg-6v2m-4j46",[1374],{"id":138,"slug":2218,"dossier":47,"summary":2219,"aliases":2220,"sourceIds":2223,"published":2224,"modified":2225,"checkedAt":7,"severity":2226,"references":2231,"versionKeys":2239,"packageCount":32,"repositoryCount":103},"ghsa-7545-fcxq-7j24-84dd19fd","GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository",[2221,2222],"CVE-2026-44243","PYSEC-2026-2162",[138,2222],"2026-05-06T19:38:48Z","2026-09-10T03:50:45.903378498Z",[2227,2229],{"type":1289,"score":2228},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",{"type":1330,"score":2230},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[2232,2234,2236,2237],{"type":1336,"url":2233},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-7545-fcxq-7j24",{"type":1293,"url":2235},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44243",{"type":1301,"url":1341},{"type":1298,"url":2238},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.48",[1347,1348,1349],{"id":139,"slug":2241,"dossier":47,"summary":2242,"aliases":2243,"sourceIds":2246,"published":2247,"modified":2248,"checkedAt":7,"severity":2249,"references":2252,"versionKeys":2265,"packageCount":32,"repositoryCount":355},"ghsa-768j-98cg-p3fv-0815ff07","fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib",[2244,2245],"CVE-2025-66034","PYSEC-2026-1389",[139,2245],"2025-12-01T19:07:00Z","2026-09-10T03:50:31.754255627Z",[2250],{"type":1289,"score":2251},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:C\u002FC:N\u002FI:H\u002FA:L",[2253,2255,2257,2259,2261,2263],{"type":1304,"url":2254},"https:\u002F\u002Fgithub.com\u002Ffonttools\u002Ffonttools\u002Fsecurity\u002Fadvisories\u002FGHSA-768j-98cg-p3fv",{"type":1293,"url":2256},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66034",{"type":1304,"url":2258},"https:\u002F\u002Fgithub.com\u002Ffonttools\u002Ffonttools\u002Fcommit\u002Fa696d5ba93270d5954f98e7cab5ddca8a02c1e32",{"type":1301,"url":2260},"https:\u002F\u002Fgithub.com\u002Ffonttools\u002Ffonttools",{"type":1301,"url":2262},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ffonttools",{"type":1293,"url":2264},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-768j-98cg-p3fv",[2266,2267,2268,2269,2270,2271],"pypi:fonttools@4.55.3","pypi:fonttools@4.55.8","pypi:fonttools@4.57.0","pypi:fonttools@4.58.0","pypi:fonttools@4.58.5","pypi:fonttools@4.59.2",{"id":140,"slug":2273,"dossier":47,"summary":2274,"aliases":2275,"sourceIds":2278,"published":2279,"modified":2280,"checkedAt":7,"severity":2281,"references":2288,"versionKeys":2303,"packageCount":32,"repositoryCount":103},"ghsa-7833-fr7j-v32q-fd003872","GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)",[2276,2277],"CVE-2026-78675","PYSEC-2026-3785",[140,2277],"2026-08-25T02:16:51.887Z","2026-09-23T05:15:05.931147061Z",[2282,2284,2286],{"type":1289,"score":2283},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1330,"score":2285},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":1289,"score":2287},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2289,2291,2293,2295,2297,2298,2299,2301],{"type":1336,"url":2290},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-7833-fr7j-v32q",{"type":1293,"url":2292},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78675",{"type":1304,"url":2294},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2211",{"type":1304,"url":2296},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fef7568e3b317ce617eacda39b8b54dcdff8c3b5c",{"type":1301,"url":1341},{"type":1304,"url":1622},{"type":1304,"url":2300},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3785.yaml",{"type":1293,"url":2302},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-local-file-content-disclosure-via-gitmodules",[1347,1348,1349],{"id":141,"slug":2305,"dossier":47,"summary":2306,"aliases":2307,"sourceIds":2311,"published":2312,"modified":2313,"checkedAt":7,"severity":2314,"references":2321,"versionKeys":2333,"packageCount":32,"repositoryCount":66},"ghsa-78cv-mqj4-43f7-2021f695","Tornado has incomplete validation of cookie attributes",[2308,2309,2310],"CVE-2026-35536","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287",[141,2309,2310],"2026-03-11T22:17:00Z","2026-09-10T03:50:44.255695398Z",[2315,2317,2319],{"type":1289,"score":2316},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:N",{"type":1289,"score":2318},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N",{"type":1289,"score":2320},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",[2322,2324,2326,2327,2329,2331],{"type":1293,"url":2323},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-78cv-mqj4-43f7",{"type":1304,"url":2325},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F24a2d96ea115f663b223887deb0060f13974c104",{"type":1301,"url":1645},{"type":1304,"url":2328},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.5",{"type":1293,"url":2330},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-35536",{"type":1293,"url":2332},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fqwm-6jpj-5wxc",[1653,1654,1655,1656],{"id":142,"slug":2335,"dossier":47,"summary":2336,"aliases":2337,"sourceIds":2340,"published":2341,"modified":2342,"checkedAt":7,"severity":2343,"references":2345,"versionKeys":2358,"packageCount":32,"repositoryCount":394},"ghsa-7cx3-6m66-7c5m-cde5125c","Tornado vulnerable to excessive logging caused by malformed multipart form data",[2338,2339],"CVE-2025-47287","PYSEC-2026-1974",[142,2339],"2025-05-16T14:12:40Z","2026-09-10T03:50:24.284224963Z",[2344],{"type":1289,"score":1531},[2346,2348,2350,2352,2353,2355,2356],{"type":1304,"url":2347},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-7cx3-6m66-7c5m",{"type":1293,"url":2349},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-47287",{"type":1304,"url":2351},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fb39b892bf78fe8fea01dd45199aa88307e7162f3",{"type":1301,"url":1645},{"type":1304,"url":2354},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F05\u002Fmsg00038.html",{"type":1301,"url":1647},{"type":1293,"url":2357},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7cx3-6m66-7c5m",[1653],{"id":143,"slug":2360,"dossier":47,"summary":2361,"aliases":2362,"sourceIds":2365,"published":2366,"modified":2367,"checkedAt":7,"severity":2368,"references":2371,"versionKeys":2388,"packageCount":32,"repositoryCount":345},"ghsa-7gcm-g887-7qv7-55bb9ff1","protobuf affected by a JSON recursion depth bypass",[2363,2364],"CVE-2026-0994","PYSEC-2026-1805",[143,2364],"2026-01-23T15:31:35Z","2026-09-10T03:50:32.795512159Z",[2369],{"type":1330,"score":2370},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:L",[2372,2374,2376,2378,2380,2382,2384,2386],{"type":1293,"url":2373},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0994",{"type":1304,"url":2375},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fissues\u002F25070",{"type":1304,"url":2377},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fpull\u002F25239",{"type":1304,"url":2379},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002F5ebddcb1bcbe51d1fe323baa145e85f4f23128cf",{"type":1304,"url":2381},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002Fd2b001626d137c62dfee6c88c87324102531868b",{"type":1301,"url":2383},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf",{"type":1301,"url":2385},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fprotobuf",{"type":1293,"url":2387},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7gcm-g887-7qv7",[2389,2390,2391,2392,2393,2394,2395,2396,2397,2398],"pypi:protobuf@4.25.7","pypi:protobuf@4.25.8","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4","pypi:protobuf@6.31.1","pypi:protobuf@6.32.0","pypi:protobuf@6.32.1","pypi:protobuf@6.33.0","pypi:protobuf@6.33.1","pypi:protobuf@6.33.4",{"id":144,"slug":2400,"dossier":47,"summary":2401,"aliases":2402,"sourceIds":2405,"published":2406,"modified":2407,"checkedAt":7,"severity":2408,"references":2413,"versionKeys":2424,"packageCount":32,"repositoryCount":375},"ghsa-7p48-42j8-8846-584b0522","Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)",[2403,2404],"CVE-2026-33682","PYSEC-2026-2285",[144,2404],"2026-03-25T21:20:52Z","2026-07-13T07:26:25.253864212Z",[2409,2411],{"type":1289,"score":2410},"CVSS:3.1\u002FAV:A\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N",{"type":1289,"score":2412},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[2414,2416,2418,2420,2422],{"type":1293,"url":2415},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fsecurity\u002Fadvisories\u002FGHSA-7p48-42j8-8846",{"type":1293,"url":2417},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33682",{"type":1298,"url":2419},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fcommit\u002F23692ca70b2f2ac720c72d1feb4f190c9d6eed76",{"type":1301,"url":2421},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit",{"type":1293,"url":2423},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Freleases\u002Ftag\u002F1.54.0",[2425,2426,2427],"pypi:streamlit@1.49.0","pypi:streamlit@1.49.1","pypi:streamlit@1.51.0",{"id":145,"slug":2429,"dossier":47,"summary":2430,"aliases":2431,"sourceIds":2433,"published":2434,"modified":2435,"checkedAt":7,"severity":2436,"references":2438,"versionKeys":2450,"packageCount":32,"repositoryCount":2452},"ghsa-8423-8fgw-73vq-142b238e","tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)",[2432],"CVE-2026-91990",[145],"2026-09-01T20:17:38Z","2026-09-16T03:56:01.992806508Z",[2437],{"type":1330,"score":2099},[2439,2441,2443,2445,2447,2448],{"type":1304,"url":2440},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-8423-8fgw-73vq",{"type":1304,"url":2442},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fpull\u002F3704",{"type":1304,"url":2444},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fde85b3f87446e323e881bbaa3d5a74f4b76e5f05",{"type":1304,"url":2446},"https:\u002F\u002Fgist.github.com\u002Fafldl\u002F649861f25d39b53b7edbe0298e171617",{"type":1301,"url":1645},{"type":1304,"url":2449},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.8",[1653,1654,1655,1656,1657,2451],"pypi:tornado@6.5.7",10,{"id":146,"slug":2454,"dossier":47,"summary":2455,"aliases":2456,"sourceIds":2460,"published":2461,"modified":2462,"checkedAt":7,"severity":2463,"references":2467,"versionKeys":2489,"packageCount":32,"repositoryCount":1720},"ghsa-887c-mr87-cxwp-233a2961","PyTorch Improper Resource Shutdown or Release vulnerability",[2457,2458,2459],"BIT-pytorch-2025-3730","CVE-2025-3730","PYSEC-2026-1970",[146,2459],"2025-04-16T21:30:59Z","2026-09-10T03:50:23.660138570Z",[2464,2465],{"type":1289,"score":1462},{"type":1330,"score":2466},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[2468,2470,2472,2474,2476,2478,2479,2481,2483,2485,2487],{"type":1293,"url":2469},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3730",{"type":1304,"url":2471},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F150835",{"type":1304,"url":2473},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F150981",{"type":1304,"url":2475},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F01f226bfb8f2c343f5c614a6bbf685d91160f3af",{"type":1304,"url":2477},"https:\u002F\u002Fgithub.com\u002Ftimocafe\u002Ftewart-pytorch\u002Fcommit\u002F46fc5d8e360127361211cb237d5f9eef0223e567",{"type":1301,"url":1478},{"type":1304,"url":2480},"https:\u002F\u002Fvuldb.com\u002F?ctiid.305076",{"type":1304,"url":2482},"https:\u002F\u002Fvuldb.com\u002F?id.305076",{"type":1304,"url":2484},"https:\u002F\u002Fvuldb.com\u002F?submit.553645",{"type":1301,"url":2486},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftorch",{"type":1293,"url":2488},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-887c-mr87-cxwp",[1490,1491,1492,2490,2491],"pypi:torch@2.7.1","pypi:torch@2.7.1+cpu",{"id":147,"slug":2493,"dossier":47,"summary":2494,"aliases":2495,"sourceIds":2498,"published":2499,"modified":2500,"checkedAt":7,"severity":2501,"references":2508,"versionKeys":2523,"packageCount":32,"repositoryCount":103},"ghsa-8mcc-hrx5-hvxc-9da62a9f","GitPython: clone_from()\u002Fclone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination",[2496,2497],"CVE-2026-78677","PYSEC-2026-3787",[147,2497],"2026-08-25T02:16:52.173Z","2026-09-08T19:00:06.914140693Z",[2502,2504,2506],{"type":1289,"score":2503},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":1330,"score":2505},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",{"type":1330,"score":2507},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[2509,2511,2513,2515,2517,2518,2519,2521],{"type":1336,"url":2510},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-8mcc-hrx5-hvxc",{"type":1293,"url":2512},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-78677",{"type":1304,"url":2514},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2210",{"type":1304,"url":2516},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fb68afff45af0f49e79a3e2d2162018986b37ad5d",{"type":1301,"url":1341},{"type":1304,"url":1622},{"type":1304,"url":2520},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3787.yaml",{"type":1293,"url":2522},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-path-traversal-via-separate-git-dir",[1347,1348,1349],{"id":148,"slug":2525,"dossier":47,"summary":2526,"aliases":2527,"sourceIds":2530,"published":2531,"modified":2532,"checkedAt":7,"severity":2533,"references":2536,"versionKeys":2555,"packageCount":32,"repositoryCount":375},"ghsa-8qvm-5x2c-j2w7-8a075519","protobuf-python has a potential Denial of Service