[{"data":1,"prerenderedAt":8545},["ShallowReactive",2],{"ki-abhaengigkeitsatlas-repository-opencode-5530":3},{"schemaVersion":4,"dataset":5,"parserVersion":6,"generatedAt":7,"trackingSince":8,"source":9,"coverage":29,"methodology":41,"summary":60,"kind":75,"entity":76,"evidence":357,"related":360},"ki-abhaengigkeitsatlas\u002Fv1","german-public-sector-ai-dependency-atlas","1","2026-08-13T02:29:21.454Z","2026-07-18T21:20:30.334Z",{"codeRadar":10,"openCode":15,"depsDev":18,"osv":21,"spdx":24},{"dataset":11,"generatedAt":12,"parserVersion":13,"url":14},"german-public-sector-ai-code-radar","2026-08-13T02:28:06.466Z","3","https:\u002F\u002Fi6eal.de\u002Ftools\u002Fki-code-radar\u002F",{"label":16,"url":17},"openCode GitLab","https:\u002F\u002Fgitlab.opencode.de\u002F",{"label":19,"url":20},"deps.dev API v3","https:\u002F\u002Fdocs.deps.dev\u002Fapi\u002Fv3\u002F",{"label":22,"url":23},"OSV API","https:\u002F\u002Fgoogle.github.io\u002Fosv.dev\u002Fapi\u002F",{"label":25,"url":26,"version":27,"releaseDate":28},"SPDX License List","https:\u002F\u002Fspdx.org\u002Flicenses\u002F","3.28.0","2026-02-20T00:00:00Z",{"repositoryCount":30,"completeTreeCount":31,"incompleteTreeCount":32,"lockfileRepositoryCount":33,"sbomRepositoryCount":34,"artifactRepositoryCount":35,"resolvedRepositoryCount":31,"resolvedArtifactRepositoryCount":35,"dependencyFileCount":36,"parsedFileCount":30,"parseErrorCount":32,"unsupportedFileCount":37,"evaluatedVersionCount":38,"metadataResolvedCount":39,"metadataNotFoundCount":40,"osvEvaluatedVersionCount":38,"codeRadarRepositoryCount":30},31,30,1,18,4,21,32,0,3642,3632,10,{"componentParserSchemaVersion":42,"candidateBoundary":43,"resolvedVersionBoundary":44,"manifestRangesResolved":45,"latestVersionSubstitution":45,"containerTagsVulnerabilityChecked":45,"osvClaim":46,"depsDevLicenseSemantics":47,"providerSemantics":48,"generativeAiUsed":45,"scoreUsed":45,"treeEntryCeiling":49,"fileByteCeiling":50,"uniqueVersionCeiling":51,"observedFormats":52},"ki-dependency-atlas-components\u002Fv1","repositories_with_exact_ai_code_evidence","exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin",false,"osv_matched_observed_resolved_package_version_at_collection_time","spdx_expressions_as_reported_without_inferred_compatibility","package_interface_presence_not_api_configuration_procurement_or_use",2500,5242880,8000,[53,54,55,56,57,58,59],"package-lock.json \u002F npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins",{"repositoryCount":30,"packageCount":61,"aiPackageCount":62,"resolvedComponentCount":63,"resolvedVersionCount":38,"providerExposureRepositoryCount":64,"licenseExpressionCount":65,"knownLicensePackageCount":66,"unknownLicensePackageCount":31,"advisoryCount":67,"matchedAdvisoryRepositoryCount":68,"topPackage":69},2274,44,5994,6,53,2244,640,26,{"id":70,"slug":71,"label":72,"repositoryCount":73,"repositoryShare":74},"package:pypi:openai","openai-0dd26ac5","OpenAI SDK",19,0.6129032258064516,"repository",{"id":77,"slug":78,"gitlabProjectId":79,"name":80,"pathWithNamespace":81,"description":82,"webUrl":83,"commitSha":84,"commitUrl":85,"lastActivityAt":86,"headCommittedAt":87,"tree":88,"files":90,"resolvedComponentCount":98,"artifactResolvedComponentCount":98,"exactManifestPinCount":37,"packageCount":99,"ecosystems":100,"aiPackageCount":40,"licenseExpressionCount":102,"unknownLicensePackageCount":32,"advisoryIds":103,"advisoryCount":355,"providers":356},"opencode:5530","opencode-5530",5530,"GSA Extraction","uba-ki-lab\u002Fgsa-extraction","information extraction and summarization; Keywords: uba, umweltbundesamt, ki-lab, NLP, LLM, GSA","https:\u002F\u002Fgitlab.opencode.de\u002Fuba-ki-lab\u002Fgsa-extraction","f5161e79d3f8c53877f9b1b0d72e1c10bff775ba","https:\u002F\u002Fgitlab.opencode.de\u002Fuba-ki-lab\u002Fgsa-extraction\u002F-\u002Fcommit\u002Ff5161e79d3f8c53877f9b1b0d72e1c10bff775ba","2025-07-08T06:55:06.033Z","2025-07-08T06:55:00.000Z",{"complete":89,"entryCount":36,"truncated":45},true,[91],{"path":54,"kind":92,"blobSha":93,"sourceUrl":94,"commitSha":84,"contentSha256":95,"byteCount":96,"state":97,"componentCount":98},"uv-lock","fbb23733e647554b5678500b3f17f13bac7f77f5","https:\u002F\u002Fgitlab.opencode.de\u002Fuba-ki-lab\u002Fgsa-extraction\u002F-\u002Fblob\u002Ff5161e79d3f8c53877f9b1b0d72e1c10bff775ba\u002Fuv.lock","766ab3a9e501607f926b430b6937368e9157d2bb2417294c81529c0b0de9999a",681172,"parsed",193,189,[101],"pypi",23,[104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270,271,272,273,274,275,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,301,302,303,304,305,306,307,308,309,310,311,312,313,314,315,316,317,318,319,320,321,322,323,324,325,326,327,328,329,330,331,332,333,334,335,336,337,338,339,340,341,342,343,344,345,346,347,348,349,350,351,352,353,354],"GHSA-248v-346w-9cwc","GHSA-27jp-wm6q-gp25","GHSA-29pf-2h5f-8g72","GHSA-29vq-49wr-vm6x","GHSA-2c2j-9gv5-cj73","GHSA-2f96-g7mh-g2hx","GHSA-2fqr-mr3j-6wp8","GHSA-2g68-c3qc-8985","GHSA-2h4p-vjrc-8xpq","GHSA-2vrm-gr82-f7m5","GHSA-2xpw-w6gg-jr37","GHSA-33p9-3p43-82vq","GHSA-3749-ghw9-m3mg","GHSA-37mw-44qp-f5jm","GHSA-38jv-5279-wg99","GHSA-3f7w-8rr8-f37f","GHSA-3j69-69wj-xqx2","GHSA-3rp5-jjmw-4wv2","GHSA-3wq7-rqq7-wx6j","GHSA-3x9g-8vmp-wqvf","GHSA-42h5-h8qh-vv9v","GHSA-45hq-cxwh-f6vc","GHSA-469j-vmhf-r6v7","GHSA-46r5-x6jq-v8g6","GHSA-48p4-8xcf-vxj5","GHSA-4fvr-rgm6-gqmc","GHSA-4g5m-c9r5-49xf","GHSA-4gmw-gg2m-w46p","GHSA-4m7w-qmgq-4wj5","GHSA-4w7r-h757-3r74","GHSA-4x4j-2g7c-83w6","GHSA-4x5p-f36r-mxxr","GHSA-4xh5-x5gv-qwph","GHSA-4xpc-pv4p-pm3w","GHSA-5239-wwwm-4pmq","GHSA-539m-9xh6-q6rr","GHSA-53mr-6c8q-9789","GHSA-53q9-r3pm-6pq6","GHSA-54jq-c3m8-4m76","GHSA-58qw-9mgm-455v","GHSA-59p9-h35m-wg4g","GHSA-5jmr-gcrj-2c9q","GHSA-5qmp-p3c4-72qj","GHSA-5rjg-fvgr-3xxf","GHSA-5x94-69rx-g8h2","GHSA-5xmw-vc9v-4wf2","GHSA-62p4-gmf7-7g93","GHSA-63hf-3vf5-4wqf","GHSA-63hw-fmq6-xxg2","GHSA-63vm-454h-vhhq","GHSA-65h7-c7c4-mghx","GHSA-65pc-fj4g-8rjx","GHSA-68j8-pq59-fqgm","GHSA-68rp-wp8r-4726","GHSA-69f9-5gxw-wvc2","GHSA-69w3-r845-3855","GHSA-69x8-hrgq-fjj8","GHSA-6hm5-jgcp-p838","GHSA-6jhg-hg63-jvvf","GHSA-6mq8-rvhq-8wgg","GHSA-6p8h-3wgx-97gf","GHSA-6r8x-57c9-28j4","GHSA-6rvg-6v2m-4j46","GHSA-6vgw-5pg2-w6jp","GHSA-72m8-9m7m-h278","GHSA-7488-6r32-c95q","GHSA-7545-fcxq-7j24","GHSA-75cm-x2w3-8mgf","GHSA-768j-98cg-p3fv","GHSA-78cv-mqj4-43f7","GHSA-7cx3-6m66-7c5m","GHSA-7f5h-v6xp-fcq8","GHSA-7gcm-g887-7qv7","GHSA-7p94-766c-hgjp","GHSA-7qhf-v65m-g5f3","GHSA-82w8-qh3p-5jfq","GHSA-848c-c2cx-j7qx","GHSA-86qp-5c8j-p5mr","GHSA-87hc-h4r5-73f7","GHSA-887c-mr87-cxwp","GHSA-8c7q-86fq-vvmh","GHSA-8ppf-4f7h-5ppj","GHSA-8qvm-5x2c-j2w7","GHSA-8v84-f9pq-wr9x","GHSA-9356-575x-2w9m","GHSA-94p4-4cq8-9g67","GHSA-9548-qrrj-x5pj","GHSA-956x-8gvw-wg5v","GHSA-966j-vmvw-g2g9","GHSA-9hjg-9r4m-mvj7","GHSA-9hw9-ch79-4vh6","GHSA-9rj7-rf2p-w77r","GHSA-9wx4-h78v-vm56","GHSA-9x8q-7h8h-wcw9","GHSA-c38f-wx89-p2xg","GHSA-c427-h43c-vf67","GHSA-c678-jfcj-6jmf","GHSA-c8rr-9gxc-jprv","GHSA-c98p-7wgm-6p64","GHSA-cfh3-3jmp-rvhc","GHSA-cpwx-vrp4-4pq7","GHSA-cq5v-8q36-5273","GHSA-cx3h-4qpv-8hc9","GHSA-cx63-2mw6-8hw5","GHSA-f2m9-wcf4-cwwx","GHSA-f4hp-rmr7-r7v8","GHSA-f96h-pmfr-66vw","GHSA-f9vj-2wh5-fj8j","GHSA-fg7f-2386-8897","GHSA-fgcw-684q-jj6r","GHSA-fh2c-86xm-pm2x","GHSA-fh55-r93g-j68g","GHSA-fh64-r2vc-xvhr","GHSA-fhff-qmm8-h2fp","GHSA-fj7v-r99m-22gq","GHSA-fjcf-3j3r-78rp","GHSA-fjr4-x663-mwxc","GHSA-fpwr-67px-3qhx","GHSA-g35p-px32-whv6","GHSA-g3cq-j2xw-wf74","GHSA-g6pg-52vf-843h","GHSA-g7vv-2v7x-gj9p","GHSA-g84x-mcqj-x9qq","GHSA-gc5v-m9x4-r6x2","GHSA-gfwx-w7gr-fvh7","GHSA-gm62-xv2j-4w53","GHSA-gmj6-6f8f-6699","GHSA-gq3w-7jj3-x7gr","GHSA-h35f-9h28-mq5c","GHSA-h75v-3vvj-5mfj","GHSA-h8wq-7xc4-p3qx","GHSA-hcc4-c3v8-rx92","GHSA-hg6j-4rv6-33pg","GHSA-hgf8-39gv-g3f2","GHSA-hh9p-6wh2-4mfc","GHSA-hm4w-wwcw-mr6r","GHSA-hmq2-w58f-27jc","GHSA-hpj7-wq8m-9hgp","GHSA-hxxf-235m-72v3","GHSA-jg22-mg44-37j8","GHSA-jhmp-mqwm-3gq8","GHSA-jj3x-wxrx-4x23","GHSA-jjhc-v7c2-5hh6","GHSA-jjj6-mw9f-p565","GHSA-jjph-296x-mrcr","GHSA-jm6w-m3j8-898g","GHSA-jm78-9fvv-mhgr","GHSA-jp4c-xjxw-mgf9","GHSA-jp82-jpqv-5vv3","GHSA-jr27-m4p2-rc6r","GHSA-m4p7-r5rc-7g4j","GHSA-m5qp-6w8w-w647","GHSA-m6qw-4cw2-hm4m","GHSA-mf9v-mfxr-j63j","GHSA-mf9w-mj56-hr94","GHSA-mfx4-hv73-q22v","GHSA-mgf9-4vpg-hj56","GHSA-mq26-g339-26xf","GHSA-mq44-7p77-q5h7","GHSA-mqqc-3gqh-h2x8","GHSA-mv93-w799-cj2w","GHSA-mwh4-6h8g-pg8w","GHSA-p4gq-832x-fm9v","GHSA-p538-c434-8v24","GHSA-p998-jp59-783m","GHSA-pg7v-jwj7-p798","GHSA-pgqp-8h46-6x4j","GHSA-phhr-52qp-3mj4","GHSA-phj9-mv4w-65pm","GHSA-pq67-6m6q-mj2v","GHSA-pr2v-jx2c-wg9f","GHSA-pw6j-qg29-8w7f","GHSA-pwv6-vv43-88gr","GHSA-q2r8-vmq7-fpx2","GHSA-q2wp-rjmx-x6x9","GHSA-q2x7-8rv6-6q7h","GHSA-q34m-jh98-gwm2","GHSA-qccp-gfcp-xxvc","GHSA-qfhq-4f3w-5fph","GHSA-qjxf-f2mg-c6mc","GHSA-qmgc-5h2g-mvrw","GHSA-qq3j-4f4f-9583","GHSA-qrc4-49gv-mv9m","GHSA-qvv7-cg9c-w4x3","GHSA-qxrp-vhvm-j765","GHSA-r23q-823p-vmf7","GHSA-r5m9-wm49-959f","GHSA-r73j-pqj5-w3x7","GHSA-r9mr-m37c-5fr3","GHSA-rcv9-qm8p-9p6j","GHSA-rf74-v2fm-23pw","GHSA-rgxp-2hwp-jwgg","GHSA-rpm5-65cw-6hj4","GHSA-rrmf-rvhw-rf47","GHSA-rvhj-8chj-8v3c","GHSA-rwj8-pgh3-r573","GHSA-v87r-6q3f-2j67","GHSA-v92g-xgxw-vvmm","GHSA-vgrw-7cvw-pwgx","GHSA-vhcx-3pq2-4fvc","GHSA-vjc4-5qp5-m44j","GHSA-vqfr-h8mv-ghfj","GHSA-vvw2-h478-xwr3","GHSA-w2fm-2cpv-w7v5","GHSA-w5xq-c4pf-ghq7","GHSA-w853-jp5j-5j7f","GHSA-w8v5-vhqr-4h9v","GHSA-wf7f-8fxf-xfxc","GHSA-wf93-45jw-7689","GHSA-wgvc-ghv9-3pmm","GHSA-whj4-6x5x-4v2j","GHSA-wjx4-4jcj-g98j","GHSA-wpfp-gwwc-vwq6","GHSA-wqp7-x3pw-xc5r","GHSA-wrfc-pvp9-mr9g","GHSA-wvpp-8hx9-p66j","GHSA-x2qx-6953-8485","GHSA-x3gm-94wq-g975","GHSA-x746-7m8f-x49c","GHSA-xcgm-r5h9-7989","GHSA-xch3-2f9x-wh9f","GHSA-xf7x-x43h-rpqh","GHSA-xg8h-j46f-w952","GHSA-xh95-f55m-82fw","GHSA-xj96-63gp-2gmr","PYSEC-2025-198","PYSEC-2025-199","PYSEC-2025-200","PYSEC-2025-201","PYSEC-2025-202","PYSEC-2025-203","PYSEC-2025-204","PYSEC-2025-205","PYSEC-2025-206","PYSEC-2025-207","PYSEC-2025-208","PYSEC-2025-209","PYSEC-2025-211","PYSEC-2025-212","PYSEC-2025-213","PYSEC-2025-214","PYSEC-2025-215","PYSEC-2025-216","PYSEC-2025-217","PYSEC-2025-218","PYSEC-2026-139","PYSEC-2026-2085","PYSEC-2026-2132","PYSEC-2026-2286","PYSEC-2026-597","PYSEC-2026-99",251,[],{"files":358,"occurrenceCount":98},[359],{"path":54,"kind":92,"blobSha":93,"sourceUrl":94,"commitSha":84,"contentSha256":95,"byteCount":96,"state":97,"componentCount":98},{"packages":361,"vulnerabilities":2081},[362,376,387,398,407,417,426,436,446,455,464,475,484,494,506,516,525,535,545,554,563,574,583,594,604,613,624,633,642,652,661,670,678,687,696,705,714,723,732,741,750,759,769,778,788,797,806,815,824,833,842,851,860,869,878,887,896,905,914,924,933,941,950,959,968,977,986,995,1004,1013,1022,1031,1039,1048,1057,1066,1075,1084,1092,1101,1110,1119,1128,1137,1146,1157,1166,1175,1184,1193,1202,1210,1219,1228,1238,1246,1254,1263,1272,1281,1290,1299,1308,1317,1326,1334,1343,1352,1361,1370,1378,1386,1395,1404,1413,1422,1432,1441,1450,1459,1467,1476,1485,1494,1503,1512,1521,1530,1539,1548,1556,1565,1574,1582,1591,1600,1610,1618,1627,1635,1644,1653,1662,1671,1680,1689,1698,1707,1716,1725,1734,1742,1751,1760,1769,1778,1787,1796,1805,1815,1824,1832,1841,1850,1858,1868,1877,1886,1896,1905,1913,1922,1931,1940,1948,1956,1965,1974,1983,1992,2001,2010,2018,2027,2036,2045,2054,2063,2072],{"id":363,"slug":364,"identity":365,"label":366,"aiRelevant":89,"provider":367,"advisoryCount":370,"licenseExpressions":371,"versions":373,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":375},"package:pypi:transformers","transformers-65289303","pypi:transformers","Transformers",{"id":368,"label":369},"hugging-face","Hugging