iqsh/collaboration-online-board/aiThis dossier retains 43 exact component occurrences from 2 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:e053bc3719cac7ca6a6b278c6593b5be1eef3090462cdd7398ae6d6ac3f21457pypi:openai1.14.2 · 1.91.0pypi:tiktoken0.7.0pypi:pillow10.3.020 OSV records returnedpypi:urllib32.2.27 OSV records returnedpypi:werkzeug3.0.16 OSV records returnedpypi:flask-cors4.0.05 OSV records returnedpypi:jinja23.1.34 OSV records returnedpypi:requests2.32.33 OSV records returnedpypi:setuptools69.2.03 OSV records returnedpypi:anyio4.3.02 OSV records returnedpypi:certifi2024.6.21 OSV record returnedpypi:click8.1.71 OSV record returnedpypi:flask3.0.21 OSV record returnedpypi:h110.14.01 OSV record returnedpypi:idna3.71 OSV record returnedpypi:pytest7.2.21 OSV record returnedpypi:python-dotenv1.0.11 OSV record returnedpypi:tqdm4.66.21 OSV record returnedpypi:wheel0.43.01 OSV record returnedpypi:annotated-types0.6.0pypi:attrs23.2.0pypi:blinker1.7.0pypi:charset-normalizer3.3.2pypi:coverage7.2.2pypi:distro1.9.0pypi:flask-sqlalchemy3.1.1pypi:greenlet3.0.3pypi:httpcore1.0.4pypi:httpx0.27.0pypi:iniconfig2.0.0pypi:itsdangerous2.1.2pypi:markupsafe2.1.5pypi:packaging24.1pypi:pluggy1.5.0pypi:psycopg2-binary2.9.9pypi:pydantic2.6.4pypi:pydantic-core2.16.3pypi:regex2024.5.15pypi:sniffio1.3.1pypi:sqlalchemy2.0.29pypi:typing-extensions4.10.0Certifi removes GLOBALTRUST root certificate
10 Sept 2026Werkzeug safe_join() allows Windows special device names
10 Sept 2026Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
25 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026Flask-CORS vulnerable to Improper Handling of Case Sensitivity
10 Sept 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10 Sept 2026AnyIO process-pool workers can block indefinitely on undrained stderr
18 Sept 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10 Sept 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10 Sept 2026Pillow has a heap buffer overflow with nested list coordinates
10 Sept 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10 Sept 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10 Sept 2026Flask session does not add `Vary: Cookie` header when accessed in some ways
10 Sept 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
10 Sept 2026pytest has vulnerable tmpdir handling
10 Sept 2026Flask-CORS improper regex path matching vulnerability
10 Sept 2026AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
18 Sept 2026flask-cors vulnerable to log injection when the log level is set to debug
10 Sept 2026Werkzeug safe_join() allows Windows special device names with compound extensions
10 Sept 2026Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
10 Sept 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
10 Sept 2026Flask-CORS allows for inconsistent CORS matching
10 Sept 2026Requests vulnerable to .netrc credentials leak via malicious URLs
10 Sept 2026Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
10 Sept 2026Requests `Session` object does not verify requests after making first request with verify=False
10 Sept 2026Pillow affected by out-of-bounds write when loading PSD images
10 Sept 2026Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
10 Sept 2026setuptools vulnerable to Command Injection via package URL
10 Sept 2026Werkzeug safe_join not safe on Windows
10 Sept 2026Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
10 Sept 2026tqdm CLI arguments injection attack
10 Sept 2026Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
10 Sept 2026urllib3 allows an unbounded number of links in the decompression chain
10 Sept 2026Jinja has a sandbox breakout through malicious filenames
10 Sept 2026setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
10 Sept 2026Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
10 Sept 2026Werkzeug safe_join() allows Windows special device names
10 Sept 2026Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
10 Sept 2026Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
10 Sept 2026urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
10 Sept 2026python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
10 Sept 2026Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
10 Sept 2026Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
10 Sept 2026urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
10 Sept 2026Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
10 Sept 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): AI — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-3608/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.