issue",[2528,2529],"CVE-2025-4565","PYSEC-2026-1806",[148,2529],"2025-06-16T16:02:58Z","2026-09-10T03:50:25.255076549Z",[2534],{"type":1330,"score":2535},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[2537,2539,2541,2543,2545,2546,2548,2550,2552,2553],{"type":1304,"url":2538},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fsecurity\u002Fadvisories\u002FGHSA-735f-pc8j-v9w8",{"type":1304,"url":2540},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fsecurity\u002Fadvisories\u002FGHSA-8qvm-5x2c-j2w7",{"type":1293,"url":2542},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-4565",{"type":1304,"url":2544},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002F17838beda2943d08b8a9d4df5b68f5f04f26d901",{"type":1301,"url":2383},{"type":1304,"url":2547},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fblob\u002Fmain\u002Fpython\u002Fgoogle\u002Fprotobuf\u002Finternal\u002Fdecoder_test.py#L87-L98",{"type":1304,"url":2549},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fblob\u002Fmain\u002Fpython\u002Fgoogle\u002Fprotobuf\u002Finternal\u002Fmessage_test.py#L1436-L1478",{"type":1304,"url":2551},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Ftree\u002Fmain\u002Fpython#implementation-backends",{"type":1301,"url":2385},{"type":1293,"url":2554},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-8qvm-5x2c-j2w7",[2389,2391,2392],{"id":149,"slug":2557,"dossier":90,"summary":2558,"aliases":2559,"sourceIds":2563,"published":2564,"modified":2565,"checkedAt":7,"severity":2566,"references":2568,"versionKeys":2578,"packageCount":32,"repositoryCount":1693},"ghsa-8v84-f9pq-wr9x-6c1b185f","Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading",[2560,2561,2562],"BIT-pillow-2026-54059","CVE-2026-54059","PYSEC-2026-2253",[149,2562],"2026-07-06T19:17:08.127Z","2026-09-10T03:51:11.229114807Z",[2567],{"type":1289,"score":1531},[2569,2571,2573,2574,2576,2577],{"type":1336,"url":2570},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-8v84-f9pq-wr9x",{"type":1293,"url":2572},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54059",{"type":1298,"url":1676},{"type":1304,"url":2575},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2253.yaml",{"type":1301,"url":1680},{"type":1293,"url":1682},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":150,"slug":2580,"dossier":47,"summary":2581,"aliases":2582,"sourceIds":2585,"published":2586,"modified":2587,"checkedAt":7,"severity":2588,"references":2590,"versionKeys":2603,"packageCount":32,"repositoryCount":34},"ghsa-9356-575x-2w9m-908a1f8c","Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability",[2583,2584],"CVE-2025-5197","PYSEC-2026-1983",[150,2584],"2025-08-06T12:31:20Z","2026-09-10T03:50:26.988216861Z",[2589],{"type":1289,"score":1761},[2591,2593,2595,2597,2598,2600,2601],{"type":1293,"url":2592},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-5197",{"type":1304,"url":2594},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F701caef704e356dc2f9331cc3fd5df0eccb4720a",{"type":1304,"url":2596},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F944b56000be5e9b61af8301aa340838770ad8a0b",{"type":1301,"url":1368},{"type":1304,"url":2599},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F3f8b3fd0-166b-46e7-b60f-60dd9d2678bf",{"type":1301,"url":1516},{"type":1293,"url":2602},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9356-575x-2w9m",[1374,1375,1376,1377],{"id":151,"slug":2605,"dossier":47,"summary":2606,"aliases":2607,"sourceIds":2610,"published":2611,"modified":2612,"checkedAt":7,"severity":2613,"references":2616,"versionKeys":2630,"packageCount":32,"repositoryCount":103},"ghsa-94p4-4cq8-9g67-9a288a09","GitPython: Environment-variable exfiltration via Repo.create_remote() \u002F Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)",[2608,2609],"CVE-2026-73622","PYSEC-2026-3951",[151,2609],"2026-07-24T21:45:16Z","2026-09-24T14:45:07.411775302Z",[2614,2615],{"type":1289,"score":2503},{"type":1330,"score":2507},[2617,2619,2621,2623,2624,2626,2628],{"type":1336,"url":2618},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-94p4-4cq8-9g67",{"type":1304,"url":2620},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F863417457a0633db7ea5aed4fd01e0b291a41162",{"type":1298,"url":2622},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F8ac5a30519b6f4af85398b9b9d7064ff4d452da2",{"type":1301,"url":1341},{"type":1304,"url":2625},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.55",{"type":1304,"url":2627},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3951.yaml",{"type":1293,"url":2629},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-environment-variable-exfiltration-via-remote-add",[1347,1348,1349],{"id":152,"slug":2632,"dossier":47,"summary":2633,"aliases":2634,"sourceIds":2637,"published":2638,"modified":2639,"checkedAt":7,"severity":2640,"references":2642,"versionKeys":2658,"packageCount":32,"repositoryCount":103},"ghsa-956x-8gvw-wg5v-f5d32b2d","GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` \u002F `Repo.blame()`",[2635,2636],"CVE-2026-67323","PYSEC-2026-3839",[152,2636],"2026-07-21T20:10:06Z","2026-09-10T12:25:39.217544351Z",[2641],{"type":1289,"score":2283},[2643,2645,2647,2649,2651,2652,2653,2655,2656],{"type":1304,"url":2644},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-956x-8gvw-wg5v",{"type":1293,"url":2646},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-67323",{"type":1304,"url":2648},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2163",{"type":1304,"url":2650},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F701ce32fe5ba8cb622c0e0342a376a6beb47d738",{"type":1301,"url":1341},{"type":1304,"url":1406},{"type":1304,"url":2654},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-command-injection-via-unguarded-git-options",{"type":1301,"url":1410},{"type":1293,"url":2657},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-956x-8gvw-wg5v",[1347,1348,1349],{"id":153,"slug":2660,"dossier":47,"summary":2661,"aliases":2662,"sourceIds":2665,"published":2666,"modified":2667,"checkedAt":7,"severity":2668,"references":2671,"versionKeys":2690,"packageCount":32,"repositoryCount":1720},"ghsa-9hjg-9r4m-mvj7-32d7b63e","Requests vulnerable to .netrc credentials leak via malicious URLs",[2663,2664],"CVE-2024-47081","PYSEC-2026-1872",[153,2664],"2025-06-09T19:06:08Z","2026-09-10T03:50:25.139398550Z",[2669],{"type":1289,"score":2670},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[2672,2674,2676,2678,2680,2682,2684,2686,2688],{"type":1304,"url":2673},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-9hjg-9r4m-mvj7",{"type":1293,"url":2675},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47081",{"type":1304,"url":2677},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fpull\u002F6965",{"type":1298,"url":2679},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002F96ba401c1296ab1dda74a2365ef36d88f7d144ef",{"type":1301,"url":2681},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests",{"type":1304,"url":2683},"https:\u002F\u002Frequests.readthedocs.io\u002Fen\u002Flatest\u002Fapi\u002F#requests.Session.trust_env",{"type":1304,"url":2685},"https:\u002F\u002Fseclists.org\u002Ffulldisclosure\u002F2025\u002FJun\u002F2",{"type":1301,"url":2687},"https:\u002F\u002Fpypi.org\u002Fproject\u002Frequests",{"type":1293,"url":2689},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9hjg-9r4m-mvj7",[2691,2692],"pypi:requests@2.31.0","pypi:requests@2.32.3",{"id":154,"slug":2694,"dossier":90,"summary":2695,"aliases":2696,"sourceIds":2700,"published":2701,"modified":2702,"checkedAt":7,"severity":2703,"references":2705,"versionKeys":2718,"packageCount":32,"repositoryCount":1693},"ghsa-9hw9-ch79-4vh6-1ebda54f","Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch",[2697,2698,2699],"BIT-pillow-2026-59205","CVE-2026-59205","PYSEC-2026-3453",[154,2699],"2026-07-14T16:17:02.370Z","2026-09-10T03:51:11.334365483Z",[2704],{"type":1289,"score":1531},[2706,2708,2710,2712,2714,2716,2717],{"type":1336,"url":2707},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-9hw9-ch79-4vh6",{"type":1293,"url":2709},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59205",{"type":1298,"url":2711},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9715",{"type":1298,"url":2713},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fa9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721",{"type":1304,"url":2715},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3453.yaml",{"type":1301,"url":1680},{"type":1293,"url":2044},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":155,"slug":2720,"dossier":47,"summary":2721,"aliases":2722,"sourceIds":2725,"published":2726,"modified":2727,"checkedAt":7,"severity":2728,"references":2730,"versionKeys":2745,"packageCount":32,"repositoryCount":103},"ghsa-9rj7-rf2p-w77r-996a0359","GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks",[2723,2724],"CVE-2026-76218","PYSEC-2026-3840",[155,2724],"2026-08-07T15:36:43Z","2026-09-10T12:25:55.324487522Z",[2729],{"type":1289,"score":2153},[2731,2733,2735,2736,2738,2739,2740,2742,2743],{"type":1304,"url":2732},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-9rj7-rf2p-w77r",{"type":1293,"url":2734},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76218",{"type":1304,"url":1738},{"type":1304,"url":2737},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fd9ddb55bdc66",{"type":1301,"url":1341},{"type":1304,"url":1743},{"type":1304,"url":2741},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-repo-init",{"type":1301,"url":1410},{"type":1293,"url":2744},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9rj7-rf2p-w77r",[1347,1348,1349],{"id":156,"slug":2747,"dossier":47,"summary":2748,"aliases":2749,"sourceIds":2752,"published":2753,"modified":2754,"checkedAt":7,"severity":2755,"references":2758,"versionKeys":2775,"packageCount":32,"repositoryCount":32},"ghsa-9wx4-h78v-vm56-6a334c57","Requests `Session` object does not verify requests after making first request with verify=False",[2750,2751],"CVE-2024-35195","PYSEC-2026-1873",[156,2751],"2024-05-20T20:15:00Z","2026-09-10T03:50:13.740879755Z",[2756],{"type":1289,"score":2757},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[2759,2761,2763,2765,2767,2768,2770,2772,2773],{"type":1304,"url":2760},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-9wx4-h78v-vm56",{"type":1293,"url":2762},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35195",{"type":1304,"url":2764},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fpull\u002F6655",{"type":1298,"url":2766},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002Fa58d7f2ffb4d00b46dca2d70a3932a0b37e22fac",{"type":1301,"url":2681},{"type":1304,"url":2769},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FIYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q",{"type":1304,"url":2771},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FN7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ",{"type":1301,"url":2687},{"type":1293,"url":2774},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9wx4-h78v-vm56",[2691],{"id":157,"slug":2777,"dossier":47,"summary":2778,"aliases":2779,"sourceIds":2783,"published":2784,"modified":2785,"checkedAt":7,"severity":2786,"references":2791,"versionKeys":2807,"packageCount":32,"repositoryCount":394},"ghsa-c678-jfcj-6jmf-cd9a8774","PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument",[2780,2781,2782],"BIT-pytorch-2025-2148","CVE-2025-2148","PYSEC-2025-189",[157],"2025-03-10T12:30:55Z","2026-06-09T21:26:06.844649427Z",[2787,2789],{"type":1289,"score":2788},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":1330,"score":2790},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[2792,2794,2796,2798,2799,2801,2803,2805],{"type":1293,"url":2793},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2148",{"type":1304,"url":2795},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147722",{"type":1304,"url":2797},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-189.yaml",{"type":1301,"url":1478},{"type":1304,"url":2800},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fblob\u002Fb0a67c7495bb11ecb23e556058db059ba48354af\u002Ftorch\u002Fautograd\u002Fprofiler.py#L990",{"type":1304,"url":2802},"https:\u002F\u002Fvuldb.com\u002F?ctiid.299059",{"type":1304,"url":2804},"https:\u002F\u002Fvuldb.com\u002F?id.299059",{"type":1304,"url":2806},"https:\u002F\u002Fvuldb.com\u002F?submit.505959",[1490,1491],{"id":158,"slug":2809,"dossier":47,"summary":2810,"aliases":2811,"sourceIds":2814,"published":2815,"modified":2816,"checkedAt":7,"severity":2817,"references":2819,"versionKeys":2831,"packageCount":32,"repositoryCount":1720},"ghsa-c98p-7wgm-6p64-ef7ac7e3","Tornado: Quadratic DoS via Repeated Header Coalescing",[2812,2813],"CVE-2025-67725","PYSEC-2025-266",[158,2813],"2025-12-12T06:15:41.380Z","2026-07-20T19:15:27.567094965Z",[2818],{"type":1289,"score":1531},[2820,2822,2824,2826,2828,2829],{"type":1293,"url":2821},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-c98p-7wgm-6p64",{"type":1293,"url":2823},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67725",{"type":1298,"url":2825},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F771472cfdaeebc0d89a9cc46e249f8891a6b29cd",{"type":1304,"url":2827},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-266.yaml",{"type":1301,"url":1645},{"type":1293,"url":2830},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.3",[1653,1654,1655],{"id":159,"slug":2833,"dossier":47,"summary":2834,"aliases":2835,"sourceIds":2839,"published":2840,"modified":2841,"checkedAt":7,"severity":2842,"references":2845,"versionKeys":2885,"packageCount":32,"repositoryCount":104},"ghsa-cfh3-3jmp-rvhc-4e95572c","Pillow affected by out-of-bounds write when loading PSD images",[2836,2837,2838],"BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249",[159,2838],"2026-02-11T14:22:50Z","2026-09-10T03:50:59.393816085Z",[2843,2844],{"type":1330,"score":2285},{"type":1289,"score":1531},[2846,2848,2850,2852,2854,2856,2857,2859,2861,2863,2865,2867,2869,2871,2873,2875,2877,2879,2881,2883],{"type":1304,"url":2847},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-cfh3-3jmp-rvhc",{"type":1293,"url":2849},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25990",{"type":1304,"url":2851},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9427",{"type":1304,"url":2853},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F54ba4db542ad3c7b918812a4e2d69c27735a3199",{"type":1304,"url":2855},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F9000313cc5d4a31bdcdd6d7f0781101abab553aa",{"type":1301,"url":1680},{"type":1304,"url":2858},"https:\u002F\u002Fpillow.readthedocs.io\u002Fen\u002Fstable\u002Freleasenotes\u002F12.1.1.html",{"type":1304,"url":2860},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-25990",{"type":1304,"url":2862},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-25990.json",{"type":1293,"url":2864},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:10184",{"type":1293,"url":2866},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:14873",{"type":1293,"url":2868},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:14874",{"type":1293,"url":2870},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16174",{"type":1293,"url":2872},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:19712",{"type":1293,"url":2874},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:28385",{"type":1293,"url":2876},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:3461",{"type":1293,"url":2878},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:3462",{"type":1293,"url":2880},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4128",{"type":1293,"url":2882},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4942",{"type":1293,"url":2884},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:5168",[1684,1685,1686,1687,1688,1689,1690],{"id":160,"slug":2887,"dossier":47,"summary":2888,"aliases":2889,"sourceIds":2892,"published":2893,"modified":2894,"checkedAt":7,"severity":2895,"references":2898,"versionKeys":2915,"packageCount":32,"repositoryCount":394},"ghsa-cpwx-vrp4-4pq7-799bdc98","Jinja2 vulnerable to sandbox breakout through attr filter selecting format method",[2890,2891],"CVE-2025-27516","PYSEC-2026-1471",[160,2891],"2025-03-05T20:40:14Z","2026-09-10T03:49:48.526758681Z",[2896],{"type":1330,"score":2897},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:P\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[2899,2901,2903,2905,2907,2909,2911,2913],{"type":1304,"url":2900},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-cpwx-vrp4-4pq7",{"type":1293,"url":2902},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-27516",{"type":1298,"url":2904},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F90457bbf33b8662926ae65cdde4c4c32e756e403",{"type":1301,"url":2906},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja",{"type":1304,"url":2908},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F04\u002Fmsg00022.html",{"type":1304,"url":2910},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F04\u002Fmsg00045.html",{"type":1301,"url":2912},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fjinja2",{"type":1293,"url":2914},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cpwx-vrp4-4pq7",[2916,2917],"pypi:jinja2@3.1.3","pypi:jinja2@3.1.5",{"id":161,"slug":2919,"dossier":47,"summary":2920,"aliases":2921,"sourceIds":2924,"published":2925,"modified":2926,"checkedAt":7,"severity":2927,"references":2930,"versionKeys":2941,"packageCount":32,"repositoryCount":66},"ghsa-cx3h-4qpv-8hc9-3078b6fa","Tornado