Face",25,[372],"Apache-2.0",[374],"4.53.1",[54],{"id":377,"slug":378,"identity":379,"label":380,"aiRelevant":89,"provider":381,"advisoryCount":102,"licenseExpressions":382,"versions":384,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":386},"package:pypi:torch","torch-47a5352a","pypi:torch","PyTorch",null,[383],"BSD-3-Clause",[385],"2.7.1",[54],{"id":388,"slug":389,"identity":390,"label":391,"aiRelevant":89,"provider":381,"advisoryCount":392,"licenseExpressions":393,"versions":395,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":397},"package:pypi:litellm","litellm-e00b5c8b","pypi:litellm","LiteLLM",12,[394],"MIT",[396],"1.73.6.post1",[54],{"id":399,"slug":400,"identity":401,"label":402,"aiRelevant":89,"provider":381,"advisoryCount":32,"licenseExpressions":403,"versions":404,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":406},"package:pypi:dspy","dspy-70e56922","pypi:dspy","DSPy",[394],[405],"2.6.27",[54],{"id":408,"slug":409,"identity":410,"label":411,"aiRelevant":89,"provider":412,"advisoryCount":37,"licenseExpressions":413,"versions":414,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":416},"package:pypi:datasets","datasets-e12c1359","pypi:datasets","Hugging Face Datasets",{"id":368,"label":369},[372],[415],"3.6.0",[54],{"id":70,"slug":71,"identity":418,"label":72,"aiRelevant":89,"provider":419,"advisoryCount":37,"licenseExpressions":422,"versions":423,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":425},"pypi:openai",{"id":420,"label":421},"openai","OpenAI",[372],[424],"1.93.0",[54],{"id":427,"slug":428,"identity":429,"label":430,"aiRelevant":89,"provider":431,"advisoryCount":37,"licenseExpressions":432,"versions":433,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":435},"package:pypi:sentence-transformers","sentence-transformers-3f3d7a36","pypi:sentence-transformers","Sentence Transformers",{"id":368,"label":369},[372],[434],"5.0.0",[54],{"id":437,"slug":438,"identity":439,"label":440,"aiRelevant":89,"provider":381,"advisoryCount":37,"licenseExpressions":441,"versions":443,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":445},"package:pypi:tokenizers","tokenizers-7ba00902","pypi:tokenizers","Hugging Face Tokenizers",[442],"non-standard",[444],"0.21.2",[54],{"id":447,"slug":448,"identity":449,"label":450,"aiRelevant":89,"provider":381,"advisoryCount":37,"licenseExpressions":451,"versions":452,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":454},"package:pypi:scikit-learn","scikit-learn-ab0941d9","pypi:scikit-learn","scikit-learn",[383,442],[453],"1.7.0",[54],{"id":456,"slug":457,"identity":458,"label":459,"aiRelevant":89,"provider":381,"advisoryCount":37,"licenseExpressions":460,"versions":461,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":463},"package:pypi:tiktoken","tiktoken-06b251a3","pypi:tiktoken","tiktoken",[442],[462],"0.9.0",[54],{"id":465,"slug":466,"identity":467,"label":468,"aiRelevant":45,"provider":381,"advisoryCount":469,"licenseExpressions":470,"versions":472,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":474},"package:pypi:aiohttp","aiohttp-5a806a63","pypi:aiohttp","aiohttp",33,[372,471],"Apache-2.0 AND MIT",[473],"3.12.13",[54],{"id":476,"slug":477,"identity":478,"label":479,"aiRelevant":45,"provider":381,"advisoryCount":102,"licenseExpressions":480,"versions":481,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":483},"package:pypi:mlflow","mlflow-43f98b3c","pypi:mlflow","mlflow",[442],[482],"3.1.1",[54],{"id":485,"slug":486,"identity":487,"label":488,"aiRelevant":45,"provider":381,"advisoryCount":489,"licenseExpressions":490,"versions":491,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":493},"package:pypi:gitpython","gitpython-dcd13009","pypi:gitpython","gitpython",22,[383],[492],"3.1.44",[54],{"id":495,"slug":496,"identity":497,"label":498,"aiRelevant":45,"provider":381,"advisoryCount":499,"licenseExpressions":500,"versions":503,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":505},"package:pypi:pillow","pillow-834347dd","pypi:pillow","pillow",20,[501,502],"HPND","MIT-CMU",[504],"11.3.0",[54],{"id":507,"slug":508,"identity":509,"label":510,"aiRelevant":45,"provider":381,"advisoryCount":511,"licenseExpressions":512,"versions":513,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":515},"package:pypi:nltk","nltk-ec2a0f85","pypi:nltk","nltk",16,[372],[514],"3.9.1",[54],{"id":517,"slug":518,"identity":519,"label":520,"aiRelevant":45,"provider":381,"advisoryCount":40,"licenseExpressions":521,"versions":522,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":524},"package:pypi:tornado","tornado-ab0f364e","pypi:tornado","tornado",[372],[523],"6.5.1",[54],{"id":526,"slug":527,"identity":528,"label":529,"aiRelevant":45,"provider":381,"advisoryCount":530,"licenseExpressions":531,"versions":532,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":534},"package:pypi:starlette","starlette-beb9e527","pypi:starlette","starlette",8,[383],[533],"0.46.2",[54],{"id":536,"slug":537,"identity":538,"label":539,"aiRelevant":45,"provider":381,"advisoryCount":540,"licenseExpressions":541,"versions":542,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":544},"package:pypi:urllib3","urllib3-fa68f32c","pypi:urllib3","urllib3",7,[394],[543],"2.5.0",[54],{"id":546,"slug":547,"identity":548,"label":549,"aiRelevant":45,"provider":381,"advisoryCount":64,"licenseExpressions":550,"versions":551,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":553},"package:pypi:pip","pip-2911c768","pypi:pip","pip",[394],[552],"25.1.1",[54],{"id":555,"slug":556,"identity":557,"label":558,"aiRelevant":45,"provider":381,"advisoryCount":64,"licenseExpressions":559,"versions":560,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":562},"package:pypi:werkzeug","werkzeug-b18d5b02","pypi:werkzeug","werkzeug",[383,442],[561],"3.1.3",[54],{"id":564,"slug":565,"identity":566,"label":567,"aiRelevant":45,"provider":381,"advisoryCount":568,"licenseExpressions":569,"versions":571,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":573},"package:pypi:pyasn1","pyasn1-348780fa","pypi:pyasn1","pyasn1",5,[570],"BSD-2-Clause",[572],"0.6.1",[54],{"id":575,"slug":576,"identity":577,"label":578,"aiRelevant":45,"provider":381,"advisoryCount":34,"licenseExpressions":579,"versions":580,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":582},"package:pypi:jinja2","jinja2-f7d34747","pypi:jinja2","jinja2",[383,442],[581],"3.1.6",[54],{"id":584,"slug":585,"identity":586,"label":587,"aiRelevant":45,"provider":381,"advisoryCount":34,"licenseExpressions":588,"versions":591,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":593},"package:pypi:ujson","ujson-337faf21","pypi:ujson","ujson",[383,589,590],"BSD-3-Clause AND TCL","TCL",[592],"5.10.0",[54],{"id":595,"slug":596,"identity":597,"label":598,"aiRelevant":45,"provider":381,"advisoryCount":599,"licenseExpressions":600,"versions":601,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":603},"package:pypi:requests","requests-53653f76","pypi:requests","requests",3,[372],[602],"2.32.4",[54],{"id":605,"slug":606,"identity":607,"label":608,"aiRelevant":45,"provider":381,"advisoryCount":599,"licenseExpressions":609,"versions":610,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":612},"package:pypi:setuptools","setuptools-fe37c31a","pypi:setuptools","setuptools",[394],[611],"80.9.0",[54],{"id":614,"slug":615,"identity":616,"label":617,"aiRelevant":45,"provider":381,"advisoryCount":618,"licenseExpressions":619,"versions":621,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":623},"package:pypi:filelock","filelock-b1c63968","pypi:filelock","filelock",2,[394,620],"Unlicense",[622],"3.18.0",[54],{"id":625,"slug":626,"identity":627,"label":628,"aiRelevant":45,"provider":381,"advisoryCount":618,"licenseExpressions":629,"versions":630,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":632},"package:pypi:mako","mako-ed406373","pypi:mako","mako",[394],[631],"1.3.10",[54],{"id":634,"slug":635,"identity":636,"label":637,"aiRelevant":45,"provider":381,"advisoryCount":618,"licenseExpressions":638,"versions":639,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":641},"package:pypi:protobuf","protobuf-6e30009a","pypi:protobuf","protobuf",[383],[640],"6.31.1",[54],{"id":643,"slug":644,"identity":645,"label":646,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":647,"versions":649,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":651},"package:pypi:certifi","certifi-d4f0c37e","pypi:certifi","certifi",[648],"MPL-2.0",[650],"2025.6.15",[54],{"id":653,"slug":654,"identity":655,"label":656,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":657,"versions":658,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":660},"package:pypi:click","click-ef97f731","pypi:click","click",[383,442],[659],"8.2.1",[54],{"id":662,"slug":663,"identity":664,"label":665,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":666,"versions":667,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":669},"package:pypi:diskcache","diskcache-a019f193","pypi:diskcache","diskcache",[372],[668],"5.6.3",[54],{"id":671,"slug":672,"identity":673,"label":674,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":675,"versions":676,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":677},"package:pypi:flask","flask-734a8b3c","pypi:flask","flask",[383,442],[482],[54],{"id":679,"slug":680,"identity":681,"label":682,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":683,"versions":684,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":686},"package:pypi:fonttools","fonttools-d2488ea8","pypi:fonttools","fonttools",[394],[685],"4.58.5",[54],{"id":688,"slug":689,"identity":690,"label":691,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":692,"versions":693,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":695},"package:pypi:h11","h11-48165ab1","pypi:h11","h11",[394],[694],"0.16.0",[54],{"id":697,"slug":698,"identity":699,"label":700,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":701,"versions":702,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":704},"package:pypi:idna","idna-994c9929","pypi:idna","idna",[383,442],[703],"3.10",[54],{"id":706,"slug":707,"identity":708,"label":709,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":710,"versions":711,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":713},"package:pypi:json-repair","json-repair-3bbcd372","pypi:json-repair","json-repair",[442],[712],"0.47.6",[54],{"id":715,"slug":716,"identity":717,"label":718,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":719,"versions":720,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":722},"package:pypi:jupyter-core","jupyter-core-44178c79","pypi:jupyter-core","jupyter-core",[383,442],[721],"5.8.1",[54],{"id":724,"slug":725,"identity":726,"label":727,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":728,"versions":729,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":731},"package:pypi:pyarrow","pyarrow-facb8516","pypi:pyarrow","pyarrow",[372,442],[730],"20.0.0",[54],{"id":733,"slug":734,"identity":735,"label":736,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":737,"versions":738,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":740},"package:pypi:pygments","pygments-ad71bc11","pypi:pygments","pygments",[570],[739],"2.19.2",[54],{"id":742,"slug":743,"identity":744,"label":745,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":746,"versions":747,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":749},"package:pypi:python-dotenv","python-dotenv-27b12285","pypi:python-dotenv","python-dotenv",[383],[748],"1.1.1",[54],{"id":751,"slug":752,"identity":753,"label":754,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":755,"versions":756,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":758},"package:pypi:sqlparse","sqlparse-96380dda","pypi:sqlparse","sqlparse",[442],[757],"0.5.3",[54],{"id":760,"slug":761,"identity":762,"label":763,"aiRelevant":45,"provider":381,"advisoryCount":32,"licenseExpressions":764,"versions":766,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":768},"package:pypi:tqdm","tqdm-04b01f90","pypi:tqdm","tqdm",[765],"MIT