uba-ki-lab/llm-testframeworkThis dossier retains 207 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:12d0fc9d738085b94454bfb018cbb5fb882c9a1a7e6fd4d1922ea65970708327pypi:vllm0.8.5.post152 OSV records returnedpypi:transformers4.51.326 OSV records returnedpypi:litellm1.68.023 OSV records returnedpypi:torch2.6.023 OSV records returnedpypi:datasets3.5.11 OSV record returnedpypi:dspy2.6.231 OSV record returnedpypi:scikit-learn1.6.11 OSV record returnedpypi:openai1.75.0pypi:sentence-transformers4.1.0pypi:codecarbon3.0.1pypi:tokenizers0.21.1pypi:tiktoken0.9.0pypi:xgboost3.0.0pypi:aiohttp3.11.1833 OSV records returnedpypi:pillow11.2.120 OSV records returnedpypi:cryptography44.0.39 OSV records returnedpypi:python-multipart0.0.208 OSV records returnedpypi:starlette0.46.28 OSV records returnedpypi:urllib32.4.07 OSV records returnedpypi:ray2.45.06 OSV records returnedpypi:pyasn10.6.15 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:ujson5.10.04 OSV records returnedpypi:requests2.32.33 OSV records returnedpypi:setuptools80.3.13 OSV records returnedpypi:anyio4.9.02 OSV records returnedpypi:filelock3.18.02 OSV records returnedpypi:mako1.3.102 OSV records returnedpypi:protobuf4.25.72 OSV records returnedpypi:xgrammar0.1.182 OSV records returnedpypi:certifi2025.4.261 OSV record returnedpypi:click8.1.81 OSV record returnedpypi:diskcache5.6.31 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:hydra-core1.3.21 OSV record returnedpypi:idna3.101 OSV record returnedpypi:json-repair0.44.11 OSV record returnedpypi:jwcrypto1.5.61 OSV record returnedpypi:msgpack1.1.01 OSV record returnedpypi:pyarrow20.0.01 OSV record returnedpypi:pygments2.19.11 OSV record returnedpypi:python-dotenv1.1.01 OSV record returnedpypi:sentencepiece0.2.01 OSV record returnedpypi:tqdm4.67.11 OSV record returnedpypi:virtualenv20.31.11 OSV record returnedpypi:aiohappyeyeballs2.6.1pypi:aiohttp-cors0.8.1pypi:aiosignal1.3.2pypi:airportsdata20250224pypi:alembic1.15.2pypi:annotated-types0.7.0pypi:antlr4-python3-runtime4.9.3pypi:arrow1.3.0pypi:astor0.8.1pypi:asyncer0.0.8pypi:attrs25.3.0pypi:backoff2.2.1pypi:blake31.0.4pypi:cachetools5.5.2pypi:cffi1.17.1pypi:charset-normalizer3.4.2pypi:cloudpickle3.1.1pypi:colorama0.4.6pypi:colorful0.5.6pypi:colorlog6.9.0pypi:compressed-tensors0.9.3pypi:cupy-cuda12x13.4.1pypi:deprecated1.2.18pypi:depyf0.18.0pypi:dill0.3.8pypi:distlib0.3.9pypi:distro1.9.0pypi:dnspython2.7.0pypi:einops0.8.1pypi:email-validator2.2.0pypi:fastapi0.115.12pypi:fastapi-cli0.0.7pypi:fastrlock0.8.3pypi:fief-client0.20.0pypi:frozenlist1.6.0pypi:fsspec2025.3.0pypi:gguf0.16.3pypi:google-api-core2.24.2pypi:google-auth2.40.0pypi:googleapis-common-protos1.70.0pypi:greenlet3.2.1pypi:grpcio1.71.0pypi:hf-xet1.1.0pypi:httpcore1.0.9pypi:httptools0.6.4pypi:httpx0.27.2pypi:huggingface-hub0.30.2pypi:importlib-metadata8.0.0pypi:interegular0.3.3pypi:jiter0.9.0pypi:joblib1.5.0pypi:jsonschema4.23.0pypi:jsonschema-specifications2025.4.1pypi:lark1.2.2pypi:llguidance0.7.19pypi:llvmlite0.44.0pypi:lm-format-enforcer0.10.11pypi:magicattr0.1.6pypi:markdown-it-py3.0.0pypi:markupsafe3.0.2pypi:mdurl0.1.2pypi:mistral-common1.5.4pypi:mpmath1.3.0pypi:msgspec0.19.0pypi:multidict6.4.3pypi:multiprocess0.70.16pypi:nest-asyncio1.6.0pypi:networkx3.4.2pypi:ninja1.11.1.4pypi:numba0.61.2pypi:numpy2.2.5pypi:nvidia-cublas-cu1212.4.5.8pypi:nvidia-cuda-cupti-cu1212.4.127pypi:nvidia-cuda-nvrtc-cu1212.4.127pypi:nvidia-cuda-runtime-cu1212.4.127This page displays 120 of 207 ordered rows. The machine-readable dossier retains the complete exact projection.
Certifi removes GLOBALTRUST root certificate
10 Sept 2026HuggingFace transformers vulnerable to remote code execution
10 Sept 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10 Sept 2026Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
10 Sept 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
10 Sept 2026Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
10 Sept 2026vLLM affected by RCE via auto_map dynamic module loading during model initialization
10 Sept 2026AIOHTTP has CRLF injection through multipart part content type header construction
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
25 Sept 2026PyTorch susceptible to local Denial of Service
10 Sept 2026Transformers is vulnerable to ReDoS attack through its DonutProcessor class
10 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026Sentencepiece has a a heap overflow issue
10 Sept 2026vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
10 Sept 2026UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
10 Sept 2026vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
10 Sept 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
10 Sept 2026vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
10 Sept 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
10 Sept 2026vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
10 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
10 Sept 2026LiteLLM: Local file read via request-supplied OIDC file references
10 Sept 2026vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
10 Sept 2026LiteLLM: MCP Proxy Has Improper Authentication
11 Sept 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
10 Sept 2026Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
07 Aug 2026vLLM has RCE In Video Processing
10 Sept 2026Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
10 Sept 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
10 Sept 2026LiteLLM: Authentication Bypass via Host Header Injection
10 Sept 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
10 Sept 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07 Aug 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
10 Sept 2026virtualenv Has TOCTOU Vulnerabilities in Directory Creation
10 Sept 2026Denial of service (DoS) via deformation `multipart/form-data` boundary
10 Sept 2026Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
10 Sept 2026XGrammar affected by Denial of Service by infinite recursion grammars
10 Sept 2026LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
10 Sept 2026vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
10 Sept 2026AnyIO process-pool workers can block indefinitely on undrained stderr
18 Sept 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
10 Sept 2026python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
10 Sept 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
10 Sept 2026Pillow has a heap buffer overflow with nested list coordinates
10 Sept 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
10 Sept 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): LLM Testframework — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-5012/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.