has out-of-bounds memory access via C extension",[2922,2923],"CVE-2026-49854","PYSEC-2026-3388",[161,2923],"2026-06-12T18:30:19Z","2026-09-10T03:50:49.232529305Z",[2928],{"type":1289,"score":2929},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[2931,2933,2934,2936,2937,2939],{"type":1304,"url":2932},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-cx3h-4qpv-8hc9",{"type":1301,"url":1645},{"type":1304,"url":2935},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.6",{"type":1301,"url":1647},{"type":1293,"url":2938},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cx3h-4qpv-8hc9",{"type":1293,"url":2940},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49854",[1653,1654,1655,1656,1657],{"id":162,"slug":2943,"dossier":47,"summary":2944,"aliases":2945,"sourceIds":2949,"published":2950,"modified":2951,"checkedAt":7,"severity":2952,"references":2957,"versionKeys":2973,"packageCount":32,"repositoryCount":32},"ghsa-cx63-2mw6-8hw5-1754ad59","setuptools vulnerable to Command Injection via package URL",[2946,2947,2948],"BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918",[162,2948],"2024-07-15T03:30:57Z","2026-09-10T03:50:16.663495061Z",[2953,2955],{"type":1289,"score":2954},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1330,"score":2956},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:A\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[2958,2960,2962,2964,2965,2967,2969,2971],{"type":1293,"url":2959},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-6345",{"type":1304,"url":2961},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fpull\u002F4332",{"type":1304,"url":2963},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002F88807c7062788254f654ea8c03427adc859321f0",{"type":1301,"url":1940},{"type":1304,"url":2966},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fd6362117-ad57-4e83-951f-b8141c6e7ca5",{"type":1304,"url":2968},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2024\u002F09\u002Fmsg00018.html",{"type":1301,"url":2970},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fsetuptools",{"type":1293,"url":2972},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cx63-2mw6-8hw5",[1946],{"id":163,"slug":2975,"dossier":47,"summary":2976,"aliases":2977,"sourceIds":2981,"published":2982,"modified":2983,"checkedAt":7,"severity":2984,"references":2989,"versionKeys":3007,"packageCount":32,"repositoryCount":394},"ghsa-f4hp-rmr7-r7v8-fe038cb7","PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function",[2978,2979,2980],"BIT-pytorch-2025-2998","CVE-2025-2998","PYSEC-2025-192",[163],"2025-03-31T15:30:48Z","2026-06-09T22:11:09.050788278Z",[2985,2987],{"type":1289,"score":2986},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":1330,"score":2988},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[2990,2992,2994,2996,2998,3000,3001,3003,3005],{"type":1293,"url":2991},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2998",{"type":1304,"url":2993},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149622",{"type":1304,"url":2995},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149622#issue-2935495265",{"type":1304,"url":2997},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F494518046816d29099b7d056a74ffa5c244fdcdd",{"type":1304,"url":2999},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-192.yaml",{"type":1301,"url":1478},{"type":1304,"url":3002},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302047",{"type":1304,"url":3004},"https:\u002F\u002Fvuldb.com\u002F?id.302047",{"type":1304,"url":3006},"https:\u002F\u002Fvuldb.com\u002F?submit.524151",[1490,1491],{"id":164,"slug":3009,"dossier":47,"summary":3010,"aliases":3011,"sourceIds":3014,"published":3015,"modified":3016,"checkedAt":7,"severity":3017,"references":3022,"versionKeys":3046,"packageCount":32,"repositoryCount":42},"ghsa-fgcw-684q-jj6r-9fe55ba1","huggingface\u002Ftransformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path",[3012,3013],"CVE-2026-5241","PYSEC-2026-2290",[164,3013],"2026-06-03T14:16:46.337Z","2026-09-10T03:50:49.345942449Z",[3018,3020],{"type":1289,"score":3019},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:N",{"type":1289,"score":3021},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[3023,3025,3027,3029,3031,3033,3035,3037,3038,3040,3042,3044],{"type":1293,"url":3024},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-5241",{"type":1298,"url":3026},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F676559d5022b74aaa0cee1cee0842b7f27c5320e",{"type":1293,"url":3028},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34456",{"type":1293,"url":3030},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:37275",{"type":1304,"url":3032},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:42644",{"type":1304,"url":3034},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-5241",{"type":1471,"url":3036},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2484384",{"type":1301,"url":1368},{"type":1304,"url":3039},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2026-2290.yaml",{"type":1336,"url":3041},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fceb3ce1a-4c45-497a-b25e-cb9a7685e619",{"type":1304,"url":3043},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-5241.json",{"type":1293,"url":3045},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fgcw-684q-jj6r",[1374,1375,1376,1377,1378,1379,1380,1381,1382],{"id":165,"slug":3048,"dossier":90,"summary":3049,"aliases":3050,"sourceIds":3054,"published":3055,"modified":3056,"checkedAt":7,"severity":3057,"references":3060,"versionKeys":3074,"packageCount":32,"repositoryCount":1693},"ghsa-fj7v-r99m-22gq-e36cfebd","Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images",[3051,3052,3053],"BIT-pillow-2026-59198","CVE-2026-59198","PYSEC-2026-3494",[165,3053],"2026-07-20T23:09:36Z","2026-09-10T03:50:51.891240357Z",[3058],{"type":1289,"score":3059},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:L",[3061,3063,3065,3067,3069,3070,3071,3072],{"type":1304,"url":3062},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-fj7v-r99m-22gq",{"type":1293,"url":3064},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59198",{"type":1304,"url":3066},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9709",{"type":1304,"url":3068},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Feada3cbd7fb9963ee90673fb7b5270124a0d5f4b",{"type":1301,"url":1680},{"type":1304,"url":2044},{"type":1301,"url":2046},{"type":1293,"url":3073},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fj7v-r99m-22gq",[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":166,"slug":3076,"dossier":47,"summary":3077,"aliases":3078,"sourceIds":3081,"published":3082,"modified":3083,"checkedAt":7,"severity":3084,"references":3087,"versionKeys":3097,"packageCount":32,"repositoryCount":103},"ghsa-fjr4-x663-mwxc-324b7aa5","GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)",[3079,3080],"CVE-2026-73624","PYSEC-2026-3995",[166,3080],"2026-07-24T16:41:20Z","2026-09-29T09:10:55.738617943Z",[3085,3086],{"type":1289,"score":1558},{"type":1330,"score":1560},[3088,3090,3091,3093,3094,3095],{"type":1336,"url":3089},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-fjr4-x663-mwxc",{"type":1304,"url":2159},{"type":1304,"url":3092},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1d51b891d7f236044a6aa17498ec682b63dad6e6",{"type":1301,"url":1341},{"type":1304,"url":2164},{"type":1293,"url":3096},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-overwrite-via-diff",[1347,1348,1349],{"id":167,"slug":3099,"dossier":47,"summary":2196,"aliases":3100,"sourceIds":3103,"published":3104,"modified":3105,"checkedAt":7,"severity":3106,"references":3109,"versionKeys":3120,"packageCount":32,"repositoryCount":32},"ghsa-fpwr-67px-3qhx-94f30126",[3101,3102],"CVE-2025-1194","PYSEC-2026-1984",[167,3102],"2025-04-29T12:30:21Z","2026-08-13T20:11:58.399313771Z",[3107],{"type":1289,"score":3108},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[3110,3112,3114,3115,3117,3118],{"type":1293,"url":3111},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-1194",{"type":1304,"url":3113},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F92c5ca9dd70de3ade2af2eb835c96215cc50e815",{"type":1301,"url":1368},{"type":1304,"url":3116},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F86f58dcd-683f-4adc-a735-849f51e9abb2",{"type":1301,"url":1516},{"type":1293,"url":3119},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fpwr-67px-3qhx",[1374],{"id":168,"slug":3122,"dossier":47,"summary":3123,"aliases":3124,"sourceIds":3127,"published":3128,"modified":3129,"checkedAt":7,"severity":3130,"references":3133,"versionKeys":3152,"packageCount":32,"repositoryCount":32},"ghsa-g7vv-2v7x-gj9p-5ef970c3","tqdm CLI arguments injection attack",[3125,3126],"CVE-2024-34062","PYSEC-2026-1976",[168,3126],"2024-05-03T19:33:28Z","2026-09-10T03:50:13.776534451Z",[3131],{"type":1289,"score":3132},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[3134,3136,3138,3140,3142,3144,3146,3148,3150],{"type":1304,"url":3135},"https:\u002F\u002Fgithub.com\u002Ftqdm\u002Ftqdm\u002Fsecurity\u002Fadvisories\u002FGHSA-g7vv-2v7x-gj9p",{"type":1293,"url":3137},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-34062",{"type":1304,"url":3139},"https:\u002F\u002Fgithub.com\u002Ftqdm\u002Ftqdm\u002Fcommit\u002F4e613f84ed2ae029559f539464df83fa91feb316",{"type":1301,"url":3141},"https:\u002F\u002Fgithub.com\u002Ftqdm\u002Ftqdm",{"type":1304,"url":3143},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FPA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6",{"type":1304,"url":3145},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FQRECVQCCESHBS3UJOWNXQUIX725TKNY6",{"type":1304,"url":3147},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FVA337CYUS4SLRFV2P6MX6MZ2LKFURKJC",{"type":1301,"url":3149},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftqdm",{"type":1293,"url":3151},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-g7vv-2v7x-gj9p",[3153],"pypi:tqdm@4.66.2",{"id":169,"slug":3155,"dossier":90,"summary":3156,"aliases":3157,"sourceIds":3160,"published":3161,"modified":3162,"checkedAt":7,"severity":3163,"references":3168,"versionKeys":3178,"packageCount":32,"repositoryCount":3181},"ghsa-gc5v-m9x4-r6x2-b9828ad8","Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function",[3158,3159],"CVE-2026-25645","PYSEC-2026-2275",[169,3159],"2026-03-25T16:56:28Z","2026-09-10T03:50:39.207922076Z",[3164,3166],{"type":1289,"score":3165},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:N",{"type":1289,"score":3167},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[3169,3171,3173,3175,3176],{"type":1293,"url":3170},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-gc5v-m9x4-r6x2",{"type":1293,"url":3172},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25645",{"type":1298,"url":3174},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002F66d21cb07bd6255b1280291c4fafb71803cdb3b7",{"type":1301,"url":2681},{"type":1293,"url":3177},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Freleases\u002Ftag\u002Fv2.33.0",[2691,2692,3179,3180],"pypi:requests@2.32.4","pypi:requests@2.32.5",18,{"id":170,"slug":3183,"dossier":47,"summary":3184,"aliases":3185,"sourceIds":3188,"published":3189,"modified":3190,"checkedAt":7,"severity":3191,"references":3193,"versionKeys":3204,"packageCount":32,"repositoryCount":1449},"ghsa-gm62-xv2j-4w53-5befa184","urllib3 allows an unbounded number of links in the decompression chain",[3186,3187],"CVE-2025-66418","PYSEC-2026-1998",[170,3187],"2025-12-05T18:15:19Z","2026-09-10T03:50:58.741847479Z",[3192],{"type":1330,"score":1425},[3194,3196,3198,3200,3201,3202],{"type":1304,"url":3195},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-gm62-xv2j-4w53",{"type":1293,"url":3197},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66418",{"type":1298,"url":3199},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F24d7b67eac89f94e11003424bcf0d8f7b72222a8",{"type":1301,"url":1440},{"type":1301,"url":1442},{"type":1293,"url":3203},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gm62-xv2j-4w53",[1444,1445,1446,1447,1448],{"id":171,"slug":3206,"dossier":47,"summary":3207,"aliases":3208,"sourceIds":3211,"published":3212,"modified":3213,"checkedAt":7,"severity":3214,"references":3217,"versionKeys":3232,"packageCount":32,"repositoryCount":32},"ghsa-gmj6-6f8f-6699-e3e02f35","Jinja has a sandbox breakout through malicious filenames",[3209,3210],"CVE-2024-56201","PYSEC-2026-1472",[171,3210],"2024-12-23T17:54:12Z","2026-09-10T03:50:56.152882717Z",[3215,3216],{"type":1289,"score":1394},{"type":1330,"score":2897},[3218,3220,3222,3224,3226,3227,3229,3230],{"type":1304,"url":3219},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-gmj6-6f8f-6699",{"type":1293,"url":3221},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56201",{"type":1304,"url":3223},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fissues\u002F1792",{"type":1298,"url":3225},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F767b23617628419ae3709ccfb02f9602ae9fe51f",{"type":1301,"url":2906},{"type":1304,"url":3228},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Freleases\u002Ftag\u002F3.1.5",{"type":1301,"url":2912},{"type":1293,"url":3231},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gmj6-6f8f-6699",[2916],{"id":172,"slug":3234,"dossier":90,"summary":3235,"aliases":3236,"sourceIds":3240,"published":3241,"modified":3242,"checkedAt":7,"severity":3243,"references":3246,"versionKeys":3258,"packageCount":32,"repositoryCount":3181},"ghsa-h35f-9h28-mq5c-f3238ba1","setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC\u002FNFD) on macOS