AND MPL-2.0",[767],"4.67.1",[54],{"id":770,"slug":771,"identity":772,"label":773,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":774,"versions":775,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":777},"package:pypi:absl-py","absl-py-50126725","pypi:absl-py","absl-py",[372],[776],"2.3.1",[54],{"id":779,"slug":780,"identity":781,"label":782,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":783,"versions":785,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":787},"package:pypi:aiohappyeyeballs","aiohappyeyeballs-ea4657b8","pypi:aiohappyeyeballs","aiohappyeyeballs",[784],"PSF-2.0",[786],"2.6.1",[54],{"id":789,"slug":790,"identity":791,"label":792,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":793,"versions":794,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":796},"package:pypi:aiosignal","aiosignal-b6794e75","pypi:aiosignal","aiosignal",[372],[795],"1.4.0",[54],{"id":798,"slug":799,"identity":800,"label":801,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":802,"versions":803,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":805},"package:pypi:alembic","alembic-662caf9d","pypi:alembic","alembic",[394],[804],"1.16.2",[54],{"id":807,"slug":808,"identity":809,"label":810,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":811,"versions":812,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":814},"package:pypi:annotated-types","annotated-types-2304c38b","pypi:annotated-types","annotated-types",[394],[813],"0.7.0",[54],{"id":816,"slug":817,"identity":818,"label":819,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":820,"versions":821,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":823},"package:pypi:antlr4-python3-runtime","antlr4-python3-runtime-52028339","pypi:antlr4-python3-runtime","antlr4-python3-runtime",[442],[822],"4.9.3",[54],{"id":825,"slug":826,"identity":827,"label":828,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":829,"versions":830,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":832},"package:pypi:anyio","anyio-399e5280","pypi:anyio","anyio",[394],[831],"4.9.0",[54],{"id":834,"slug":835,"identity":836,"label":837,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":838,"versions":839,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":841},"package:pypi:appnope","appnope-1881f8cd","pypi:appnope","appnope",[442],[840],"0.1.4",[54],{"id":843,"slug":844,"identity":845,"label":846,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":847,"versions":848,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":850},"package:pypi:argilla","argilla-35b6bbbe","pypi:argilla","argilla",[372],[849],"2.8.0",[54],{"id":852,"slug":853,"identity":854,"label":855,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":856,"versions":857,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":859},"package:pypi:asttokens","asttokens-c349c5f9","pypi:asttokens","asttokens",[372],[858],"3.0.0",[54],{"id":861,"slug":862,"identity":863,"label":864,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":865,"versions":866,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":868},"package:pypi:async-timeout","async-timeout-218334ed","pypi:async-timeout","async-timeout",[372],[867],"5.0.1",[54],{"id":870,"slug":871,"identity":872,"label":873,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":874,"versions":875,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":877},"package:pypi:asyncer","asyncer-86b9c8c0","pypi:asyncer","asyncer",[394],[876],"0.0.8",[54],{"id":879,"slug":880,"identity":881,"label":882,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":883,"versions":884,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":886},"package:pypi:attrs","attrs-2e7954ac","pypi:attrs","attrs",[394],[885],"25.3.0",[54],{"id":888,"slug":889,"identity":890,"label":891,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":892,"versions":893,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":895},"package:pypi:backoff","backoff-594e7418","pypi:backoff","backoff",[394],[894],"2.2.1",[54],{"id":897,"slug":898,"identity":899,"label":900,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":901,"versions":902,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":904},"package:pypi:blinker","blinker-409e1445","pypi:blinker","blinker",[394],[903],"1.9.0",[54],{"id":906,"slug":907,"identity":908,"label":909,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":910,"versions":911,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":913},"package:pypi:cachetools","cachetools-84fe6563","pypi:cachetools","cachetools",[394],[912],"5.5.2",[54],{"id":915,"slug":916,"identity":917,"label":918,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":919,"versions":921,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":923},"package:pypi:cffi","cffi-38e65d3e","pypi:cffi","cffi",[394,920],"MIT-0",[922],"1.17.1",[54],{"id":925,"slug":926,"identity":927,"label":928,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":929,"versions":930,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":932},"package:pypi:charset-normalizer","charset-normalizer-74ccb20a","pypi:charset-normalizer","charset-normalizer",[394],[931],"3.4.2",[54],{"id":934,"slug":935,"identity":936,"label":937,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":938,"versions":939,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":940},"package:pypi:cloudpickle","cloudpickle-12e9c0d7","pypi:cloudpickle","cloudpickle",[383],[482],[54],{"id":942,"slug":943,"identity":944,"label":945,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":946,"versions":947,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":949},"package:pypi:colorama","colorama-abaf57c3","pypi:colorama","colorama",[442],[948],"0.4.6",[54],{"id":951,"slug":952,"identity":953,"label":954,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":955,"versions":956,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":958},"package:pypi:colorlog","colorlog-a388001c","pypi:colorlog","colorlog",[394],[957],"6.9.0",[54],{"id":960,"slug":961,"identity":962,"label":963,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":964,"versions":965,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":967},"package:pypi:comm","comm-0720ed7b","pypi:comm","comm",[442],[966],"0.2.2",[54],{"id":969,"slug":970,"identity":971,"label":972,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":973,"versions":974,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":976},"package:pypi:contourpy","contourpy-f86f9e10","pypi:contourpy","contourpy",[442],[975],"1.3.2",[54],{"id":978,"slug":979,"identity":980,"label":981,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":982,"versions":983,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":985},"package:pypi:cycler","cycler-3e14883d","pypi:cycler","cycler",[442],[984],"0.12.1",[54],{"id":987,"slug":988,"identity":989,"label":990,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":991,"versions":992,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":994},"package:pypi:databricks-sdk","databricks-sdk-26867d3a","pypi:databricks-sdk","databricks-sdk",[442],[993],"0.57.0",[54],{"id":996,"slug":997,"identity":998,"label":999,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1000,"versions":1001,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1003},"package:pypi:debugpy","debugpy-71725cbb","pypi:debugpy","debugpy",[394],[1002],"1.8.14",[54],{"id":1005,"slug":1006,"identity":1007,"label":1008,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1009,"versions":1010,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1012},"package:pypi:decorator","decorator-500c1fb8","pypi:decorator","decorator",[570,442],[1011],"5.2.1",[54],{"id":1014,"slug":1015,"identity":1016,"label":1017,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1018,"versions":1019,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1021},"package:pypi:deprecated","deprecated-e7bb8a9a","pypi:deprecated","deprecated",[394],[1020],"1.2.18",[54],{"id":1023,"slug":1024,"identity":1025,"label":1026,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1027,"versions":1028,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1030},"package:pypi:dill","dill-e2d26698","pypi:dill","dill",[383],[1029],"0.3.8",[54],{"id":1032,"slug":1033,"identity":1034,"label":1035,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1036,"versions":1037,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1038},"package:pypi:distro","distro-36b318e9","pypi:distro","distro",[372],[903],[54],{"id":1040,"slug":1041,"identity":1042,"label":1043,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1044,"versions":1045,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1047},"package:pypi:docker","docker-fa61cb72","pypi:docker","docker",[372],[1046],"7.1.0",[54],{"id":1049,"slug":1050,"identity":1051,"label":1052,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1053,"versions":1054,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1056},"package:pypi:evaluate","evaluate-18162fdd","pypi:evaluate","evaluate",[372],[1055],"0.4.4",[54],{"id":1058,"slug":1059,"identity":1060,"label":1061,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1062,"versions":1063,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1065},"package:pypi:exceptiongroup","exceptiongroup-316db5d9","pypi:exceptiongroup","exceptiongroup",[394],[1064],"1.3.0",[54],{"id":1067,"slug":1068,"identity":1069,"label":1070,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1071,"versions":1072,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1074},"package:pypi:executing","executing-36845a5b","pypi:executing","executing",[394],[1073],"2.2.0",[54],{"id":1076,"slug":1077,"identity":1078,"label":1079,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1080,"versions":1081,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1083},"package:pypi:fastapi","fastapi-e52fd482","pypi:fastapi","fastapi",[394],[1082],"0.115.14",[54],{"id":1085,"slug":1086,"identity":1087,"label":1088,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1089,"versions":1090,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1091},"package:pypi:frozenlist","frozenlist-110237da","pypi:frozenlist","frozenlist",[372],[453],[54],{"id":1093,"slug":1094,"identity":1095,"label":1096,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1097,"versions":1098,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1100},"package:pypi:fsspec","fsspec-b1a7c311","pypi:fsspec","fsspec