APFS\u002FHFS+",[3237,3238,3239],"BIT-setuptools-2026-59890","CVE-2026-59890","PYSEC-2026-3447",[172,3239],"2026-07-08T17:17:27.020Z","2026-09-10T03:50:52.323347787Z",[3244],{"type":1289,"score":3245},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[3247,3249,3251,3253,3255,3256],{"type":1336,"url":3248},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fsecurity\u002Fadvisories\u002FGHSA-h35f-9h28-mq5c",{"type":1293,"url":3250},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59890",{"type":1298,"url":3252},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002Fdd9f436a36486b4cb8a4c70a2321548b0be09b8f",{"type":1304,"url":3254},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fsetuptools\u002FPYSEC-2026-3447.yaml",{"type":1301,"url":1940},{"type":1293,"url":3257},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Freleases\u002Ftag\u002Fv83.0.0",[1946,1947,1948,1949,3259,3260,3261,3262,3263,3264,3265,3266],"pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@81.0.0","pypi:setuptools@82.0.1",{"id":173,"slug":3268,"dossier":47,"summary":3269,"aliases":3270,"sourceIds":3273,"published":3274,"modified":3275,"checkedAt":7,"severity":3276,"references":3278,"versionKeys":3299,"packageCount":32,"repositoryCount":32},"ghsa-h75v-3vvj-5mfj-d8fc6bb7","Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter",[3271,3272],"CVE-2024-34064","PYSEC-2026-1474",[173,3272],"2024-05-06T14:20:59Z","2026-09-10T03:50:13.786450101Z",[3277],{"type":1289,"score":2316},[3279,3281,3283,3285,3286,3288,3290,3292,3294,3296,3297],{"type":1304,"url":3280},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-h75v-3vvj-5mfj",{"type":1293,"url":3282},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-34064",{"type":1298,"url":3284},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F0668239dc6b44ef38e7a6c9f91f312fd4ca581cb",{"type":1301,"url":2906},{"type":1304,"url":3287},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2024\u002F12\u002Fmsg00009.html",{"type":1304,"url":3289},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002F567XIGSZMABG6TSMYWD7MIYNJSUQQRUC",{"type":1304,"url":3291},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FGCLF44KY43BSVMTE6S53B4V5WP3FRRSE",{"type":1304,"url":3293},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FSSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS",{"type":1304,"url":3295},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS",{"type":1301,"url":2912},{"type":1293,"url":3298},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-h75v-3vvj-5mfj",[2916],{"id":174,"slug":3301,"dossier":47,"summary":3302,"aliases":3303,"sourceIds":3306,"published":3307,"modified":3308,"checkedAt":7,"severity":3309,"references":3311,"versionKeys":3326,"packageCount":32,"repositoryCount":103},"ghsa-hh9p-6wh2-4mfc-8e33cff1","GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()",[3304,3305],"CVE-2026-76217","PYSEC-2026-3841",[174,3305],"2026-08-07T15:43:56Z","2026-09-10T12:26:07.095223621Z",[3310],{"type":1289,"score":1610},[3312,3314,3316,3317,3319,3320,3321,3323,3324],{"type":1304,"url":3313},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-hh9p-6wh2-4mfc",{"type":1293,"url":3315},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76217",{"type":1304,"url":1738},{"type":1304,"url":3318},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Ff2550b65bf60ca087190981e2c7b6865e201f40c",{"type":1301,"url":1341},{"type":1304,"url":1743},{"type":1304,"url":3322},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-read-via-pathspec-from-file",{"type":1301,"url":1410},{"type":1293,"url":3325},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-hh9p-6wh2-4mfc",[1347,1348,1349],{"id":175,"slug":3328,"dossier":47,"summary":3329,"aliases":3330,"sourceIds":3333,"published":3334,"modified":3335,"checkedAt":7,"severity":3336,"references":3341,"versionKeys":3358,"packageCount":32,"repositoryCount":103},"ghsa-hmq2-w58f-27jc-f0b0fe70","GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython",[3331,3332],"CVE-2026-76222","PYSEC-2026-3784",[175,3332],"2026-08-07T15:45:39Z","2026-09-08T21:00:05.149418166Z",[3337,3339],{"type":1289,"score":3338},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:N\u002FI:H\u002FA:L",{"type":1330,"score":3340},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:N\u002FVI:H\u002FVA:L\u002FSC:N\u002FSI:H\u002FSA:L\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[3342,3344,3346,3348,3350,3352,3353,3354,3356],{"type":1336,"url":3343},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-hmq2-w58f-27jc",{"type":1293,"url":3345},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76222",{"type":1304,"url":3347},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2202",{"type":1304,"url":3349},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F4299c990e1ca21896f9485277caf7bb0ae5b404c",{"type":1304,"url":3351},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fe4b8e7d026ca6abb4cf604f8e77093432ce23c06",{"type":1301,"url":1341},{"type":1304,"url":1743},{"type":1304,"url":3355},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3784.yaml",{"type":1293,"url":3357},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-path-traversal-via-gitmodules-submodule-name",[1347,1348,1349],{"id":176,"slug":3360,"dossier":47,"summary":3361,"aliases":3362,"sourceIds":3365,"published":3366,"modified":3367,"checkedAt":7,"severity":3368,"references":3372,"versionKeys":3388,"packageCount":32,"repositoryCount":32},"ghsa-hxxf-235m-72v3-21da19b0","Deserialization of Untrusted Data in Hugging Face Transformers",[3363,3364],"CVE-2024-11394","PYSEC-2024-229",[176,3364],"2024-11-22T22:15:07Z","2026-09-10T03:50:20.811665084Z",[3369,3371],{"type":1289,"score":3370},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1289,"score":2954},[3373,3375,3377,3379,3380,3382,3384,3386],{"type":1293,"url":3374},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-11394",{"type":1304,"url":3376},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fissues\u002F34840",{"type":1304,"url":3378},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F35296",{"type":1301,"url":1368},{"type":1304,"url":3381},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2024-229.yaml",{"type":1304,"url":3383},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1515",{"type":1293,"url":3385},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1515\u002F",{"type":1293,"url":3387},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-hxxf-235m-72v3",[1374],{"id":177,"slug":3390,"dossier":47,"summary":3391,"aliases":3392,"sourceIds":3395,"published":3396,"modified":3397,"checkedAt":7,"severity":3398,"references":3400,"versionKeys":3410,"packageCount":32,"repositoryCount":1720},"ghsa-jhmp-mqwm-3gq8-3b1c10a9","Tornado: Quadratic DoS via Crafted Multipart Parameters",[3393,3394],"CVE-2025-67726","PYSEC-2025-267",[177,3394],"2025-12-12T07:15:44.920Z","2026-07-20T19:15:27.583657512Z",[3399],{"type":1289,"score":1531},[3401,3403,3405,3406,3408,3409],{"type":1293,"url":3402},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-jhmp-mqwm-3gq8",{"type":1293,"url":3404},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67726",{"type":1298,"url":2825},{"type":1304,"url":3407},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-267.yaml",{"type":1301,"url":1645},{"type":1293,"url":2830},[1653,1654,1655],{"id":178,"slug":3412,"dossier":90,"summary":3413,"aliases":3414,"sourceIds":3418,"published":3419,"modified":3420,"checkedAt":7,"severity":3421,"references":3423,"versionKeys":3437,"packageCount":32,"repositoryCount":1693},"ghsa-jjj6-mw9f-p565-ed2d1f46","Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()",[3415,3416,3417],"BIT-pillow-2026-59200","CVE-2026-59200","PYSEC-2026-3495",[178,3417],"2026-07-20T23:11:29Z","2026-09-10T03:50:12.341825852Z",[3422],{"type":1289,"score":1531},[3424,3426,3428,3430,3432,3433,3434,3435],{"type":1304,"url":3425},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-jjj6-mw9f-p565",{"type":1293,"url":3427},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59200",{"type":1304,"url":3429},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9718",{"type":1304,"url":3431},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Ff7a31ea75e460e108c37126da1f47812f21f6b09",{"type":1301,"url":1680},{"type":1304,"url":2044},{"type":1301,"url":2046},{"type":1293,"url":3436},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jjj6-mw9f-p565",[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":179,"slug":3439,"dossier":47,"summary":3440,"aliases":3441,"sourceIds":3444,"published":3445,"modified":3446,"checkedAt":7,"severity":3447,"references":3449,"versionKeys":3462,"packageCount":32,"repositoryCount":32},"ghsa-jjph-296x-mrcr-0f661d67","Transformers vulnerable to ReDoS attack through its get_imports() function",[3442,3443],"CVE-2025-3264","PYSEC-2026-1985",[179,3443],"2025-07-07T12:30:22Z","2026-07-07T17:56:51.899728258Z",[3448],{"type":1289,"score":1761},[3450,3452,3454,3456,3457,3459,3460],{"type":1293,"url":3451},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3264",{"type":1304,"url":3453},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F0720e206c6ba28887e4d60ef60a6a089f6c1cc76",{"type":1304,"url":3455},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F126abe3461762e5fc180e7e614391d1b4ab051ca",{"type":1301,"url":1368},{"type":1304,"url":3458},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F3c6f7822-9992-476d-8cf0-b0b1623427df",{"type":1301,"url":1516},{"type":1293,"url":3461},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jjph-296x-mrcr",[1374],{"id":180,"slug":3464,"dossier":47,"summary":3465,"aliases":3466,"sourceIds":3469,"published":3470,"modified":3471,"checkedAt":7,"severity":3472,"references":3476,"versionKeys":3486,"packageCount":32,"repositoryCount":103},"ghsa-jm78-9fvv-mhgr-2c167ddc","GitPython: git-config OPTION-name injection via =\u002F#\u002Fwhitespace bypasses name validator, enabling forged core.sshCommand\u002FhooksPath (RCE)",[3467,3468],"CVE-2026-76221","PYSEC-2026-3783",[180,3468],"2026-08-07T15:46:35Z","2026-09-10T03:51:14.296736368Z",[3473,3474],{"type":1289,"score":1394},{"type":1330,"score":3475},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[3477,3479,3480,3482,3483,3484],{"type":1336,"url":3478},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-jm78-9fvv-mhgr",{"type":1304,"url":1738},{"type":1304,"url":3481},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fa495ccd3b547ccd60b2187215823b72a9c0188bf",{"type":1301,"url":1341},{"type":1304,"url":1743},{"type":1293,"url":3485},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-config-injection-via-option-name",[1347,1348,1349],{"id":181,"slug":3488,"dossier":47,"summary":3489,"aliases":3490,"sourceIds":3493,"published":3494,"modified":3495,"checkedAt":7,"severity":3496,"references":3501,"versionKeys":3514,"packageCount":32,"repositoryCount":32},"ghsa-jw8x-6495-233v-cb32b711","scikit-learn sensitive data leakage vulnerability",[3491,3492],"CVE-2024-5206","PYSEC-2024-110",[181,3492],"2024-06-06T19:16:00Z","2026-09-10T03:50:15.628224747Z",[3497,3499],{"type":1289,"score":3498},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":1289,"score":3500},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[3502,3504,3506,3508,3510,3512],{"type":1293,"url":3503},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-5206",{"type":1298,"url":3505},"https:\u002F\u002Fgithub.com\u002Fscikit-learn\u002Fscikit-learn\u002Fcommit\u002F70ca21f106b603b611da73012c9ade7cd8e438b8",{"type":1304,"url":3507},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fscikit-learn\u002FPYSEC-2024-110.yaml",{"type":1301,"url":3509},"https:\u002F\u002Fgithub.com\u002Fscikit-learn\u002Fscikit-learn",{"type":1304,"url":3511},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F14bc0917-a85b-4106-a170-d09d5191517c",{"type":1293,"url":3513},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jw8x-6495-233v",[3515],"pypi:scikit-learn@1.3.2",{"id":182,"slug":3517,"dossier":47,"summary":3518,"aliases":3519,"sourceIds":3522,"published":3523,"modified":3524,"checkedAt":7,"severity":3525,"references":3528,"versionKeys":3536,"packageCount":32,"repositoryCount":375},"ghsa-mf9v-mfxr-j63j-1a7db6d4","urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API",[3520,3521],"CVE-2026-44432","PYSEC-2026-142",[182,3521],"2026-05-11T14:51:45Z","2026-09-10T03:51:06.409994465Z",[3526,3527],{"type":1289,"score":1531},{"type":1330,"score":1425},[3529,3531,3533,3535],{"type":1293,"url":3530},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-mf9v-mfxr-j63j",{"type":1293,"url":3532},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44432",{"type":1304,"url":3534},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Furllib3\u002FPYSEC-2026-142.yaml",{"type":1301,"url":1440},[3537],"pypi:urllib3@2.6.3",{"id":183,"slug":3539,"dossier":47,"summary":3540,"aliases":3541,"sourceIds":3544,"published":3545,"modified":3546,"checkedAt":7,"severity":3547,"references":3549,"versionKeys":3558,"packageCount":32,"repositoryCount":66},"ghsa-mgf9-4vpg-hj56-00729355","tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)",[3542,3543],"CVE-2026-49855","PYSEC-2026-3389",[183,3543],"2026-06-15T20:19:28Z","2026-09-10T03:51:09.080081033Z",[3548],{"type":1289,"score":1531},[3550,3552,3553,3554,3556],{"type":1304,"url":3551},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-mgf9-4vpg-hj56",{"type":1301,"url":1645},{"type":1301,"url":1647},{"type":1293,"url":3555},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mgf9-4vpg-hj56",{"type":1293,"url":3557},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49855",[1653,1654,1655,1656,1657],{"id":184,"slug":3560,"dossier":47,"summary":3561,"aliases":3562,"sourceIds":3565,"published":3566,"modified":3567,"checkedAt":7,"severity":3568,"references":3570,"versionKeys":3583,"packageCount":32,"repositoryCount":2452},"ghsa-mpf4-983q-p7j4-9fb72bc8","Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop",[3563,3564],"CVE-2026-82397","PYSEC-2026-3928",[184,3564],"2026-09-02T14:38:43Z","2026-09-10T12:25:33.492830390Z",[3569],{"type":1289,"score":1531},[3571,3573,3575,3576,3578,3579,3580,3581],{"type":1304,"url":3572},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-mpf4-983q-p7j4",{"type":1293,"url":3574},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-82397",{"type":1304,"url":2442},{"type":1304,"url":3577},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F8d6363ed7b69d5f0da806efe34d256627a2191de",{"type":1301,"url":1645},{"type":1304,"url":2449},{"type":1301,"url":1647},{"type":1293,"url":3582},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mpf4-983q-p7j4",[1653,1654,1655,1656,1657,2451],{"id":185,"slug":3585,"dossier":47,"summary":3586,"aliases":3587,"sourceIds":3590,"published":3591,"modified":3592,"checkedAt":7,"severity":3593,"references":3596,"versionKeys":3604,"packageCount":32,"repositoryCount":103},"ghsa-mv93-w799-cj2w-4413137a","GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath",[3588,3589],"CVE-2026-67326","PYSEC-2026-3980",[185,3589],"2026-05-08T23:19:02Z","2026-09-17T09:10:55.928803360Z",[3594,3595],{"type":1289,"score":1585},{"type":1289,"score":2287},[3597,3599,3601,3602],{"type":1336,"url":3598},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-mv93-w799-cj2w",{"type":1293,"url":3600},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rpm5-65cw-6hj4",{"type":1301,"url":1341},{"type":1293,"url":3603},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-newline-injection-via-config-writer-section",[1347,1348,1349],{"id":186,"slug":3606,"dossier":47,"summary":3607,"aliases":3608,"sourceIds":3611,"published":3612,"modified":3613,"checkedAt":7,"severity":3614,"references":3619,"versionKeys":3631,"packageCount":32,"repositoryCount":103},"ghsa-p538-c434-8v24-c303e516","GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count",[3609,3610],"CVE-2026-73621","PYSEC-2026-3950",[186,3610],"2026-08-03T20:23:17Z","2026-09-10T13:10:55.177009469Z",[3615,3617],{"type":1289,"score":3616},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:L",{"type":1330,"score":3618},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[3620,3622,3624,3626,3627,3629],{"type":1336,"url":3621},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-p538-c434-8v24",{"type":1304,"url":3623},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2184",{"type":1304,"url":3625},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F38553b6fddc7f6a667cdb45a6762343a08fc72b2",{"type":1301,"url":1341},{"type":1304,"url":3628},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.56",{"type":1293,"url":3630},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-arbitrary-file-truncation-via-commit-count",[1347,1348,1349],{"id":187,"slug":3633,"dossier":47,"summary":3634,"aliases":3635,"sourceIds":3639,"published":3640,"modified":3641,"checkedAt":7,"severity":3642,"references":3645,"versionKeys":3658,"packageCount":32,"repositoryCount":103},"ghsa-pg7v-jwj7-p798-7c77aab5","Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service",[3636,3637,3638],"BIT-pillow-2026-59203","CVE-2026-59203","PYSEC-2026-3452",[187,3638],"2026-07-14T16:17:02.063Z","2026-09-10T03:50:52.876709782Z",[3643,3644],{"type":1289,"score":1504},{"type":1289,"score":1531},[3646,3648,3650,3652,3654,3656,3657],{"type":1336,"url":3647},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-pg7v-jwj7-p798",{"type":1293,"url":3649},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59203",{"type":1298,"url":3651},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9708",{"type":1298,"url":3653},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F03992618118b4a76b6163cd72ab5ecd684133b83",{"type":1304,"url":3655},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3452.yaml",{"type":1301,"url":1680},{"type":1293,"url":2044},[1689,1690,1691,1692],{"id":188,"slug":3660,"dossier":47,"summary":3661,"aliases":3662,"sourceIds":3665,"published":3445,"modified":3666,"checkedAt":7,"severity":3667,"references":3670,"versionKeys":3683,"packageCount":32,"repositoryCount":375},"ghsa-phhr-52qp-3mj4-6f5d82e3","Transformers's Improper Input Validation vulnerability can be exploited through username injection",[3663,3664],"CVE-2025-3777","PYSEC-2026-1986",[188,3664],"2026-09-10T03:50:26.198077196Z",[3668],{"type":1289,"score":3669},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[3671,3673,3675,3676,3678,3680,3681],{"type":1293,"url":3672},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3777",{"type":1304,"url":3674},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F4dda5f71b35fb70cf602187eef84bb17a50b9082",{"type":1301,"url":1368},{"type":1304,"url":3677},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fblame\u002Fa7d2bbaaa8aac64f7c1ee8c1421cfe84b38359a4\u002Fsrc\u002Ftransformers\u002Fimage_utils.py",{"type":1304,"url":3679},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fccba0730-9248-4853-b7ff-5c20e6364f09",{"type":1301,"url":1516},{"type":1293,"url":3682},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-phhr-52qp-3mj4",[1374,1375,1376],{"id":189,"slug":3685,"dossier":90,"summary":3686,"aliases":3687,"sourceIds":3691,"published":3692,"modified":3693,"checkedAt":7,"severity":3694,"references":3696,"versionKeys":3707,"packageCount":32,"repositoryCount":1693},"ghsa-phj9-mv4w-65pm-481e7dc3","Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`",[3688,3689,3690],"BIT-pillow-2026-55380","CVE-2026-55380","PYSEC-2026-2256",[189,3690],"2026-07-06T19:17:08.703Z","2026-09-10T03:51:11.734605509Z",[3695],{"type":1289,"score":1531},[3697,3699,3701,3703,3705,3706],{"type":1336,"url":3698},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-phj9-mv4w-65pm",{"type":1293,"url":3700},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55380",{"type":1298,"url":3702},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Ff39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675",{"type":1304,"url":3704},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2256.yaml",{"type":1301,"url":1680},{"type":1293,"url":1682},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":190,"slug":3709,"dossier":47,"summary":3710,"aliases":3711,"sourceIds":3714,"published":3715,"modified":3716,"checkedAt":7,"severity":3717,"references":3719,"versionKeys":3731,"packageCount":32,"repositoryCount":1720},"ghsa-pq67-6m6q-mj2v-3522d1d4","urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation",[3712,3713],"CVE-2025-50181","PYSEC-2026-1999",[190,3713],"2025-06-18T17:50:00Z","2026-09-10T03:50:25.299291456Z",[3718],{"type":1289,"score":1705},[3720,3722,3724,3726,3727,3728,3729],{"type":1304,"url":3721},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-pq67-6m6q-mj2v",{"type":1293,"url":3723},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-50181",{"type":1298,"url":3725},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Ff05b1329126d5be6de501f9d1e3e36738bc08857",{"type":1301,"url":1440},{"type":1304,"url":1715},{"type":1301,"url":1442},{"type":1293,"url":3730},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pq67-6m6q-mj2v",[1444,1445,1446,1447],{"id":191,"slug":3733,"dossier":47,"summary":3734,"aliases":3735,"sourceIds":3738,"published":3739,"modified":3740,"checkedAt":7,"severity":3741,"references":3745,"versionKeys":3756,"packageCount":32,"repositoryCount":1720},"ghsa-pr2v-jx2c-wg9f-1ca6d67c","Tornado vulnerable to Header Injection and XSS via reason argument",[3736,3737],"CVE-2025-67724","PYSEC-2025-265",[191,3737],"2025-12-12T06:15:41.213Z","2026-07-20T19:00:24.953994999Z",[3742,3743],{"type":1289,"score":2316},{"type":1289,"score":3744},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N",[3746,3748,3750,3752,3754,3755],{"type":1293,"url":3747},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-pr2v-jx2c-wg9f",{"type":1293,"url":3749},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67724",{"type":1298,"url":3751},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F9c163aebeaad9e6e7d28bac1f33580eb00b0e421",{"type":1304,"url":3753},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-265.yaml",{"type":1301,"url":1645},{"type":1293,"url":2830},[1653,1654,1655],{"id":192,"slug":3758,"dossier":47,"summary":3759,"aliases":3760,"sourceIds":3762,"published":3763,"modified":3764,"checkedAt":7,"severity":3765,"references":3768,"versionKeys":3772,"packageCount":32,"repositoryCount":66},"ghsa-pw6j-qg29-8w7f-fb4d7ed6","Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse",[3761],"CVE-2026-91992",[192],"2026-06-15T20:37:24Z","2026-09-16T03:56:01.290461498Z",[3766],{"type":1289,"score":3767},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[3769,3771],{"type":1304,"url":3770},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-pw6j-qg29-8w7f",{"type":1301,"url":1645},[1653,1654,1655,1656,1657],{"id":193,"slug":3774,"dossier":47,"summary":3775,"aliases":3776,"sourceIds":3780,"published":3781,"modified":3782,"checkedAt":7,"severity":3783,"references":3786,"versionKeys":3798,"packageCount":32,"repositoryCount":1449},"ghsa-pwv6-vv43-88gr-c5f811d0","Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)",[3777,3778,3779],"BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252",[193,3779],"2026-05-04T20:20:31Z","2026-09-10T03:50:47.242104143Z",[3784,3785],{"type":1330,"score":2285},{"type":1289,"score":2128},[3787,3788,3790,3792,3794,3796,3797],{"type":1304,"url":2847},{"type":1298,"url":3789},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-pwv6-vv43-88gr",{"type":1293,"url":3791},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42311",{"type":1298,"url":3793},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9520",{"type":1298,"url":3795},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F58f9a1d166dcb0c274807d4423522d205b0c35ea",{"type":1301,"url":1680},{"type":1293,"url":1994},[1684,1685,1686,1687,1688,1689,1690,1691],{"id":194,"slug":3800,"dossier":47,"summary":3801,"aliases":3802,"sourceIds":3805,"published":3445,"modified":3806,"checkedAt":7,"severity":3807,"references":3809,"versionKeys":3820,"packageCount":32,"repositoryCount":32},"ghsa-q2wp-rjmx-x6x9-43135d3d","Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking",[3803,3804],"CVE-2025-3263","PYSEC-2026-1987",[194,3804],"2026-07-07T17:56:57.889099913Z",[3808],{"type":1289,"score":1761},[3810,3812,3813,3814,3815,3817,3818],{"type":1293,"url":3811},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3263",{"type":1304,"url":3453},{"type":1304,"url":3455},{"type":1301,"url":1368},{"type":1304,"url":3816},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fc7a69150-54f8-4e81-8094-791e7a2a0f29",{"type":1301,"url":1516},{"type":1293,"url":3819},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q2wp-rjmx-x6x9",[1374],{"id":195,"slug":3822,"dossier":47,"summary":3823,"aliases":3824,"sourceIds":3827,"published":3828,"modified":3829,"checkedAt":7,"severity":3830,"references":3833,"versionKeys":3846,"packageCount":32,"repositoryCount":32},"ghsa-q2x7-8rv6-6q7h-1113a288","Jinja has a sandbox breakout through indirect reference to format method",[3825,3826],"CVE-2024-56326","PYSEC-2026-1475",[195,3826],"2024-12-23T17:56:08Z","2026-09-10T03:50:21.662855250Z",[3831,3832],{"type":1289,"score":2287},{"type":1330,"score":2897},[3834,3836,3838,3840,3841,3842,3843,3844],{"type":1304,"url":3835},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-q2x7-8rv6-6q7h",{"type":1293,"url":3837},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56326",{"type":1298,"url":3839},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F48b0687e05a5466a91cd5812d604fa37ad0943b4",{"type":1301,"url":2906},{"type":1304,"url":3228},{"type":1304,"url":2908},{"type":1301,"url":2912},{"type":1293,"url":3845},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q2x7-8rv6-6q7h",[2916],{"id":196,"slug":3848,"dossier":90,"summary":3849,"aliases":3850,"sourceIds":3853,"published":3854,"modified":3855,"checkedAt":7,"severity":3856,"references":3861,"versionKeys":3867,"packageCount":32,"repositoryCount":3181},"ghsa-qccp-gfcp-xxvc-0d988969","urllib3: Sensitive headers forwarded across origins in proxied low-level redirects",[3851,3852],"CVE-2026-44431","PYSEC-2026-141",[196,3852],"2026-05-11T14:51:20Z","2026-09-10T03:50:47.272765640Z",[3857,3859],{"type":1289,"score":3858},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",{"type":1330,"score":3860},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3862,3864,3866],{"type":1293,"url":3863},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-qccp-gfcp-xxvc",{"type":1293,"url":3865},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44431",{"type":1301,"url":1440},[1444,1445,1446,1447,1448,3537],{"id":197,"slug":3869,"dossier":47,"summary":3870,"aliases":3871,"sourceIds":3875,"published":3876,"modified":3877,"checkedAt":7,"severity":3878,"references":3882,"versionKeys":3900,"packageCount":32,"repositoryCount":345},"ghsa-qfhq-4f3w-5fph-33bc3f14","PyTorch is vulnerable to memory corruption through its torch.lstm_cell function",[3872,3873,3874],"BIT-pytorch-2025-3001","CVE-2025-3001","PYSEC-2025-195",[197],"2025-03-31T18:31:08Z","2026-06-10T18:26:26.736808954Z",[3879,3880],{"type":1289,"score":2986},{"type":1330,"score":3881},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[3883,3885,3887,3889,3891,3893,3894,3896,3898],{"type":1293,"url":3884},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3001",{"type":1304,"url":3886},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149626",{"type":1304,"url":3888},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149626#issue-2935860995",{"type":1304,"url":3890},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F999d94b5ede5f4ec111ba7dd144129e2c2725b03",{"type":1304,"url":3892},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-195.yaml",{"type":1301,"url":1478},{"type":1304,"url":3895},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302050",{"type":1304,"url":3897},"https:\u002F\u002Fvuldb.com\u002F?id.302050",{"type":1304,"url":3899},"https:\u002F\u002Fvuldb.com\u002F?submit.524212",[1490,1491,1492,2490,2491,3901,3902,3903,3904],"pypi:torch@2.8.0","pypi:torch@2.9.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu",{"id":198,"slug":3906,"dossier":47,"summary":3907,"aliases":3908,"sourceIds":3911,"published":3912,"modified":3913,"checkedAt":7,"severity":3914,"references":3918,"versionKeys":3931,"packageCount":32,"repositoryCount":66},"ghsa-qjxf-f2mg-c6mc-58d52008","Tornado is vulnerable to DoS due to too many multipart parts",[3909,3910],"CVE-2026-31958","PYSEC-2026-140",[198,3910],"2026-03-11T20:16:16.617Z","2026-09-10T03:50:40.522968763Z",[3915,3916],{"type":1289,"score":1531},{"type":1330,"score":3917},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[3919,3921,3923,3925,3927,3928,3929],{"type":1293,"url":3920},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-qjxf-f2mg-c6mc",{"type":1293,"url":3922},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31958",{"type":1304,"url":3924},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F119a195e290c43ad2d63a2cf012c29d43d6ed839",{"type":1304,"url":3926},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2026-140.yaml",{"type":1301,"url":1645},{"type":1304,"url":2328},{"type":1304,"url":3930},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F04\u002Fmsg00000.html",[1653,1654,1655,1656],{"id":199,"slug":3933,"dossier":47,"summary":3934,"aliases":3935,"sourceIds":3938,"published":3939,"modified":3940,"checkedAt":7,"severity":3941,"references":3944,"versionKeys":3959,"packageCount":32,"repositoryCount":345},"ghsa-qmgc-5h2g-mvrw-199eacc8","filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock",[3936,3937],"CVE-2026-22701","PYSEC-2026-1374",[199,3937],"2026-01-13T18:44:55Z","2026-09-10T03:50:33.702580779Z",[3942],{"type":1289,"score":3943},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:H",[3945,3947,3949,3951,3953,3955,3957],{"type":1304,"url":3946},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fsecurity\u002Fadvisories\u002FGHSA-qmgc-5h2g-mvrw",{"type":1293,"url":3948},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22701",{"type":1304,"url":3950},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F255ed068bc85d1ef406e50a135e1459170dd1bf0",{"type":1304,"url":3952},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F41b42dd2c72aecf7da83dbda5903b8087dddc4d5",{"type":1301,"url":3954},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock",{"type":1301,"url":3956},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ffilelock",{"type":1293,"url":3958},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qmgc-5h2g-mvrw",[3960,3961,3962,3963],"pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0",{"id":200,"slug":3965,"dossier":47,"summary":3966,"aliases":3967,"sourceIds":3970,"published":3971,"modified":3972,"checkedAt":7,"severity":3973,"references":3976,"versionKeys":3990,"packageCount":32,"repositoryCount":32},"ghsa-qq3j-4f4f-9583-cd76c72c","Hugging Face Transformers Regular Expression Denial of