",[383,442],[1099],"2025.3.0",[54],{"id":1102,"slug":1103,"identity":1104,"label":1105,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1106,"versions":1107,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1109},"package:pypi:gitdb","gitdb-dac4580b","pypi:gitdb","gitdb",[442],[1108],"4.0.12",[54],{"id":1111,"slug":1112,"identity":1113,"label":1114,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1115,"versions":1116,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1118},"package:pypi:google-auth","google-auth-42cfc01f","pypi:google-auth","google-auth",[372],[1117],"2.40.3",[54],{"id":1120,"slug":1121,"identity":1122,"label":1123,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1124,"versions":1125,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1127},"package:pypi:graphene","graphene-e89251f5","pypi:graphene","graphene",[394],[1126],"3.4.3",[54],{"id":1129,"slug":1130,"identity":1131,"label":1132,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1133,"versions":1134,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1136},"package:pypi:graphql-core","graphql-core-6d217145","pypi:graphql-core","graphql-core",[394],[1135],"3.2.6",[54],{"id":1138,"slug":1139,"identity":1140,"label":1141,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1142,"versions":1143,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1145},"package:pypi:graphql-relay","graphql-relay-f4584f38","pypi:graphql-relay","graphql-relay",[394],[1144],"3.2.0",[54],{"id":1147,"slug":1148,"identity":1149,"label":1150,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1151,"versions":1154,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1156},"package:pypi:greenlet","greenlet-cd6f7934","pypi:greenlet","greenlet",[394,1152,1153],"MIT AND PSF-2.0","MIT AND Python-2.0",[1155],"3.2.3",[54],{"id":1158,"slug":1159,"identity":1160,"label":1161,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1162,"versions":1163,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1165},"package:pypi:gunicorn","gunicorn-a765d3c5","pypi:gunicorn","gunicorn",[394],[1164],"23.0.0",[54],{"id":1167,"slug":1168,"identity":1169,"label":1170,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1171,"versions":1172,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1174},"package:pypi:hf-xet","hf-xet-732ec6c8","pypi:hf-xet","hf-xet",[372],[1173],"1.1.5",[54],{"id":1176,"slug":1177,"identity":1178,"label":1179,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1180,"versions":1181,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1183},"package:pypi:httpcore","httpcore-ba6ae671","pypi:httpcore","httpcore",[383],[1182],"1.0.9",[54],{"id":1185,"slug":1186,"identity":1187,"label":1188,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1189,"versions":1190,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1192},"package:pypi:httpx","httpx-a512a166","pypi:httpx","httpx",[383],[1191],"0.28.1",[54],{"id":1194,"slug":1195,"identity":1196,"label":1197,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1198,"versions":1199,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1201},"package:pypi:huggingface-hub","huggingface-hub-443ec6ef","pypi:huggingface-hub","huggingface-hub",[372,442],[1200],"0.33.2",[54],{"id":1203,"slug":1204,"identity":1205,"label":1206,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1207,"versions":1208,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1209},"package:pypi:hydra-core","hydra-core-88ed8b5b","pypi:hydra-core","hydra-core",[394],[975],[54],{"id":1211,"slug":1212,"identity":1213,"label":1214,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1215,"versions":1216,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1218},"package:pypi:importlib-metadata","importlib-metadata-a3dfda3c","pypi:importlib-metadata","importlib-metadata",[372,442],[1217],"8.7.0",[54],{"id":1220,"slug":1221,"identity":1222,"label":1223,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1224,"versions":1225,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1227},"package:pypi:ipykernel","ipykernel-37162218","pypi:ipykernel","ipykernel",[383,442],[1226],"6.29.5",[54],{"id":1229,"slug":1230,"identity":1231,"label":1232,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1233,"versions":1234,"dossier":45,"occurrenceCount":618,"directOccurrenceCount":37,"evidenceFiles":1237},"package:pypi:ipython","ipython-7a140323","pypi:ipython","ipython",[383],[1235,1236],"8.37.0","9.3.0",[54],{"id":1239,"slug":1240,"identity":1241,"label":1242,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1243,"versions":1244,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1245},"package:pypi:ipython-pygments-lexers","ipython-pygments-lexers-6216051e","pypi:ipython-pygments-lexers","ipython-pygments-lexers",[442],[748],[54],{"id":1247,"slug":1248,"identity":1249,"label":1250,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1251,"versions":1252,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1253},"package:pypi:itsdangerous","itsdangerous-4af70837","pypi:itsdangerous","itsdangerous",[383,442],[1073],[54],{"id":1255,"slug":1256,"identity":1257,"label":1258,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1259,"versions":1260,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1262},"package:pypi:jedi","jedi-9eb0c211","pypi:jedi","jedi",[394],[1261],"0.19.2",[54],{"id":1264,"slug":1265,"identity":1266,"label":1267,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1268,"versions":1269,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1271},"package:pypi:jiter","jiter-d62b34e9","pypi:jiter","jiter",[394],[1270],"0.10.0",[54],{"id":1273,"slug":1274,"identity":1275,"label":1276,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1277,"versions":1278,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1280},"package:pypi:joblib","joblib-8cbb7872","pypi:joblib","joblib",[383],[1279],"1.5.1",[54],{"id":1282,"slug":1283,"identity":1284,"label":1285,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1286,"versions":1287,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1289},"package:pypi:jsonschema","jsonschema-df23f5cd","pypi:jsonschema","jsonschema",[394],[1288],"4.24.0",[54],{"id":1291,"slug":1292,"identity":1293,"label":1294,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1295,"versions":1296,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1298},"package:pypi:jsonschema-specifications","jsonschema-specifications-5d87863a","pypi:jsonschema-specifications","jsonschema-specifications",[394],[1297],"2025.4.1",[54],{"id":1300,"slug":1301,"identity":1302,"label":1303,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1304,"versions":1305,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1307},"package:pypi:jupyter-client","jupyter-client-3b4db88c","pypi:jupyter-client","jupyter-client",[442],[1306],"8.6.3",[54],{"id":1309,"slug":1310,"identity":1311,"label":1312,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1313,"versions":1314,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1316},"package:pypi:kiwisolver","kiwisolver-41b47c33","pypi:kiwisolver","kiwisolver",[442],[1315],"1.4.8",[54],{"id":1318,"slug":1319,"identity":1320,"label":1321,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1322,"versions":1323,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1325},"package:pypi:magicattr","magicattr-40bff089","pypi:magicattr","magicattr",[394],[1324],"0.1.6",[54],{"id":1327,"slug":1328,"identity":1329,"label":1330,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1331,"versions":1332,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1333},"package:pypi:markdown-it-py","markdown-it-py-27073f5e","pypi:markdown-it-py","markdown-it-py",[394],[858],[54],{"id":1335,"slug":1336,"identity":1337,"label":1338,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1339,"versions":1340,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1342},"package:pypi:markupsafe","markupsafe-1bdd4c7f","pypi:markupsafe","markupsafe",[383,442],[1341],"3.0.2",[54],{"id":1344,"slug":1345,"identity":1346,"label":1347,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1348,"versions":1349,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1351},"package:pypi:matplotlib","matplotlib-9dc72309","pypi:matplotlib","matplotlib",[442],[1350],"3.10.3",[54],{"id":1353,"slug":1354,"identity":1355,"label":1356,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1357,"versions":1358,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1360},"package:pypi:matplotlib-inline","matplotlib-inline-50f95e0d","pypi:matplotlib-inline","matplotlib-inline",[383,442],[1359],"0.1.7",[54],{"id":1362,"slug":1363,"identity":1364,"label":1365,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1366,"versions":1367,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1369},"package:pypi:mdurl","mdurl-e6f5f075","pypi:mdurl","mdurl",[394],[1368],"0.1.2",[54],{"id":1371,"slug":1372,"identity":1373,"label":1374,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1375,"versions":1376,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1377},"package:pypi:mlflow-skinny","mlflow-skinny-05e8b169","pypi:mlflow-skinny","mlflow-skinny",[442],[482],[54],{"id":1379,"slug":1380,"identity":1381,"label":1382,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1383,"versions":1384,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1385},"package:pypi:mpmath","mpmath-4ccb7a41","pypi:mpmath","mpmath",[442],[1064],[54],{"id":1387,"slug":1388,"identity":1389,"label":1390,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1391,"versions":1392,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1394},"package:pypi:multidict","multidict-b407a4ac","pypi:multidict","multidict",[372],[1393],"6.6.3",[54],{"id":1396,"slug":1397,"identity":1398,"label":1399,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1400,"versions":1401,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1403},"package:pypi:multiprocess","multiprocess-9b2083dd","pypi:multiprocess","multiprocess",[383],[1402],"0.70.16",[54],{"id":1405,"slug":1406,"identity":1407,"label":1408,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1409,"versions":1410,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1412},"package:pypi:nest-asyncio","nest-asyncio-f76531b1","pypi:nest-asyncio","nest-asyncio",[442],[1411],"1.6.0",[54],{"id":1414,"slug":1415,"identity":1416,"label":1417,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1418,"versions":1419,"dossier":45,"occurrenceCount":618,"directOccurrenceCount":37,"evidenceFiles":1421},"package:pypi:networkx","networkx-c2336a8d","pypi:networkx","networkx",[383,442],[931,1420],"3.5",[54],{"id":1423,"slug":1424,"identity":1425,"label":1426,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1427,"versions":1429,"dossier":45,"occurrenceCount":618,"directOccurrenceCount":37,"evidenceFiles":1431},"package:pypi:numpy","numpy-ba79b98d","pypi:numpy","numpy",[1428,442],"0BSD AND BSD-3-Clause AND CC0-1.0 AND MIT AND