Service",[3968,3969],"CVE-2025-2099","PYSEC-2025-40",[200,3969],"2025-05-19T12:15:19Z","2026-06-10T17:02:48.111891265Z",[3974,3975],{"type":1289,"score":1761},{"type":1289,"score":1531},[3977,3979,3981,3983,3984,3986,3988],{"type":1293,"url":3978},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2099",{"type":1304,"url":3980},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F36648",{"type":1298,"url":3982},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F8cb522b4190bd556ce51be04942720650b1a3e57",{"type":1301,"url":1368},{"type":1304,"url":3985},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2025-40.yaml",{"type":1304,"url":3987},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F97b780f3-ffca-424f-ad5d-0e1c57a5bde4",{"type":1293,"url":3989},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qq3j-4f4f-9583",[1374],{"id":201,"slug":3992,"dossier":47,"summary":3361,"aliases":3993,"sourceIds":3996,"published":3997,"modified":3998,"checkedAt":7,"severity":3999,"references":4003,"versionKeys":4017,"packageCount":32,"repositoryCount":32},"ghsa-qxrp-vhvm-j765-63c6e9a2",[3994,3995],"CVE-2024-11392","PYSEC-2024-227",[201,3995],"2024-11-22T22:15:06Z","2026-09-10T03:50:21.016710762Z",[4000,4002],{"type":1289,"score":4001},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1289,"score":2954},[4004,4006,4007,4008,4009,4011,4013,4015],{"type":1293,"url":4005},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-11392",{"type":1304,"url":3376},{"type":1304,"url":3378},{"type":1301,"url":1368},{"type":1304,"url":4010},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2024-227.yaml",{"type":1304,"url":4012},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1513",{"type":1293,"url":4014},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1513\u002F",{"type":1293,"url":4016},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qxrp-vhvm-j765",[1374],{"id":202,"slug":4019,"dossier":47,"summary":4020,"aliases":4021,"sourceIds":4025,"published":4026,"modified":4027,"checkedAt":7,"severity":4028,"references":4031,"versionKeys":4045,"packageCount":32,"repositoryCount":1449},"ghsa-r73j-pqj5-w3x7-8d4d543f","Pillow has a PDF Parsing Trailer Infinite Loop (DoS)",[4022,4023,4024],"BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874",[202,4024],"2026-05-04T20:19:30Z","2026-09-10T03:50:55.309086884Z",[4029,4030],{"type":1289,"score":1466},{"type":1330,"score":1986},[4032,4034,4036,4038,4040,4041,4042,4043],{"type":1304,"url":4033},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-r73j-pqj5-w3x7",{"type":1293,"url":4035},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42310",{"type":1304,"url":4037},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9519",{"type":1304,"url":4039},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F3bf614e4b8615d0ce1d5039efaf6db447fe7c468",{"type":1301,"url":1680},{"type":1304,"url":1994},{"type":1301,"url":2046},{"type":1293,"url":4044},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-r73j-pqj5-w3x7",[1684,1685,1686,1687,1688,1689,1690,1691],{"id":203,"slug":4047,"dossier":47,"summary":4048,"aliases":4049,"sourceIds":4052,"published":4053,"modified":4054,"checkedAt":7,"severity":4055,"references":4058,"versionKeys":4068,"packageCount":32,"repositoryCount":103},"ghsa-r9mr-m37c-5fr3-d43000fc","GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution",[4050,4051],"CVE-2026-73625","PYSEC-2026-3953",[203,4051],"2026-07-24T16:42:57Z","2026-09-10T13:10:47.448946391Z",[4056,4057],{"type":1289,"score":1394},{"type":1330,"score":3475},[4059,4061,4062,4064,4065,4066],{"type":1336,"url":4060},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-r9mr-m37c-5fr3",{"type":1304,"url":2159},{"type":1304,"url":4063},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fe8d0fbf774d1f6baa3b481adfe48bd262e43b453",{"type":1301,"url":1341},{"type":1304,"url":2164},{"type":1293,"url":4067},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-remote-code-execution-via-kwarg-value-smuggling",[1347,1348,1349],{"id":204,"slug":4070,"dossier":47,"summary":4071,"aliases":4072,"sourceIds":4075,"published":4076,"modified":4077,"checkedAt":7,"severity":4078,"references":4080,"versionKeys":4095,"packageCount":32,"repositoryCount":34},"ghsa-rcv9-qm8p-9p6j-edc1db04","Hugging Face Transformers library has Regular Expression Denial of Service",[4073,4074],"CVE-2025-6051","PYSEC-2026-1988",[204,4074],"2025-09-14T18:30:26Z","2026-09-10T03:50:28.694224028Z",[4079],{"type":1289,"score":1761},[4081,4083,4085,4087,4089,4090,4092,4093],{"type":1293,"url":4082},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6051",{"type":1304,"url":4084},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F38844",{"type":1304,"url":4086},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F54a02160eb030da9be18231c77791f2eb3a52216",{"type":1304,"url":4088},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fba8eaba9865618253f997784aa565b96206426f0",{"type":1301,"url":1368},{"type":1304,"url":4091},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Faf929523-7b59-418a-bf55-301830b2ac9d",{"type":1301,"url":1516},{"type":1293,"url":4094},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rcv9-qm8p-9p6j",[1374,1375,1376,1377],{"id":205,"slug":4097,"dossier":47,"summary":4098,"aliases":4099,"sourceIds":4102,"published":4103,"modified":4104,"checkedAt":7,"severity":4105,"references":4108,"versionKeys":4121,"packageCount":32,"repositoryCount":345},"ghsa-rgxp-2hwp-jwgg-76cdda06","Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering",[4100,4101],"CVE-2026-25087","PYSEC-2026-113",[205,4101],"2026-02-17T14:16:01.947Z","2026-09-10T03:50:35.750182003Z",[4106],{"type":1289,"score":4107},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:H",[4109,4111,4113,4115,4117,4119],{"type":1293,"url":4110},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25087",{"type":1298,"url":4112},"https:\u002F\u002Fgithub.com\u002Fapache\u002Farrow\u002Fpull\u002F48925",{"type":1301,"url":4114},"https:\u002F\u002Fgithub.com\u002Fapache\u002Farrow",{"type":1304,"url":4116},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpyarrow\u002FPYSEC-2026-113.yaml",{"type":1293,"url":4118},"https:\u002F\u002Flists.apache.org\u002Fthread\u002Fmpm4ld1qony30tchfpjtk5b11tcyvmwh",{"type":1293,"url":4120},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rgxp-2hwp-jwgg",[4122,4123,4124,4125],"pypi:pyarrow@18.1.0","pypi:pyarrow@20.0.0","pypi:pyarrow@21.0.0","pypi:pyarrow@22.0.0",{"id":206,"slug":4127,"dossier":47,"summary":4128,"aliases":4129,"sourceIds":4132,"published":4133,"modified":4134,"checkedAt":7,"severity":4135,"references":4137,"versionKeys":4145,"packageCount":32,"repositoryCount":103},"ghsa-rpm5-65cw-6hj4-6c97dd77","GitPython has Command Injection via Git options bypass",[4130,4131],"CVE-2026-42215","PYSEC-2026-2160",[206,4131],"2026-04-25T23:42:16Z","2026-09-10T03:51:03.167884784Z",[4136],{"type":1289,"score":1394},[4138,4140,4142,4143],{"type":1336,"url":4139},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-rpm5-65cw-6hj4",{"type":1293,"url":4141},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42215",{"type":1301,"url":1341},{"type":1298,"url":4144},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.47",[1347,1348,1349],{"id":207,"slug":4147,"dossier":47,"summary":4148,"aliases":4149,"sourceIds":4153,"published":2982,"modified":4154,"checkedAt":7,"severity":4155,"references":4158,"versionKeys":4176,"packageCount":32,"repositoryCount":1449},"ghsa-rrmf-rvhw-rf47-389d8330","PyTorch is vulnerable to memory corruption through its torch.jit.script function",[4150,4151,4152],"BIT-pytorch-2025-3000","CVE-2025-3000","PYSEC-2025-194",[207],"2026-09-10T03:49:48.419046410Z",[4156,4157],{"type":1289,"score":2986},{"type":1330,"score":3881},[4159,4161,4163,4165,4167,4169,4170,4172,4174],{"type":1293,"url":4160},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3000",{"type":1304,"url":4162},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149623",{"type":1304,"url":4164},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149623#issue-2935703015",{"type":1304,"url":4166},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002Fb90c94991cdf8b87c8f7439f79518e0ef2c4ca4f",{"type":1304,"url":4168},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-194.yaml",{"type":1301,"url":1478},{"type":1304,"url":4171},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302049",{"type":1304,"url":4173},"https:\u002F\u002Fvuldb.com\u002F?id.302049",{"type":1304,"url":4175},"https:\u002F\u002Fvuldb.com\u002F?submit.524197",[4177,4178,4179,1490,1491,1492,2490,2491,3901,3902,3903,3904],"pypi:torch@2.10.0","pypi:torch@2.11.0","pypi:torch@2.12.1",{"id":208,"slug":4181,"dossier":47,"summary":4182,"aliases":4183,"sourceIds":4186,"published":4187,"modified":4188,"checkedAt":7,"severity":4189,"references":4191,"versionKeys":4209,"packageCount":32,"repositoryCount":103},"ghsa-rwj8-pgh3-r573-0bf779f8","GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL",[4184,4185],"CVE-2026-67322","PYSEC-2026-3842",[208,4185],"2026-07-21T22:06:09Z","2026-09-24T18:28:17.149390188Z",[4190],{"type":1289,"score":2503},[4192,4194,4196,4198,4199,4201,4202,4204,4206,4207],{"type":1304,"url":4193},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-rwj8-pgh3-r573",{"type":1293,"url":4195},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-67322",{"type":1304,"url":4197},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2172",{"type":1304,"url":2622},{"type":1293,"url":4200},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rwj8-pgh3-r573",{"type":1301,"url":1341},{"type":1304,"url":4203},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.52",{"type":1304,"url":4205},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fgitpython\u002FPYSEC-2026-3842.yaml",{"type":1301,"url":1410},{"type":1304,"url":4208},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-environment-variable-exfiltration-via-clone-from",[1347,1348,1349],{"id":209,"slug":4211,"dossier":47,"summary":4212,"aliases":4213,"sourceIds":4216,"published":4217,"modified":4218,"checkedAt":7,"severity":4219,"references":4221,"versionKeys":4229,"packageCount":32,"repositoryCount":103},"ghsa-v87r-6q3f-2j67-81913ca6","GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath",[4214,4215],"CVE-2026-44244","PYSEC-2026-2163",[209,4215],"2026-05-06T21:58:00Z","2026-09-10T03:50:47.691444343Z",[4220],{"type":1289,"score":2287},[4222,4224,4226,4227],{"type":1336,"url":4223},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-v87r-6q3f-2j67",{"type":1293,"url":4225},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44244",{"type":1301,"url":1341},{"type":1298,"url":4228},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.49",[1347,1348,1349],{"id":210,"slug":4231,"dossier":47,"summary":4232,"aliases":4233,"sourceIds":4237,"published":2982,"modified":4238,"checkedAt":7,"severity":4239,"references":4242,"versionKeys":4257,"packageCount":32,"repositoryCount":42},"ghsa-vgrw-7cvw-pwgx-766c6098","PyTorch is vulnerable to memory corruption through its unpack_sequence function",[4234,4235,4236],"BIT-pytorch-2025-2999","CVE-2025-2999","PYSEC-2025-193",[210],"2026-06-10T17:41:15.774477397Z",[4240,4241],{"type":1289,"score":2986},{"type":1330,"score":2988},[4243,4245,4246,4247,4248,4250,4251,4253,4255],{"type":1293,"url":4244},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2999",{"type":1304,"url":2993},{"type":1304,"url":2995},{"type":1304,"url":2997},{"type":1304,"url":4249},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-193.yaml",{"type":1301,"url":1478},{"type":1304,"url":4252},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302048",{"type":1304,"url":4254},"https:\u002F\u002Fvuldb.com\u002F?id.302048",{"type":1304,"url":4256},"https:\u002F\u002Fvuldb.com\u002F?submit.524198",[1490,1491,1492,2490,2491,3901,3902],{"id":211,"slug":4259,"dossier":90,"summary":4260,"aliases":4261,"sourceIds":4265,"published":4266,"modified":4267,"checkedAt":7,"severity":4268,"references":4270,"versionKeys":4284,"packageCount":32,"repositoryCount":1693},"ghsa-vjc4-5qp5-m44j-08063b19","Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service",[4262,4263,4264],"BIT-pillow-2026-59204","CVE-2026-59204","PYSEC-2026-3496",[211,4264],"2026-07-20T23:18:32Z","2026-09-10T03:50:53.107920034Z",[4269],{"type":1330,"score":3917},[4271,4273,4275,4277,4279,4280,4281,4282],{"type":1304,"url":4272},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-vjc4-5qp5-m44j",{"type":1293,"url":4274},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59204",{"type":1304,"url":4276},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9704",{"type":1304,"url":4278},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F13ada41172142f2fd9f0906f615a00ea623a11ca",{"type":1301,"url":1680},{"type":1304,"url":2044},{"type":1301,"url":2046},{"type":1293,"url":4283},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vjc4-5qp5-m44j",[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":212,"slug":4286,"dossier":47,"summary":4287,"aliases":4288,"sourceIds":4291,"published":4292,"modified":4293,"checkedAt":7,"severity":4294,"references":4301,"versionKeys":4327,"packageCount":32,"repositoryCount":375},"ghsa-vqwp-45wm-r9r5-eaa960a2","Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission",[4289,4290],"CVE-2026-10804","PYSEC-2026-212",[212,4290],"2026-06-04T12:16:24.620Z","2026-07-23T15:00:23.893493649Z",[4295,4297,4299],{"type":1289,"score":4296},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:L",{"type":1330,"score":4298},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":1289,"score":4300},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[4302,4304,4306,4308,4310,4312,4314,4315,4317,4319,4321,4323,4325],{"type":1293,"url":4303},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-10804",{"type":1298,"url":4305},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fissues\u002F14622",{"type":1298,"url":4307},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fpull\u002F14635",{"type":1304,"url":4309},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fpull\u002F15397",{"type":1304,"url":4311},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002Fcommit\u002Ffec0f584dae9261abed16cad35b32922104bb933",{"type":1304,"url":4313},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fstreamlit\u002FPYSEC-2026-212.yaml",{"type":1301,"url":2421},{"type":1293,"url":4316},"https:\u002F\u002Fvuldb.com\u002Fcve\u002FCVE-2026-10804",{"type":1293,"url":4318},"https:\u002F\u002Fvuldb.com\u002Fsubmit\u002F831508",{"type":1293,"url":4320},"https:\u002F\u002Fvuldb.com\u002Fvuln\u002F368253",{"type":1471,"url":4322},"https:\u002F\u002Fvuldb.com\u002Fvuln\u002F368253\u002Fcti",{"type":1304,"url":4324},"https:\u002F\u002Fgithub.com\u002Fstreamlit\u002Fstreamlit\u002F",{"type":1293,"url":4326},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vqwp-45wm-r9r5",[2425,2426,2427],{"id":213,"slug":4329,"dossier":47,"summary":4330,"aliases":4331,"sourceIds":4334,"published":4335,"modified":4336,"checkedAt":7,"severity":4337,"references":4340,"versionKeys":4357,"packageCount":32,"repositoryCount":345},"ghsa-w853-jp5j-5j7f-2786386f","filelock has a TOCTOU race condition which allows symlink attacks during lock file