Zlib",[1430,776],"2.2.6",[54],{"id":1433,"slug":1434,"identity":1435,"label":1436,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1437,"versions":1438,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1440},"package:pypi:nvidia-cublas-cu12","nvidia-cublas-cu12-1d052261","pypi:nvidia-cublas-cu12","nvidia-cublas-cu12",[442],[1439],"12.6.4.1",[54],{"id":1442,"slug":1443,"identity":1444,"label":1445,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1446,"versions":1447,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1449},"package:pypi:nvidia-cuda-cupti-cu12","nvidia-cuda-cupti-cu12-973480f1","pypi:nvidia-cuda-cupti-cu12","nvidia-cuda-cupti-cu12",[442],[1448],"12.6.80",[54],{"id":1451,"slug":1452,"identity":1453,"label":1454,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1455,"versions":1456,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1458},"package:pypi:nvidia-cuda-nvrtc-cu12","nvidia-cuda-nvrtc-cu12-e32b7f38","pypi:nvidia-cuda-nvrtc-cu12","nvidia-cuda-nvrtc-cu12",[442],[1457],"12.6.77",[54],{"id":1460,"slug":1461,"identity":1462,"label":1463,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1464,"versions":1465,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1466},"package:pypi:nvidia-cuda-runtime-cu12","nvidia-cuda-runtime-cu12-2b875d2a","pypi:nvidia-cuda-runtime-cu12","nvidia-cuda-runtime-cu12",[442],[1457],[54],{"id":1468,"slug":1469,"identity":1470,"label":1471,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1472,"versions":1473,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1475},"package:pypi:nvidia-cudnn-cu12","nvidia-cudnn-cu12-a21dce6d","pypi:nvidia-cudnn-cu12","nvidia-cudnn-cu12",[442],[1474],"9.5.1.17",[54],{"id":1477,"slug":1478,"identity":1479,"label":1480,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1481,"versions":1482,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1484},"package:pypi:nvidia-cufft-cu12","nvidia-cufft-cu12-21ff54dd","pypi:nvidia-cufft-cu12","nvidia-cufft-cu12",[442],[1483],"11.3.0.4",[54],{"id":1486,"slug":1487,"identity":1488,"label":1489,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1490,"versions":1491,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1493},"package:pypi:nvidia-cufile-cu12","nvidia-cufile-cu12-14048140","pypi:nvidia-cufile-cu12","nvidia-cufile-cu12",[442],[1492],"1.11.1.6",[54],{"id":1495,"slug":1496,"identity":1497,"label":1498,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1499,"versions":1500,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1502},"package:pypi:nvidia-curand-cu12","nvidia-curand-cu12-2fed778b","pypi:nvidia-curand-cu12","nvidia-curand-cu12",[442],[1501],"10.3.7.77",[54],{"id":1504,"slug":1505,"identity":1506,"label":1507,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1508,"versions":1509,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1511},"package:pypi:nvidia-cusolver-cu12","nvidia-cusolver-cu12-7db0a33a","pypi:nvidia-cusolver-cu12","nvidia-cusolver-cu12",[442],[1510],"11.7.1.2",[54],{"id":1513,"slug":1514,"identity":1515,"label":1516,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1517,"versions":1518,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1520},"package:pypi:nvidia-cusparse-cu12","nvidia-cusparse-cu12-d7e6a309","pypi:nvidia-cusparse-cu12","nvidia-cusparse-cu12",[442],[1519],"12.5.4.2",[54],{"id":1522,"slug":1523,"identity":1524,"label":1525,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1526,"versions":1527,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1529},"package:pypi:nvidia-cusparselt-cu12","nvidia-cusparselt-cu12-97587f50","pypi:nvidia-cusparselt-cu12","nvidia-cusparselt-cu12",[442],[1528],"0.6.3",[54],{"id":1531,"slug":1532,"identity":1533,"label":1534,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1535,"versions":1536,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1538},"package:pypi:nvidia-nccl-cu12","nvidia-nccl-cu12-90361558","pypi:nvidia-nccl-cu12","nvidia-nccl-cu12",[383,442],[1537],"2.26.2",[54],{"id":1540,"slug":1541,"identity":1542,"label":1543,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1544,"versions":1545,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1547},"package:pypi:nvidia-nvjitlink-cu12","nvidia-nvjitlink-cu12-6d08af75","pypi:nvidia-nvjitlink-cu12","nvidia-nvjitlink-cu12",[442],[1546],"12.6.85",[54],{"id":1549,"slug":1550,"identity":1551,"label":1552,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1553,"versions":1554,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1555},"package:pypi:nvidia-nvtx-cu12","nvidia-nvtx-cu12-9a2d0378","pypi:nvidia-nvtx-cu12","nvidia-nvtx-cu12",[372,442],[1457],[54],{"id":1557,"slug":1558,"identity":1559,"label":1560,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1561,"versions":1562,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1564},"package:pypi:omegaconf","omegaconf-7670402e","pypi:omegaconf","omegaconf",[383],[1563],"2.3.0",[54],{"id":1566,"slug":1567,"identity":1568,"label":1569,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1570,"versions":1571,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1573},"package:pypi:opentelemetry-api","opentelemetry-api-341bc8f7","pypi:opentelemetry-api","opentelemetry-api",[372],[1572],"1.34.1",[54],{"id":1575,"slug":1576,"identity":1577,"label":1578,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1579,"versions":1580,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1581},"package:pypi:opentelemetry-sdk","opentelemetry-sdk-38b86085","pypi:opentelemetry-sdk","opentelemetry-sdk",[372],[1572],[54],{"id":1583,"slug":1584,"identity":1585,"label":1586,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1587,"versions":1588,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1590},"package:pypi:opentelemetry-semantic-conventions","opentelemetry-semantic-conventions-15f3be17","pypi:opentelemetry-semantic-conventions","opentelemetry-semantic-conventions",[372],[1589],"0.55b1",[54],{"id":1592,"slug":1593,"identity":1594,"label":1595,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1596,"versions":1597,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1599},"package:pypi:optuna","optuna-5cb30128","pypi:optuna","optuna",[383,394],[1598],"4.4.0",[54],{"id":1601,"slug":1602,"identity":1603,"label":1604,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1605,"versions":1607,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1609},"package:pypi:packaging","packaging-78ee1f47","pypi:packaging","packaging",[1606,442],"Apache-2.0 OR BSD-2-Clause",[1608],"25.0",[54],{"id":1611,"slug":1612,"identity":1613,"label":1614,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1615,"versions":1616,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1617},"package:pypi:pandas","pandas-e8d52445","pypi:pandas","pandas",[442],[1563],[54],{"id":1619,"slug":1620,"identity":1621,"label":1622,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1623,"versions":1624,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1626},"package:pypi:parso","parso-fa59fdde","pypi:parso","parso",[394],[1625],"0.8.4",[54],{"id":1628,"slug":1629,"identity":1630,"label":1631,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1632,"versions":1633,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1634},"package:pypi:pexpect","pexpect-9ad65a0c","pypi:pexpect","pexpect",[442],[831],[54],{"id":1636,"slug":1637,"identity":1638,"label":1639,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1640,"versions":1641,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1643},"package:pypi:platformdirs","platformdirs-e64002f0","pypi:platformdirs","platformdirs",[394],[1642],"4.3.8",[54],{"id":1645,"slug":1646,"identity":1647,"label":1648,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1649,"versions":1650,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1652},"package:pypi:prompt-toolkit","prompt-toolkit-e6f4118a","pypi:prompt-toolkit","prompt-toolkit",[383,442],[1651],"3.0.51",[54],{"id":1654,"slug":1655,"identity":1656,"label":1657,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1658,"versions":1659,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1661},"package:pypi:propcache","propcache-1fcd6be4","pypi:propcache","propcache",[372],[1660],"0.3.2",[54],{"id":1663,"slug":1664,"identity":1665,"label":1666,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1667,"versions":1668,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1670},"package:pypi:psutil","psutil-840b9a74","pypi:psutil","psutil",[383],[1669],"7.0.0",[54],{"id":1672,"slug":1673,"identity":1674,"label":1675,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1676,"versions":1677,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1679},"package:pypi:psycopg2","psycopg2-65dfcce0","pypi:psycopg2","psycopg2",[442],[1678],"2.9.10",[54],{"id":1681,"slug":1682,"identity":1683,"label":1684,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1685,"versions":1687,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1688},"package:pypi:ptyprocess","ptyprocess-ec2650c7","pypi:ptyprocess","ptyprocess",[1686],"ISC",[813],[54],{"id":1690,"slug":1691,"identity":1692,"label":1693,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1694,"versions":1695,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1697},"package:pypi:pure-eval","pure-eval-24d2bc1c","pypi:pure-eval","pure-eval",[394],[1696],"0.2.3",[54],{"id":1699,"slug":1700,"identity":1701,"label":1702,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1703,"versions":1704,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1706},"package:pypi:pyasn1-modules","pyasn1-modules-6a7471e8","pypi:pyasn1-modules","pyasn1-modules",[442],[1705],"0.4.2",[54],{"id":1708,"slug":1709,"identity":1710,"label":1711,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1712,"versions":1713,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1715},"package:pypi:pycparser","pycparser-102d9d3e","pypi:pycparser","pycparser",[383],[1714],"2.22",[54],{"id":1717,"slug":1718,"identity":1719,"label":1720,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1721,"versions":1722,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1724},"package:pypi:pydantic","pydantic-4ac148ca","pypi:pydantic","pydantic",[394],[1723],"2.11.7",[54],{"id":1726,"slug":1727,"identity":1728,"label":1729,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1730,"versions":1731,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1733},"package:pypi:pydantic-core","pydantic-core-f9814ebc","pypi:pydantic-core","pydantic-core",[394],[1732],"2.33.2",[54],{"id":1735,"slug":1736,"identity":1737,"label":1738,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1739,"versions":1740,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1741},"package:pypi:pyparsing","pyparsing-a28b9b62","pypi:pyparsing","pyparsing",[394],[1155],[54],{"id":1743,"slug":1744,"identity":1745,"label":1746,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1747,"versions":1748,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1750},"package:pypi:python-dateutil","python-dateutil-8eac96b7","pypi:python-dateutil","python-dateutil",[442],[1749],"2.9.0.post0",[54],{"id":1752,"slug":1753,"identity":1754,"label":1755,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1756,"versions":1757,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1759},"package:pypi:pytz","pytz-cbf1d95c","pypi:pytz","pytz",[394],[1758],"2025.2",[54],{"id":1761,"slug":1762,"identity":1763,"label":1764,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1765,"versions":1766,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1768},"package:pypi:pywin32","pywin32-9a7c83ae","pypi:pywin32","pywin32",[],[1767],"310",[54],{"id":1770,"slug":1771,"identity":1772,"label":1773,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1774,"versions":1775,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1777},"package:pypi:pyyaml","pyyaml-16000901","pypi:pyyaml","pyyaml",[394],[1776],"6.0.2",[54],{"id":1779,"slug":1780,"identity":1781,"label":1782,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1783,"versions":1784,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1786},"package:pypi:pyzmq","pyzmq-30b92392","pypi:pyzmq","pyzmq",[442],[1785],"27.0.0",[54],{"id":1788,"slug":1789,"identity":1790,"label":1791,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1792,"versions":1793,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1795},"package:pypi:redis","redis-94bd1499","pypi:redis","redis",[394],[1794],"6.2.0",[54],{"id":1797,"slug":1798,"identity":1799,"label":1800,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1801,"versions":1802,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1804},"package:pypi:referencing","referencing-b8d98ce1","pypi:referencing","referencing",[394],[1803],"0.36.2",[54],{"id":1806,"slug":1807,"identity":1808,"label":1809,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1810,"versions":1812,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1814},"package:pypi:regex","regex-5e8be65e","pypi:regex","regex",[1811,442],"Apache-2.0 AND CNRI-Python",[1813],"2024.11.6",[54],{"id":1816,"slug":1817,"identity":1818,"label":1819,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1820,"versions":1821,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1823},"package:pypi:rich","rich-23b343f7","pypi:rich","rich",[394],[1822],"14.0.0",[54],{"id":1825,"slug":1826,"identity":1827,"label":1828,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1829,"versions":1830,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1831},"package:pypi:rouge-score","rouge-score-2585384e","pypi:rouge-score","rouge-score",[442],[1368],[54],{"id":1833,"slug":1834,"identity":1835,"label":1836,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1837,"versions":1838,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1840},"package:pypi:rpds-py","rpds-py-67c64be8","pypi:rpds-py","rpds-py",[394],[1839],"0.26.0",[54],{"id":1842,"slug":1843,"identity":1844,"label":1845,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1846,"versions":1847,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1849},"package:pypi:rsa","rsa-1037e3e0","pypi:rsa","rsa",[372],[1848],"4.9.1",[54],{"id":1851,"slug":1852,"identity":1853,"label":1854,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1855,"versions":1856,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1857},"package:pypi:safetensors","safetensors-2a32c77a","pypi:safetensors","safetensors",[442],[757],[54],{"id":1859,"slug":1860,"identity":1861,"label":1862,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1863,"versions":1864,"dossier":45,"occurrenceCount":618,"directOccurrenceCount":37,"evidenceFiles":1867},"package:pypi:scipy","scipy-215f884d","pypi:scipy","scipy",[442],[1865,1866],"1.15.3","1.16.0",[54],{"id":1869,"slug":1870,"identity":1871,"label":1872,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1873,"versions":1874,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1876},"package:pypi:six","six-3c3888bd","pypi:six","six",[394],[1875],"1.17.0",[54],{"id":1878,"slug":1879,"identity":1880,"label":1881,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1882,"versions":1883,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1885},"package:pypi:smmap","smmap-943fc5aa","pypi:smmap","smmap",[383],[1884],"5.0.2",[54],{"id":1887,"slug":1888,"identity":1889,"label":1890,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1891,"versions":1893,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1895},"package:pypi:sniffio","sniffio-83f32c9d","pypi:sniffio","sniffio",[1892],"Apache-2.0 OR MIT",[1894],"1.3.1",[54],{"id":1897,"slug":1898,"identity":1899,"label":1900,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1901,"versions":1902,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1904},"package:pypi:sqlalchemy","sqlalchemy-5de7c53b","pypi:sqlalchemy","sqlalchemy",[394],[1903],"2.0.41",[54],{"id":1906,"slug":1907,"identity":1908,"label":1909,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1910,"versions":1911,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1912},"package:pypi:stack-data","stack-data-d640fe0e","pypi:stack-data","stack-data",[394],[1528],[54],{"id":1914,"slug":1915,"identity":1916,"label":1917,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1918,"versions":1919,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1921},"package:pypi:standardwebhooks","standardwebhooks-9da13670","pypi:standardwebhooks","standardwebhooks",[394],[1920],"1.0.0",[54],{"id":1923,"slug":1924,"identity":1925,"label":1926,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1927,"versions":1928,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1930},"package:pypi:sympy","sympy-b30cb89e","pypi:sympy","sympy",[442],[1929],"1.14.0",[54],{"id":1932,"slug":1933,"identity":1934,"label":1935,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1936,"versions":1937,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1939},"package:pypi:tenacity","tenacity-415454f8","pypi:tenacity","tenacity",[372],[1938],"9.1.2",[54],{"id":1941,"slug":1942,"identity":1943,"label":1944,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1945,"versions":1946,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1947},"package:pypi:threadpoolctl","threadpoolctl-e94f6300","pypi:threadpoolctl","threadpoolctl",[383],[415],[54],{"id":1949,"slug":1950,"identity":1951,"label":1952,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1953,"versions":1954,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1955},"package:pypi:tomli","tomli-e09082bd","pypi:tomli","tomli",[394],[894],[54],{"id":1957,"slug":1958,"identity":1959,"label":1960,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1961,"versions":1962,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1964},"package:pypi:traitlets","traitlets-52bd6ddb","pypi:traitlets","traitlets",[442],[1963],"5.14.3",[54],{"id":1966,"slug":1967,"identity":1968,"label":1969,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1970,"versions":1971,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1973},"package:pypi:triton","triton-601ea838","pypi:triton","triton",[394],[1972],"3.3.1",[54],{"id":1975,"slug":1976,"identity":1977,"label":1978,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1979,"versions":1980,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1982},"package:pypi:types-deprecated","types-deprecated-ad3f077c","pypi:types-deprecated","types-deprecated",[372],[1981],"1.2.15.20250304",[54],{"id":1984,"slug":1985,"identity":1986,"label":1987,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1988,"versions":1989,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":1991},"package:pypi:types-python-dateutil","types-python-dateutil-7c72d321","pypi:types-python-dateutil","types-python-dateutil",[372],[1990],"2.9.0.20250516",[54],{"id":1993,"slug":1994,"identity":1995,"label":1996,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":1997,"versions":1998,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2000},"package:pypi:typing-extensions","typing-extensions-87d153eb","pypi:typing-extensions","typing-extensions",[784,442],[1999],"4.14.0",[54],{"id":2002,"slug":2003,"identity":2004,"label":2005,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2006,"versions":2007,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2009},"package:pypi:typing-inspection","typing-inspection-0abeb500","pypi:typing-inspection","typing-inspection",[394],[2008],"0.4.1",[54],{"id":2011,"slug":2012,"identity":2013,"label":2014,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2015,"versions":2016,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2017},"package:pypi:tzdata","tzdata-f80b3bb7","pypi:tzdata","tzdata",[372],[1758],[54],{"id":2019,"slug":2020,"identity":2021,"label":2022,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2023,"versions":2024,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2026},"package:pypi:uvicorn","uvicorn-07c7a595","pypi:uvicorn","uvicorn",[383],[2025],"0.35.0",[54],{"id":2028,"slug":2029,"identity":2030,"label":2031,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2032,"versions":2034,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2035},"package:pypi:waitress","waitress-e47950e2","pypi:waitress","waitress",[2033],"ZPL-2.1",[1341],[54],{"id":2037,"slug":2038,"identity":2039,"label":2040,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2041,"versions":2042,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2044},"package:pypi:wcwidth","wcwidth-038a8957","pypi:wcwidth","wcwidth",[394],[2043],"0.2.13",[54],{"id":2046,"slug":2047,"identity":2048,"label":2049,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2050,"versions":2051,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2053},"package:pypi:wrapt","wrapt-505c01f2","pypi:wrapt","wrapt",[442],[2052],"1.17.2",[54],{"id":2055,"slug":2056,"identity":2057,"label":2058,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2059,"versions":2060,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2062},"package:pypi:xxhash","xxhash-908d556a","pypi:xxhash","xxhash",[570,442],[2061],"3.5.0",[54],{"id":2064,"slug":2065,"identity":2066,"label":2067,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2068,"versions":2069,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2071},"package:pypi:yarl","yarl-05cd1b35","pypi:yarl","yarl",[372],[2070],"1.20.1",[54],{"id":2073,"slug":2074,"identity":2075,"label":2076,"aiRelevant":45,"provider":381,"advisoryCount":37,"licenseExpressions":2077,"versions":2078,"dossier":45,"occurrenceCount":32,"directOccurrenceCount":37,"evidenceFiles":2080},"package:pypi:zipp","zipp-75ac1ddb","pypi:zipp","zipp",[394],[2079],"3.23.0",[54],[2082,2121,2143,2175,2206,2238,2264,2295,2328,2360,2385,2417,2444,2487,2513,2539,2560,2588,2608,2631,2660,2690,2724,2760,2794,2820,2840,2872,2892,2910,2936,2965,2990,3024,3058,3096,3115,3137,3162,3187,3213,3236,3264,3304,3339,3362,3385,3415,3442,3461,3515,3539,3566,3591,3621,3644,3671,3686,3708,3731,3754,3775,3801,3824,3850,3876,3903,3926,3950,3981,4010,4035,4066,4105,4134,4156,4174,4209,4259,4283,4322,4354,4377,4409,4432,4457,4475,4499,4520,4543,4577,4603,4621,4651,4671,4695,4720,4752,4780,4804,4857,4889,4919,4943,4975,5000,5034,5059,5087,5108,5146,5172,5196,5227,5254,5282,5306,5324,5347,5378,5397,5420,5453,5478,5506,5529,5552,5580,5608,5642,5675,5702,5724,5746,5770,5788,5809,5831,5851,5881,5913,5935,5958,5980,6007,6032,6061,6079,6105,6127,6173,6196,6220,6239,6261,6291,6319,6340,6383,6408,6431,6448,6470,6499,6520,6542,6569,6596,6621,6645,6669,6693,6708,6734,6758,6780,6806,6840,6860,6896,6922,6954,6981,7018,7040,7067,7093,7118,7146,7164,7191,7205,7235,7255,7287,7314,7335,7355,7381,7409,7433,7460,7487,7513,7536,7559,7589,7614,7636,7687,7715,7767,7790,7822,7856,7881,7899,7922,7954,7973,7992,8019,8039,8066,8087,8112,8132,8149,8168,8185,8206,8222,8237,8254,8269,8286,8303,8320,8333,8346,8359,8372,8385,8398,8411,8424,8446,8459,8490,8519,8532],{"id":104,"slug":2083,"dossier":45,"summary":2084,"aliases":2085,"sourceIds":2088,"published":2089,"modified":2090,"checkedAt":7,"severity":2091,"references":2095,"versionKeys":2119,"packageCount":32,"repositoryCount":32},"ghsa-248v-346w-9cwc-8a7dbdf1","Certifi