creation",[4332,4333],"CVE-2025-68146","PYSEC-2026-1375",[213,4333],"2025-12-16T20:52:55Z","2026-09-10T03:50:32.252960082Z",[4338],{"type":1289,"score":4339},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",[4341,4343,4345,4346,4348,4350,4352,4353,4355],{"type":1304,"url":4342},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fsecurity\u002Fadvisories\u002FGHSA-w853-jp5j-5j7f",{"type":1304,"url":4344},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F4724d7f8c3393ec1f048c93933e6e3e6ec321f0e",{"type":1301,"url":3954},{"type":1304,"url":4347},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Freleases\u002Ftag\u002F3.20.1",{"type":1304,"url":4349},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Ffileio\u002Ffile-attribute-constants",{"type":1304,"url":4351},"https:\u002F\u002Fpubs.opengroup.org\u002Fonlinepubs\u002F9699919799\u002Ffunctions\u002Fopen.html",{"type":1301,"url":3956},{"type":1293,"url":4354},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-w853-jp5j-5j7f",{"type":1293,"url":4356},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68146",[3960,3961,3962,3963],{"id":214,"slug":4359,"dossier":47,"summary":4360,"aliases":4361,"sourceIds":4365,"published":4366,"modified":4367,"checkedAt":7,"severity":4368,"references":4371,"versionKeys":4409,"packageCount":32,"repositoryCount":1449},"ghsa-whj4-6x5x-4v2j-eb5fc6a1","FITS GZIP decompression bomb in Pillow",[4362,4363,4364],"BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250",[214,4364],"2026-04-13T19:22:35Z","2026-09-10T03:51:03.847830288Z",[4369,4370],{"type":1289,"score":1531},{"type":1330,"score":3917},[4372,4374,4376,4378,4380,4381,4383,4385,4387,4389,4391,4393,4394,4396,4398,4400,4401,4403,4405,4407],{"type":1304,"url":4373},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-whj4-6x5x-4v2j",{"type":1293,"url":4375},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40192",{"type":1304,"url":4377},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9521",{"type":1304,"url":4379},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F3cb854e8b2bab43f40e342e665f9340d861aa628",{"type":1301,"url":1680},{"type":1304,"url":4382},"https:\u002F\u002Fpillow.readthedocs.io\u002Fen\u002Fstable\u002Freleasenotes\u002F12.2.0.html#prevent-fits-decompression-bomb",{"type":1304,"url":4384},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-40192",{"type":1304,"url":4386},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-40192.json",{"type":1293,"url":4388},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16008",{"type":1293,"url":4390},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16009",{"type":1293,"url":4392},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16030",{"type":1293,"url":2870},{"type":1293,"url":4395},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:17609",{"type":1293,"url":4397},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:17611",{"type":1293,"url":4399},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:19375",{"type":1293,"url":2872},{"type":1293,"url":4402},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:21017",{"type":1293,"url":4404},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22465",{"type":1293,"url":4406},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22629",{"type":1293,"url":4408},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22840",[1684,1685,1686,1687,1688,1689,1690,1691],{"id":215,"slug":4411,"dossier":47,"summary":4412,"aliases":4413,"sourceIds":4417,"published":4418,"modified":4419,"checkedAt":7,"severity":4420,"references":4423,"versionKeys":4432,"packageCount":32,"repositoryCount":1449},"ghsa-wjx4-4jcj-g98j-e937161b","Pillow has an integer overflow when processing fonts",[4414,4415,4416],"BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165",[215,4416],"2026-05-04T20:18:45Z","2026-09-10T03:50:47.950262681Z",[4421,4422],{"type":1289,"score":1466},{"type":1330,"score":1986},[4424,4426,4428,4430,4431],{"type":1293,"url":4425},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-wjx4-4jcj-g98j",{"type":1293,"url":4427},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42308",{"type":1304,"url":4429},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-165.yaml",{"type":1301,"url":1680},{"type":1293,"url":1994},[1684,1685,1686,1687,1688,1689,1690,1691],{"id":216,"slug":4434,"dossier":47,"summary":3361,"aliases":4435,"sourceIds":4438,"published":3366,"modified":4439,"checkedAt":7,"severity":4440,"references":4443,"versionKeys":4457,"packageCount":32,"repositoryCount":32},"ghsa-wrfc-pvp9-mr9g-c6b03ddf",[4436,4437],"CVE-2024-11393","PYSEC-2024-228",[216,4437],"2026-09-10T03:50:55.987633957Z",[4441,4442],{"type":1289,"score":3370},{"type":1289,"score":2954},[4444,4446,4447,4448,4449,4451,4453,4455],{"type":1293,"url":4445},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-11393",{"type":1304,"url":3376},{"type":1304,"url":3378},{"type":1301,"url":1368},{"type":1304,"url":4450},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2024-228.yaml",{"type":1304,"url":4452},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1514",{"type":1293,"url":4454},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1514\u002F",{"type":1293,"url":4456},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wrfc-pvp9-mr9g",[1374],{"id":217,"slug":4459,"dossier":47,"summary":4460,"aliases":4461,"sourceIds":4464,"published":4465,"modified":4466,"checkedAt":7,"severity":4467,"references":4469,"versionKeys":4484,"packageCount":32,"repositoryCount":103},"ghsa-wvpp-8hx9-p66j-188b3951","GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution",[4462,4463],"CVE-2026-76220","PYSEC-2026-3843",[217,4463],"2026-08-07T15:49:07Z","2026-09-10T12:26:01.792035310Z",[4468],{"type":1289,"score":1394},[4470,4472,4474,4475,4477,4478,4479,4481,4482],{"type":1304,"url":4471},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-wvpp-8hx9-p66j",{"type":1293,"url":4473},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-76220",{"type":1304,"url":1738},{"type":1304,"url":4476},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F96a888f4d782cb2f80452148e48e60ce4af6d541",{"type":1301,"url":1341},{"type":1304,"url":1743},{"type":1304,"url":4480},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-command-execution-via-split-single-char-options",{"type":1301,"url":1410},{"type":1293,"url":4483},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wvpp-8hx9-p66j",[1347,1348,1349],{"id":218,"slug":4486,"dossier":47,"summary":4487,"aliases":4488,"sourceIds":4490,"published":4491,"modified":4492,"checkedAt":7,"severity":4493,"references":4496,"versionKeys":4508,"packageCount":32,"repositoryCount":394},"ghsa-wwv5-g3v4-889x-b37c7c95","Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`",[4489],"CVE-2026-91991",[218],"2026-09-01T20:17:23Z","2026-09-16T03:56:00.367681644Z",[4494],{"type":1330,"score":4495},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:P\u002FVC:L\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[4497,4499,4500,4502,4504,4506,4507],{"type":1304,"url":4498},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-wwv5-g3v4-889x",{"type":1304,"url":2442},{"type":1304,"url":4501},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fpull\u002F3706",{"type":1304,"url":4503},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F6ef836e43e1278530041376adb32504daa977b91",{"type":1304,"url":4505},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fda284767eae8e1f0484f123b8c3225f6465b09c7",{"type":1301,"url":1645},{"type":1304,"url":2449},[1657,2451],{"id":219,"slug":4510,"dossier":47,"summary":4511,"aliases":4512,"sourceIds":4515,"published":4516,"modified":4517,"checkedAt":7,"severity":4518,"references":4522,"versionKeys":4531,"packageCount":32,"repositoryCount":103},"ghsa-x2qx-6953-8485-107f8fe2","GitPython: Unsafe option check validates multi_options before shlex.split transformation",[4513,4514],"CVE-2026-42284","PYSEC-2026-2161",[219,4514],"2026-04-25T23:41:49Z","2026-09-10T03:51:03.787491179Z",[4519,4521],{"type":1289,"score":4520},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":1289,"score":1328},[4523,4525,4527,4528,4529],{"type":1336,"url":4524},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-x2qx-6953-8485",{"type":1293,"url":4526},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42284",{"type":1301,"url":1341},{"type":1298,"url":4144},{"type":1304,"url":4530},"https:\u002F\u002Fwww.tenable.com\u002Fcve\u002FCVE-2026-32686",[1347,1348,1349],{"id":220,"slug":4533,"dossier":47,"summary":4534,"aliases":4535,"sourceIds":4539,"published":4540,"modified":4541,"checkedAt":7,"severity":4542,"references":4547,"versionKeys":4563,"packageCount":32,"repositoryCount":394},"ghsa-x3gm-94wq-g975-a197ba31","PyTorch: Manipulation of the argument scale\u002Fzero_point leads to improper initialization via Quantized Sigmoid Module",[4536,4537,4538],"BIT-pytorch-2025-2149","CVE-2025-2149","PYSEC-2025-190",[220],"2025-03-10T15:30:47Z","2026-06-09T22:11:08.734544854Z",[4543,4545],{"type":1289,"score":4544},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",{"type":1330,"score":4546},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[4548,4550,4552,4554,4556,4557,4559,4561],{"type":1293,"url":4549},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2149",{"type":1304,"url":4551},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147818",{"type":1304,"url":4553},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147818#issue-2877301660",{"type":1304,"url":4555},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-190.yaml",{"type":1301,"url":1478},{"type":1304,"url":4558},"https:\u002F\u002Fvuldb.com\u002F?ctiid.299060",{"type":1304,"url":4560},"https:\u002F\u002Fvuldb.com\u002F?id.299060",{"type":1304,"url":4562},"https:\u002F\u002Fvuldb.com\u002F?submit.506563",[1490,1491],{"id":221,"slug":4565,"dossier":47,"summary":4566,"aliases":4567,"sourceIds":4571,"published":4572,"modified":4573,"checkedAt":7,"severity":4574,"references":4576,"versionKeys":4590,"packageCount":32,"repositoryCount":34},"ghsa-xg8h-j46f-w952-da36a616","Pillow vulnerability can cause write buffer overflow on BCn encoding",[4568,4569,4570],"BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61",[221,4570],"2025-07-01T17:29:37Z","2026-09-10T03:50:26.431657121Z",[4575],{"type":1289,"score":2228},[4577,4579,4581,4583,4585,4587,4588],{"type":1293,"url":4578},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-xg8h-j46f-w952",{"type":1293,"url":4580},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-48379",{"type":1304,"url":4582},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9041",{"type":1298,"url":4584},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fef98b3510e3e4f14b547762764813d7e5ca3c5a4",{"type":1304,"url":4586},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2025-61.yaml",{"type":1301,"url":1680},{"type":1304,"url":4589},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F11.3.0",[1687],{"id":222,"slug":4592,"dossier":90,"summary":4593,"aliases":4594,"sourceIds":4598,"published":4599,"modified":4600,"checkedAt":7,"severity":4601,"references":4604,"versionKeys":4615,"packageCount":32,"repositoryCount":1693},"ghsa-xj96-63gp-2gmr-85e1cf15","Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`",[4595,4596,4597],"BIT-pillow-2026-59197","CVE-2026-59197","PYSEC-2026-3454",[222,4597],"2026-07-14T17:17:14.487Z","2026-09-10T03:50:53.192759645Z",[4602],{"type":1289,"score":4603},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:H",[4605,4607,4609,4611,4613,4614],{"type":1336,"url":4606},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-xj96-63gp-2gmr",{"type":1293,"url":4608},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59197",{"type":1298,"url":4610},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9695",{"type":1298,"url":4612},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fcce3bdb867c77a3420261ed1bfdb6b0787ec8fc1",{"type":1301,"url":1680},{"type":1293,"url":2044},[1684,1685,1686,1687,1688,1689,1690,1691,1692],{"id":223,"slug":4617,"dossier":47,"summary":4618,"aliases":4619,"sourceIds":4622,"published":4623,"modified":4624,"checkedAt":7,"severity":4625,"references":4628,"versionKeys":4641,"packageCount":32,"repositoryCount":1996},"ghsa-xrqw-3rrv-vx5w-3d985837","Transformers save_pretrained path traversal allows arbitrary file writes through chat template names",[4620,4621],"CVE-2026-9856","PYSEC-2026-3929",[223,4621],"2026-08-02T18:30:20Z","2026-09-10T12:25:36.528730268Z",[4626],{"type":1289,"score":4627},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:L",[4629,4631,4633,4635,4636,4638,4639],{"type":1293,"url":4630},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-9856",{"type":1304,"url":4632},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F46191",{"type":1304,"url":4634},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Feaaaf8494dd5386634ae37d1d122212fdc315be5",{"type":1301,"url":1368},{"type":1304,"url":4637},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F362824d5-fe18-40e8-a6cf-62277f97a170",{"type":1301,"url":1516},{"type":1293,"url":4640},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-xrqw-3rrv-vx5w",[1374,1375,1376,1377,1378,1379,1380,1381,1382,4642],"pypi:transformers@5.8.0",{"id":224,"slug":4644,"dossier":47,"summary":83,"aliases":4645,"sourceIds":4648,"published":4649,"modified":4650,"checkedAt":7,"severity":4651,"references":4654,"versionKeys":4663,"packageCount":32,"repositoryCount":32},"pysec-2025-112-653e8a7c",[4646,4647],"CVE-2025-64429","GHSA-vmp8-hg63-v2hp",[224],"2025-11-12T22:15:49.813Z","2026-05-20T09:18:59.601738Z",[4652],{"type":1289,"score":4653},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[4655,4657,4659,4661],{"type":1304,"url":4656},"https:\u002F\u002Fgithub.com\u002Fduckdb\u002Fduckdb\u002Fblob\u002F029a5b87ff5b1cd22f7f9717d48cd8830d00807c\u002Fsrc\u002Fcommon\u002Frandom_engine.cpp#L20",{"type":1293,"url":4658},"https:\u002F\u002Fduckdb.org\u002F2025\u002F09\u002F16\u002Fannouncing-duckdb-140.html",{"type":1293,"url":4660},"https:\u002F\u002Fgithub.com\u002Fduckdb\u002Fduckdb\u002Fsecurity\u002Fadvisories\u002FGHSA-vmp8-hg63-v2hp",{"type":1298,"url":4662},"https:\u002F\u002Fgithub.com\u002Fduckdb\u002Fduckdb\u002Fpull\u002F17275",[4664],"pypi:duckdb@1.4.1",{"id":225,"slug":4666,"dossier":47,"summary":83,"aliases":4667,"sourceIds":4670,"published":4671,"modified":4672,"checkedAt":7,"severity":4673,"references":4675,"versionKeys":4684,"packageCount":32,"repositoryCount":394},"pysec-2025-198-62b25ed4",[4668,4669],"BIT-pytorch-2025-46148","CVE-2025-46148",[225],"2025-09-25T15:16:12.007Z","2026-05-20T09:19:19.437232Z",[4674],{"type":1289,"score":3858},[4676,4678,4680,4682],{"type":1293,"url":4677},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F4bcefba4004f8271e64b5185c95a248a",{"type":1293,"url":4679},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F65a587a579dfdff887b9b35bb79b9093",{"type":1471,"url":4681},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151198",{"type":1298,"url":4683},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F152993",[1490,1491],{"id":226,"slug":4686,"dossier":47,"summary":83,"aliases":4687,"sourceIds":4690,"published":4691,"modified":4692,"checkedAt":7,"severity":4693,"references":4695,"versionKeys":4701,"packageCount":32,"repositoryCount":32},"pysec-2025-199-c528cb5a",[4688,4689],"BIT-pytorch-2025-46149","CVE-2025-46149",[226],"2025-09-25T15:16:12.153Z","2026-05-20T09:19:19.498677Z",[4694],{"type":1289,"score":3858},[4696,4697,4699],{"type":1293,"url":4677},{"type":1471,"url":4698},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147848",{"type":1298,"url":4700},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F147961",[1491],{"id":227,"slug":4703,"dossier":47,"summary":83,"aliases