removes GLOBALTRUST root certificate",[2086,2087],"CVE-2024-39689","PYSEC-2024-230",[104,2087],"2024-07-05T19:15:10Z","2026-06-10T17:14:18.786020835Z",[2092],{"type":2093,"score":2094},"CVSS_V3","CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[2096,2099,2101,2104,2107,2110,2113,2115,2117],{"type":2097,"url":2098},"ADVISORY","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi\u002Fsecurity\u002Fadvisories\u002FGHSA-248v-346w-9cwc",{"type":2097,"url":2100},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-39689",{"type":2102,"url":2103},"FIX","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi\u002Fcommit\u002Fbd8153872e9c6fc98f4023df9c2deaffea2fa463",{"type":2105,"url":2106},"PACKAGE","https:\u002F\u002Fgithub.com\u002Fcertifi\u002Fpython-certifi",{"type":2108,"url":2109},"WEB","https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fcertifi\u002FPYSEC-2024-230.yaml",{"type":2111,"url":2112},"ARTICLE","https:\u002F\u002Fgroups.google.com\u002Fa\u002Fmozilla.org\u002Fg\u002Fdev-security-policy\u002Fc\u002FXpknYMPO8dI",{"type":2108,"url":2114},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20241206-0001",{"type":2097,"url":2116},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20241206-0001\u002F",{"type":2097,"url":2118},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-248v-346w-9cwc",[2120],"pypi:certifi@2024.6.2",{"id":105,"slug":2122,"dossier":45,"summary":2123,"aliases":2124,"sourceIds":2125,"published":2126,"modified":2127,"checkedAt":7,"severity":2128,"references":2132,"versionKeys":2141,"packageCount":32,"repositoryCount":618},"ghsa-27jp-wm6q-gp25-5ce03f88","sqlparse: formatting list of tuples leads to denial of service",[],[105],"2026-02-13T16:16:11Z","2026-02-19T02:59:07.083683Z",[2129],{"type":2130,"score":2131},"CVSS_V4","CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[2133,2135,2137,2139],{"type":2108,"url":2134},"https:\u002F\u002Fgithub.com\u002Fandialbrecht\u002Fsqlparse\u002Fsecurity\u002Fadvisories\u002FGHSA-27jp-wm6q-gp25",{"type":2108,"url":2136},"https:\u002F\u002Fgithub.com\u002Fandialbrecht\u002Fsqlparse\u002Fcommit\u002F40ed3aa958657fa4a82055927fa9de70ab903360",{"type":2105,"url":2138},"https:\u002F\u002Fgithub.com\u002Fandialbrecht\u002Fsqlparse",{"type":2108,"url":2140},"https:\u002F\u002Fgithub.com\u002Fandialbrecht\u002Fsqlparse\u002Freleases\u002Ftag\u002F0.5.4",[2142],"pypi:sqlparse@0.5.3",{"id":106,"slug":2144,"dossier":45,"summary":2145,"aliases":2146,"sourceIds":2149,"published":2150,"modified":2151,"checkedAt":7,"severity":2152,"references":2155,"versionKeys":2167,"packageCount":32,"repositoryCount":530},"ghsa-29pf-2h5f-8g72-1d83ebb4","HuggingFace transformers vulnerable to remote code execution",[2147,2148],"CVE-2026-4372","PYSEC-2026-2289",[106,2148],"2026-05-24T14:16:16.917Z","2026-07-13T16:45:06.535860363Z",[2153],{"type":2093,"score":2154},"CVSS:3.0\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2156,2158,2160,2162,2165],{"type":2097,"url":2157},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-4372",{"type":2102,"url":2159},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fa7f8e7ff37d87d1a1a0c8cf607971c607741452f",{"type":2105,"url":2161},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers",{"type":2163,"url":2164},"EVIDENCE","https:\u002F\u002Fhuntr.com\u002Fbounties\u002F1f693a6e-6836-4b8b-a0bd-ca036fba8884",{"type":2097,"url":2166},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-29pf-2h5f-8g72",[2168,2169,2170,2171,2172,2173,2174],"pypi:transformers@4.47.1","pypi:transformers@4.51.3","pypi:transformers@4.53.1","pypi:transformers@4.57.1","pypi:transformers@4.57.3","pypi:transformers@4.57.4","pypi:transformers@4.57.6",{"id":107,"slug":2176,"dossier":45,"summary":2177,"aliases":2178,"sourceIds":2181,"published":2182,"modified":2183,"checkedAt":7,"severity":2184,"references":2189,"versionKeys":2200,"packageCount":32,"repositoryCount":64},"ghsa-29vq-49wr-vm6x-7d88633b","Werkzeug safe_join() allows Windows special device names",[2179,2180],"CVE-2026-27199","PYSEC-2026-2320",[107,2180],"2026-02-19T20:32:45Z","2026-07-13T07:26:55.904978535Z",[2185,2187],{"type":2130,"score":2186},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":2188},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[2190,2192,2194,2196,2198],{"type":2097,"url":2191},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fsecurity\u002Fadvisories\u002FGHSA-29vq-49wr-vm6x",{"type":2097,"url":2193},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27199",{"type":2102,"url":2195},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002Ff407712fdc60a09c2b3f4fe7db557703e5d9338d",{"type":2105,"url":2197},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug",{"type":2097,"url":2199},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Freleases\u002Ftag\u002F3.1.6",[2201,2202,2203,2204,2205],"pypi:werkzeug@3.0.1","pypi:werkzeug@3.0.6","pypi:werkzeug@3.1.1","pypi:werkzeug@3.1.3","pypi:werkzeug@3.1.5",{"id":108,"slug":2207,"dossier":45,"summary":2208,"aliases":2209,"sourceIds":2212,"published":2213,"modified":2214,"checkedAt":7,"severity":2215,"references":2217,"versionKeys":2234,"packageCount":32,"repositoryCount":34},"ghsa-2c2j-9gv5-cj73-60bc1f35","Starlette has possible denial-of-service vector when parsing large files in multipart forms",[2210,2211],"CVE-2025-54121","PYSEC-2026-1941",[108,2211],"2025-07-21T19:34:23Z","2026-07-07T17:57:05.760766451Z",[2216],{"type":2093,"score":2188},[2218,2220,2222,2224,2226,2228,2230,2232],{"type":2108,"url":2219},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-2c2j-9gv5-cj73",{"type":2097,"url":2221},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-54121",{"type":2102,"url":2223},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette\u002Fcommit\u002F9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1",{"type":2105,"url":2225},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette",{"type":2108,"url":2227},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette\u002Fblob\u002Ffa5355442753f794965ae1af0f87f9fec1b9a3de\u002Fstarlette\u002Fdatastructures.py#L436C5-L447C14",{"type":2108,"url":2229},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette\u002Fdiscussions\u002F2927#discussioncomment-13721403",{"type":2105,"url":2231},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fstarlette",{"type":2097,"url":2233},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2c2j-9gv5-cj73",[2235,2236,2237],"pypi:starlette@0.37.2","pypi:starlette@0.44.0","pypi:starlette@0.46.2",{"id":109,"slug":2239,"dossier":45,"summary":2240,"aliases":2241,"sourceIds":2243,"published":2244,"modified":2245,"checkedAt":7,"severity":2246,"references":2249,"versionKeys":2260,"packageCount":32,"repositoryCount":34},"ghsa-2f96-g7mh-g2hx-dd7ec02d","GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist",[2242],"CVE-2026-67325",[109],"2026-07-21T19:43:43Z","2026-08-02T03:56:45.052208380Z",[2247],{"type":2093,"score":2248},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2250,2252,2254,2256,2258],{"type":2108,"url":2251},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-2f96-g7mh-g2hx",{"type":2108,"url":2253},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2161",{"type":2108,"url":2255},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F56806080c1348749b07daa4a2024ce47b3cad285",{"type":2105,"url":2257},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython",{"type":2108,"url":2259},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.51",[2261,2262,2263],"pypi:gitpython@3.1.44","pypi:gitpython@3.1.45","pypi:gitpython@3.1.46",{"id":110,"slug":2265,"dossier":45,"summary":2266,"aliases":2267,"sourceIds":2270,"published":2271,"modified":2272,"checkedAt":7,"severity":2273,"references":2278,"versionKeys":2285,"packageCount":32,"repositoryCount":2294},"ghsa-2fqr-mr3j-6wp8-5ee7c60f","aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence",[2268,2269],"CVE-2026-54279","PYSEC-2026-2112",[110,2269],"2026-06-15T20:08:51Z","2026-07-13T07:26:35.059071977Z",[2274,2276],{"type":2130,"score":2275},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:N\u002FVI:N\u002FVA:N\u002FSC:L\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":2277},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",[2279,2281,2283],{"type":2097,"url":2280},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-2fqr-mr3j-6wp8",{"type":2105,"url":2282},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp",{"type":2102,"url":2284},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fa329a7aacad5284f087af36103aff778746da0f2",[2286,2287,2288,2289,2290,2291,2292,2293],"pypi:aiohttp@3.10.11","pypi:aiohttp@3.11.11","pypi:aiohttp@3.11.18","pypi:aiohttp@3.12.13","pypi:aiohttp@3.12.15","pypi:aiohttp@3.13.1","pypi:aiohttp@3.13.2","pypi:aiohttp@3.13.3",9,{"id":111,"slug":2296,"dossier":45,"summary":2297,"aliases":2298,"sourceIds":2301,"published":2302,"modified":2303,"checkedAt":7,"severity":2304,"references":2307,"versionKeys":2327,"packageCount":32,"repositoryCount":32},"ghsa-2g68-c3qc-8985-d6075eca","Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain",[2299,2300],"CVE-2024-34069","PYSEC-2026-2043",[111,2300],"2024-05-06T14:21:27Z","2026-07-07T17:56:15.006571356Z",[2305],{"type":2093,"score":2306},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2308,2310,2312,2314,2315,2317,2319,2321,2323,2325],{"type":2108,"url":2309},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fsecurity\u002Fadvisories\u002FGHSA-2g68-c3qc-8985",{"type":2097,"url":2311},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-34069",{"type":2108,"url":2313},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002F3386395b24c7371db11a5b8eaac0c91da5362692",{"type":2105,"url":2197},{"type":2108,"url":2316},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F02\u002Fmsg00026.html",{"type":2108,"url":2318},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FH4SH32AM3CTPMAAEOIDAN7VU565LO4IR",{"type":2108,"url":2320},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FHFERFN7PINV4MOGMGA3DPIXJPDCYOEJZ",{"type":2108,"url":2322},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20240614-0004",{"type":2105,"url":2324},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fwerkzeug",{"type":2097,"url":2326},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2g68-c3qc-8985",[2201],{"id":112,"slug":2329,"dossier":45,"summary":2330,"aliases":2331,"sourceIds":2334,"published":2335,"modified":2336,"checkedAt":7,"severity":2337,"references":2340,"versionKeys":2357,"packageCount":32,"repositoryCount":568},"ghsa-2h4p-vjrc-8xpq-f59f8dec","Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup",[2332,2333],"CVE-2026-44307","PYSEC-2026-2617",[112,2333],"2026-05-06T21:45:16Z","2026-07-13T16:42:39.139801717Z",[2338],{"type":2130,"score":2339},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[2341,2343,2345,2347,2349,2351,2353,2355],{"type":2108,"url":2342},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Fsecurity\u002Fadvisories\u002FGHSA-2h4p-vjrc-8xpq",{"type":2097,"url":2344},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44307",{"type":2108,"url":2346},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Fissues\u002F435",{"type":2108,"url":2348},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Fcommit\u002F72e10c573ca0fbcbddd4455abca8ce92a61780d7",{"type":2105,"url":2350},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako",{"type":2108,"url":2352},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Freleases\u002Ftag\u002Frel_1_3_12",{"type":2105,"url":2354},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fmako",{"type":2097,"url":2356},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2h4p-vjrc-8xpq",[2358,2359],"pypi:mako@1.3.10","pypi:mako@1.3.8",{"id":113,"slug":2361,"dossier":45,"summary":2362,"aliases":2363,"sourceIds":2366,"published":2367,"modified":2368,"checkedAt":7,"severity":2369,"references":2374,"versionKeys":2384,"packageCount":32,"repositoryCount":2294},"ghsa-2vrm-gr82-f7m5-5092ea0c","AIOHTTP