":4704,"sourceIds":4707,"published":4708,"modified":4709,"checkedAt":7,"severity":4710,"references":4712,"versionKeys":4720,"packageCount":32,"repositoryCount":32},"pysec-2025-200-d11172cd",[4705,4706],"BIT-pytorch-2025-46150","CVE-2025-46150",[227],"2025-09-25T15:16:12.303Z","2026-05-20T09:19:19.559970Z",[4711],{"type":1289,"score":3858},[4713,4714,4716,4718],{"type":1293,"url":4677},{"type":1471,"url":4715},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F141538",{"type":1471,"url":4717},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F141538#issuecomment-2537424658",{"type":1298,"url":4719},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F144395",[1491],{"id":228,"slug":4722,"dossier":47,"summary":83,"aliases":4723,"sourceIds":4726,"published":4727,"modified":4728,"checkedAt":7,"severity":4729,"references":4731,"versionKeys":4737,"packageCount":32,"repositoryCount":32},"pysec-2025-201-c002b022",[4724,4725],"BIT-pytorch-2025-46152","CVE-2025-46152",[228],"2025-09-25T15:16:12.470Z","2026-05-20T09:19:19.618679Z",[4730],{"type":1289,"score":1504},[4732,4733,4735],{"type":1293,"url":4677},{"type":1471,"url":4734},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F143555",{"type":1298,"url":4736},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F143635",[1491],{"id":229,"slug":4739,"dossier":47,"summary":83,"aliases":4740,"sourceIds":4743,"published":4744,"modified":4745,"checkedAt":7,"severity":4746,"references":4748,"versionKeys":4758,"packageCount":32,"repositoryCount":32},"pysec-2025-202-f0ff1751",[4741,4742],"BIT-pytorch-2025-46153","CVE-2025-46153",[229],"2025-09-25T15:16:12.603Z","2026-05-20T09:19:19.678555Z",[4747],{"type":1289,"score":3858},[4749,4751,4752,4754,4756],{"type":1304,"url":4750},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcompare\u002Fv2.6.0...v2.7.0",{"type":1293,"url":4677},{"type":1293,"url":4753},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002Fe636f2e7a306105b7e96809e2b85c28a",{"type":1471,"url":4755},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F142853",{"type":1298,"url":4757},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F143460",[1491],{"id":230,"slug":4760,"dossier":47,"summary":83,"aliases":4761,"sourceIds":4764,"published":4765,"modified":4766,"checkedAt":7,"severity":4767,"references":4769,"versionKeys":4774,"packageCount":32,"repositoryCount":66},"pysec-2025-203-2febb201",[4762,4763],"BIT-pytorch-2025-55551","CVE-2025-55551",[230],"2025-09-25T15:16:12.887Z","2026-05-20T09:19:19.739357Z",[4768],{"type":1289,"score":1531},[4770,4772],{"type":1293,"url":4771},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F0e7d2a586297ae9c8ed14d8706749efc",{"type":1471,"url":4773},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151401",[1490,1491,1492,2490,2491,3901],{"id":231,"slug":4776,"dossier":47,"summary":83,"aliases":4777,"sourceIds":4780,"published":4781,"modified":4782,"checkedAt":7,"severity":4783,"references":4785,"versionKeys":4789,"packageCount":32,"repositoryCount":66},"pysec-2025-204-cdae47da",[4778,4779],"BIT-pytorch-2025-55552","CVE-2025-55552",[231],"2025-09-25T16:15:34.320Z","2026-05-20T09:19:19.802802Z",[4784],{"type":1289,"score":1531},[4786,4787],{"type":1293,"url":4771},{"type":1471,"url":4788},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147847",[1490,1491,1492,2490,2491,3901],{"id":232,"slug":4791,"dossier":47,"summary":83,"aliases":4792,"sourceIds":4795,"published":4796,"modified":4797,"checkedAt":7,"severity":4798,"references":4800,"versionKeys":4806,"packageCount":32,"repositoryCount":375},"pysec-2025-205-fd5e58fd",[4793,4794],"BIT-pytorch-2025-55553","CVE-2025-55553",[232],"2025-09-25T16:15:34.460Z","2026-05-20T09:19:19.866970Z",[4799],{"type":1289,"score":1531},[4801,4802,4804],{"type":1293,"url":4771},{"type":1471,"url":4803},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151432",{"type":1298,"url":4805},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F154645",[1490,1491,1492],{"id":233,"slug":4808,"dossier":47,"summary":83,"aliases":4809,"sourceIds":4812,"published":4813,"modified":4814,"checkedAt":7,"severity":4815,"references":4817,"versionKeys":4821,"packageCount":32,"repositoryCount":66},"pysec-2025-206-58322476",[4810,4811],"BIT-pytorch-2025-55554","CVE-2025-55554",[233],"2025-09-25T16:15:34.593Z","2026-05-20T09:19:19.928295Z",[4816],{"type":1289,"score":1504},[4818,4819],{"type":1293,"url":4771},{"type":1471,"url":4820},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151510",[1490,1491,1492,2490,2491,3901],{"id":234,"slug":4823,"dossier":47,"summary":83,"aliases":4824,"sourceIds":4827,"published":4828,"modified":4829,"checkedAt":7,"severity":4830,"references":4832,"versionKeys":4838,"packageCount":32,"repositoryCount":375},"pysec-2025-207-2abef3fc",[4825,4826],"BIT-pytorch-2025-55557","CVE-2025-55557",[234],"2025-09-25T16:15:34.833Z","2026-05-20T09:19:19.989717Z",[4831],{"type":1289,"score":1531},[4833,4834,4836],{"type":1293,"url":4771},{"type":1471,"url":4835},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151738",{"type":1298,"url":4837},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151931",[1490,1491,1492],{"id":235,"slug":4840,"dossier":47,"summary":83,"aliases":4841,"sourceIds":4844,"published":4845,"modified":4846,"checkedAt":7,"severity":4847,"references":4849,"versionKeys":4855,"packageCount":32,"repositoryCount":375},"pysec-2025-208-6e93fe9d",[4842,4843],"BIT-pytorch-2025-55558","CVE-2025-55558",[235],"2025-09-25T16:15:34.960Z","2026-05-20T09:19:20.054109Z",[4848],{"type":1289,"score":1531},[4850,4851,4853],{"type":1293,"url":4771},{"type":1471,"url":4852},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151523",{"type":1298,"url":4854},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151887",[1490,1491,1492],{"id":236,"slug":4857,"dossier":47,"summary":83,"aliases":4858,"sourceIds":4861,"published":4862,"modified":4863,"checkedAt":7,"severity":4864,"references":4866,"versionKeys":4872,"packageCount":32,"repositoryCount":375},"pysec-2025-209-e6f352b0",[4859,4860],"BIT-pytorch-2025-55560","CVE-2025-55560",[236],"2025-09-25T16:15:35.197Z","2026-05-20T09:19:20.117285Z",[4865],{"type":1289,"score":1531},[4867,4868,4870],{"type":1293,"url":4771},{"type":1471,"url":4869},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151522",{"type":1298,"url":4871},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151897",[1490,1491,1492],{"id":237,"slug":4874,"dossier":47,"summary":83,"aliases":4875,"sourceIds":4877,"published":4878,"modified":4879,"checkedAt":7,"severity":4880,"references":4882,"versionKeys":4885,"packageCount":32,"repositoryCount":4886},"pysec-2025-211-d8bd15de",[4876],"CVE-2025-14920",[237],"2025-12-23T21:15:47.183Z","2026-05-21T15:00:32.080516132Z",[4881],{"type":1289,"score":1361},[4883],{"type":1293,"url":4884},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1150\u002F",[1374,1375,1376,1377,1378],5,{"id":238,"slug":4888,"dossier":47,"summary":83,"aliases":4889,"sourceIds":4891,"published":4892,"modified":4893,"checkedAt":7,"severity":4894,"references":4896,"versionKeys":4899,"packageCount":32,"repositoryCount":4886},"pysec-2025-212-a011b97d",[4890],"CVE-2025-14921",[238],"2025-12-23T21:15:47.340Z","2026-05-21T15:00:32.052313357Z",[4895],{"type":1289,"score":1361},[4897],{"type":1293,"url":4898},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1149\u002F",[1374,1375,1376,1377,1378],{"id":239,"slug":4901,"dossier":47,"summary":83,"aliases":4902,"sourceIds":4904,"published":4905,"modified":4906,"checkedAt":7,"severity":4907,"references":4909,"versionKeys":4912,"packageCount":32,"repositoryCount":4886},"pysec-2025-213-9043dc9b",[4903],"CVE-2025-14924",[239],"2025-12-23T21:15:47.600Z","2026-05-21T15:00:32.048516839Z",[4908],{"type":1289,"score":1361},[4910],{"type":1293,"url":4911},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1141\u002F",[1374,1375,1376,1377,1378],{"id":240,"slug":4914,"dossier":47,"summary":83,"aliases":4915,"sourceIds":4917,"published":4918,"modified":4919,"checkedAt":7,"severity":4920,"references":4922,"versionKeys":4925,"packageCount":32,"repositoryCount":4886},"pysec-2025-214-eb241255",[4916],"CVE-2025-14926",[240],"2025-12-23T21:15:47.857Z","2026-05-21T15:00:32.929011749Z",[4921],{"type":1289,"score":1361},[4923],{"type":1293,"url":4924},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1147\u002F",[1374,1375,1376,1377,1378],{"id":241,"slug":4927,"dossier":47,"summary":83,"aliases":4928,"sourceIds":4930,"published":4931,"modified":4932,"checkedAt":7,"severity":4933,"references":4935,"versionKeys":4938,"packageCount":32,"repositoryCount":4886},"pysec-2025-215-6064f491",[4929],"CVE-2025-14927",[241],"2025-12-23T21:15:47.987Z","2026-05-21T15:00:32.888290877Z",[4934],{"type":1289,"score":1361},[4936],{"type":1293,"url":4937},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1148\u002F",[1374,1375,1376,1377,1378],{"id":242,"slug":4940,"dossier":47,"summary":83,"aliases":4941,"sourceIds":4943,"published":4944,"modified":4945,"checkedAt":7,"severity":4946,"references":4948,"versionKeys":4951,"packageCount":32,"repositoryCount":4886},"pysec-2025-216-5708ed01",[4942],"CVE-2025-14928",[242],"2025-12-23T21:15:48.110Z","2026-05-21T15:00:32.939311939Z",[4947],{"type":1289,"score":1361},[4949],{"type":1293,"url":4950},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1146\u002F",[1374,1375,1376,1377,1378],{"id":243,"slug":4953,"dossier":47,"summary":83,"aliases":4954,"sourceIds":4956,"published":4957,"modified":4958,"checkedAt":7,"severity":4959,"references":4961,"versionKeys":4964,"packageCount":32,"repositoryCount":42},"pysec-2025-217-2c1ad388",[4955],"CVE-2025-14929",[243],"2025-12-23T21:15:48.240Z","2026-05-21T15:00:24.271970226Z",[4960],{"type":1289,"score":1361},[4962],{"type":1293,"url":4963},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1144\u002F",[1374,1375,1376,1377,1378,1379,1380,1381,1382],{"id":244,"slug":4966,"dossier":47,"summary":83,"aliases":4967,"sourceIds":4969,"published":4970,"modified":4971,"checkedAt":7,"severity":4972,"references":4974,"versionKeys":4977,"packageCount":32,"repositoryCount":1720},"pysec-2025-218-39811fc3",[4968],"CVE-2025-14930",[244],"2025-12-23T21:15:48.367Z","2026-05-21T15:00:33.791364554Z",[4973],{"type":1289,"score":1361},[4975],{"type":1293,"url":4976},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1145\u002F",[1374,1375,1376,1377,1378,1379],{"id":245,"slug":4979,"dossier":47,"summary":83,"aliases":4980,"sourceIds":4983,"published":4984,"modified":4985,"checkedAt":7,"severity":4986,"references":4988,"versionKeys":4999,"packageCount":32,"repositoryCount":5000},"pysec-2026-139-96951ff6",[4981,4982],"BIT-pytorch-2026-4538","CVE-2026-4538",[245],"2026-03-22T05:16:20.273Z","2026-05-21T15:00:31.962442644Z",[4987],{"type":1289,"score":2287},[4989,4991,4993,4995,4997],{"type":1304,"url":4990},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002F",{"type":1293,"url":4992},"https:\u002F\u002Fvuldb.com\u002F?id.352326",{"type":1293,"url":4994},"https:\u002F\u002Fvuldb.com\u002F?submit.774681",{"type":1471,"url":4996},"https:\u002F\u002Fvuldb.com\u002F?ctiid.352326",{"type":1298,"url":4998},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F176791",[4177,1490,1491,1492,2490,2491,3901,3902,3903,3904],14,{"id":246,"slug":5002,"dossier":90,"summary":83,"aliases":5003,"sourceIds":5006,"published":5007,"modified":5008,"checkedAt":7,"severity":5009,"references":5012,"versionKeys":5027,"packageCount":32,"repositoryCount":1693},"pysec-2026-2132-627bf7c7",[5004,5005],"CVE-2026-7246","GHSA-47fr-3ffg-hgmw",[246],"2026-04-30T14:16:36.433Z","2026-07-13T07:15:21.899333658Z",[5010],{"type":1289,"score":5011},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[5013,5015,5017,5019,5021,5023,5025],{"type":1304,"url":5014},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-7246",{"type":1304,"url":5016},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-7246.json",{"type":1293,"url":5018},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24761",{"type":1293,"url":5020},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24762",{"type":1471,"url":5022},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2464121",{"type":1298,"url":5024},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fclick\u002Freleases\u002Ftag\u002F8.3.3",{"type":1336,"url":5026},"https:\u002F\u002Fgithub.com\u002Ftsigouris007\u002Fsecurity-advisories\u002Fsecurity\u002Fadvisories\u002FGHSA-47fr-3ffg-hgmw",[5028,5029,5030,5031,5032,5033],"pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1",{"id":247,"slug":5035,"dossier":47,"summary":83,"aliases":5036,"sourceIds":5041,"published":5042,"modified":5043,"checkedAt":7,"severity":5044,"references":5046,"versionKeys":5063,"packageCount":32,"repositoryCount":345},"pysec-2026-2286-8795b007",[5037,5038,5039,5040],"BIT-pytorch-2026-24747","CVE-2026-24747","GHSA-63cw-57p8-fm3p","PYSEC-2026-1856",[247],"2026-01-27T22:15:56.470Z","2026-07-13T07:26:23.701611780Z",[5045],{"type":1289,"score":2954},[5047,5049,5051,5053,5055,5057,5059,5061],{"type":1304,"url":5048},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-24747",{"type":1304,"url":5050},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-24747.json",{"type":1293,"url":5052},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24977",{"type":1293,"url":5054},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Freleases\u002Ftag\u002Fv2.10.0",{"type":1293,"url":5056},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fsecurity\u002Fadvisories\u002FGHSA-63cw-57p8-fm3p",{"type":1471,"url":5058},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2433612",{"type":1471,"url":5060},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F163105",{"type":1298,"url":5062},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002F163122\u002Fcommit\u002F954dc5183ee9205cbe79876ad05dd2d9ae752139",[1490,1491,1492,2490,2491,3901,3902,3903,3904],{"id":248,"slug":5065,"dossier":47,"summary":83,"aliases":5066,"sourceIds":5069,"published":5070,"modified":5071,"checkedAt":7,"severity":5072,"references":5075,"versionKeys":5080,"packageCount":32,"repositoryCount":103},"pysec-2026-3982-7ce8a239",[5067,5068],"CVE-2026-87817","GHSA-239g-whfq-7xj9",[248],"2026-09-09T12:17:16.830Z","2026-09-17T09:00:03.355630821Z",[5073],{"type":1330,"score":5074},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[5076,5078],{"type":1293,"url":5077},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonation",{"type":1336,"url":5079},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-239g-whfq-7xj9",[1347,1348,1349],{"id":249,"slug":5082,"dossier":47,"summary":83,"aliases":5083,"sourceIds":5086,"published":5087,"modified":5088,"checkedAt":7,"severity":5089,"references":5091,"versionKeys":5096,"packageCount":32,"repositoryCount":103},"pysec-2026-3984-82a1692f",[5084,5085],"CVE-2026-87819","GHSA-g5vv-9gxw-82hx",[249],"2026-09-09T12:17:17.120Z","2026-09-17T09:00:03.352876639Z",[5090],{"type":1289,"score":1531},[5092,5094],{"type":1293,"url":5093},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fgitpython-before-3.1.60-denial-of-service-via-redos",{"type":1336,"url":5095},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-g5vv-9gxw-82hx",[1347,1348,1349],1790757843517]