has CRLF injection through multipart part content type header construction",[2364,2365],"CVE-2026-34514","PYSEC-2026-2096",[113,2365],"2026-04-01T21:16:59.417Z","2026-07-13T07:26:28.471600737Z",[2370,2372],{"type":2130,"score":2371},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":2373},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",[2375,2377,2379,2381,2382],{"type":2102,"url":2376},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-2vrm-gr82-f7m5",{"type":2097,"url":2378},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34514",{"type":2102,"url":2380},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06",{"type":2105,"url":2282},{"type":2097,"url":2383},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Freleases\u002Ftag\u002Fv3.13.4",[2286,2287,2288,2289,2290,2291,2292,2293],{"id":114,"slug":2386,"dossier":89,"summary":2387,"aliases":2388,"sourceIds":2391,"published":2392,"modified":2393,"checkedAt":7,"severity":2394,"references":2397,"versionKeys":2410,"packageCount":32,"repositoryCount":2416},"ghsa-2xpw-w6gg-jr37-91cead57","urllib3 streaming API improperly handles highly compressed data",[2389,2390],"CVE-2025-66471","PYSEC-2026-1994",[114,2390],"2025-12-05T18:15:54Z","2026-07-07T17:56:33.872074196Z",[2395],{"type":2130,"score":2396},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:H",[2398,2400,2402,2404,2406,2408],{"type":2108,"url":2399},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-2xpw-w6gg-jr37",{"type":2097,"url":2401},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66471",{"type":2102,"url":2403},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Fc19571de34c47de3a766541b041637ba5f716ed7",{"type":2105,"url":2405},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3",{"type":2105,"url":2407},"https:\u002F\u002Fpypi.org\u002Fproject\u002Furllib3",{"type":2097,"url":2409},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2xpw-w6gg-jr37",[2411,2412,2413,2414,2415],"pypi:urllib3@2.2.2","pypi:urllib3@2.2.3","pypi:urllib3@2.3.0","pypi:urllib3@2.4.0","pypi:urllib3@2.5.0",13,{"id":115,"slug":2418,"dossier":45,"summary":2419,"aliases":2420,"sourceIds":2423,"published":2424,"modified":2425,"checkedAt":7,"severity":2426,"references":2429,"versionKeys":2442,"packageCount":32,"repositoryCount":618},"ghsa-33p9-3p43-82vq-f6a57ddd","Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability",[2421,2422],"CVE-2025-30167","PYSEC-2026-1477",[115,2422],"2025-06-04T21:00:23Z","2026-07-07T17:57:34.145908633Z",[2427],{"type":2093,"score":2428},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2430,2432,2434,2436,2438,2440],{"type":2108,"url":2431},"https:\u002F\u002Fgithub.com\u002Fjupyter\u002Fjupyter_core\u002Fsecurity\u002Fadvisories\u002FGHSA-33p9-3p43-82vq",{"type":2097,"url":2433},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-30167",{"type":2108,"url":2435},"https:\u002F\u002Fgithub.com\u002Fjupyter\u002Fjupyter_core\u002Fcommit\u002F5e8965600adda6b416692ce7e85ecb2bd814bd52",{"type":2105,"url":2437},"https:\u002F\u002Fgithub.com\u002Fjupyter\u002Fjupyter_core",{"type":2105,"url":2439},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fjupyter-core",{"type":2097,"url":2441},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-33p9-3p43-82vq",[2443],"pypi:jupyter-core@5.7.2",{"id":116,"slug":2445,"dossier":45,"summary":2446,"aliases":2447,"sourceIds":2451,"published":2452,"modified":2453,"checkedAt":7,"severity":2454,"references":2461,"versionKeys":2483,"packageCount":32,"repositoryCount":599},"ghsa-3749-ghw9-m3mg-fadf4a32","PyTorch susceptible to local Denial of Service",[2448,2449,2450],"BIT-pytorch-2025-2953","CVE-2025-2953","PYSEC-2025-191",[116,2450],"2025-03-30T16:15:14.380Z","2026-06-10T17:02:35.808223212Z",[2455,2457,2459],{"type":2093,"score":2456},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",{"type":2130,"score":2458},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":2093,"score":2460},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",[2462,2464,2467,2469,2471,2473,2475,2477,2479,2481],{"type":2097,"url":2463},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2953",{"type":2465,"url":2466},"REPORT","https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149274",{"type":2465,"url":2468},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149274#issue-2923122269",{"type":2108,"url":2470},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-191.yaml",{"type":2105,"url":2472},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch",{"type":2108,"url":2474},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fblob\u002Fmain\u002FSECURITY.md#untrusted-models",{"type":2465,"url":2476},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302006",{"type":2097,"url":2478},"https:\u002F\u002Fvuldb.com\u002F?id.302006",{"type":2097,"url":2480},"https:\u002F\u002Fvuldb.com\u002F?submit.521279",{"type":2097,"url":2482},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3749-ghw9-m3mg",[2484,2485,2486],"pypi:torch@2.5.1","pypi:torch@2.6.0","pypi:torch@2.7.0",{"id":117,"slug":2488,"dossier":45,"summary":2489,"aliases":2490,"sourceIds":2493,"published":2494,"modified":2495,"checkedAt":7,"severity":2496,"references":2498,"versionKeys":2512,"packageCount":32,"repositoryCount":618},"ghsa-37mw-44qp-f5jm-fb05555e","Transformers is vulnerable to ReDoS attack through its DonutProcessor class",[2491,2492],"CVE-2025-3933","PYSEC-2026-1977",[117,2492],"2025-07-11T12:30:32Z","2026-07-07T17:57:16.879129924Z",[2497],{"type":2093,"score":2188},[2499,2501,2503,2505,2506,2508,2510],{"type":2097,"url":2500},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3933",{"type":2108,"url":2502},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F37788",{"type":2108,"url":2504},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Febbe9b12dd75b69f92100d684c47f923ee262a93",{"type":2105,"url":2161},{"type":2108,"url":2507},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F25282953-5827-4384-bb6f-5790d275721b",{"type":2105,"url":2509},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftransformers",{"type":2097,"url":2511},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-37mw-44qp-f5jm",[2168,2169],{"id":118,"slug":2514,"dossier":89,"summary":2515,"aliases":2516,"sourceIds":2519,"published":2520,"modified":2521,"checkedAt":7,"severity":2522,"references":2525,"versionKeys":2538,"packageCount":32,"repositoryCount":2416},"ghsa-38jv-5279-wg99-c9df8f7b","Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)",[2517,2518],"CVE-2026-21441","PYSEC-2026-1996",[118,2518],"2026-01-07T19:18:14Z","2026-07-07T17:56:31.346111893Z",[2523,2524],{"type":2093,"score":2277},{"type":2130,"score":2396},[2526,2528,2530,2532,2533,2535,2536],{"type":2108,"url":2527},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-38jv-5279-wg99",{"type":2097,"url":2529},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-21441",{"type":2102,"url":2531},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F8864ac407bba8607950025e0979c4c69bc7abc7b",{"type":2105,"url":2405},{"type":2108,"url":2534},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F01\u002Fmsg00017.html",{"type":2105,"url":2407},{"type":2097,"url":2537},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-38jv-5279-wg99",[2411,2412,2413,2414,2415],{"id":119,"slug":2540,"dossier":45,"summary":2541,"aliases":2542,"sourceIds":2543,"published":2544,"modified":2545,"checkedAt":7,"severity":2546,"references":2549,"versionKeys":2559,"packageCount":32,"repositoryCount":34},"ghsa-3f7w-8rr8-f37f-9cab61a6","GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read",[],[119],"2026-08-03T20:09:56Z","2026-08-08T03:26:54.875954204Z",[2547],{"type":2093,"score":2548},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",[2550,2552,2554,2556,2557],{"type":2108,"url":2551},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3f7w-8rr8-f37f",{"type":2108,"url":2553},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2193",{"type":2108,"url":2555},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F3af0c2516c5e18c829da30338614688f6b69b49c",{"type":2105,"url":2257},{"type":2108,"url":2558},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.57",[2261,2262,2263],{"id":120,"slug":2561,"dossier":45,"summary":2562,"aliases":2563,"sourceIds":2566,"published":2567,"modified":2568,"checkedAt":7,"severity":2569,"references":2572,"versionKeys":2585,"packageCount":32,"repositoryCount":568},"ghsa-3j69-69wj-xqx2-6b8725d1","UltraJSON: Malformed\u002FTruncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()",[2564,2565],"CVE-2026-54911","PYSEC-2026-2294",[120,2565],"2026-06-19T20:47:43Z","2026-07-18T17:45:20.862335233Z",[2570],{"type":2093,"score":2571},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[2573,2575,2577,2579,2581,2583],{"type":2102,"url":2574},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fsecurity\u002Fadvisories\u002FGHSA-3j69-69wj-xqx2",{"type":2097,"url":2576},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54911",{"type":2102,"url":2578},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fcommit\u002F169eaf36b1116fece5034ee79a7a0ef3f6deedcf",{"type":2108,"url":2580},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fujson\u002FPYSEC-2026-2294.yaml",{"type":2105,"url":2582},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson",{"type":2097,"url":2584},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Freleases\u002Ftag\u002F5.13.0",[2586,2587],"pypi:ujson@5.10.0","pypi:ujson@5.12.0",{"id":121,"slug":2589,"dossier":45,"summary":2590,"aliases":2591,"sourceIds":2593,"published":2594,"modified":2595,"checkedAt":7,"severity":2596,"references":2599,"versionKeys":2607,"packageCount":32,"repositoryCount":34},"ghsa-3rp5-jjmw-4wv2-6d7352e6","GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)",[2592],"CVE-2026-69097",[121],"2026-07-24T16:22:02Z","2026-08-04T05:41:05.585188057Z",[2597],{"type":2093,"score":2598},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2600,2602,2604,2605],{"type":2108,"url":2601},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-3rp5-jjmw-4wv2",{"type":2108,"url":2603},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1ed1b924f4e2d2ee7bab296df77b978af21853f1",{"type":2105,"url":2257},{"type":2108,"url":2606},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.53",[2261,2262,2263],{"id":122,"slug":2609,"dossier":45,"summary":2610,"aliases":2611,"sourceIds":2614,"published":2615,"modified":2616,"checkedAt":7,"severity":2617,"references":2621,"versionKeys":2630,"packageCount":32,"repositoryCount":2294},"ghsa-3wq7-rqq7-wx6j-29b8d785","AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS",[2612,2613],"CVE-2026-34517","PYSEC-2026-2099",[122,2613],"2026-04-01T21:16:59.870Z","2026-07-13T07:26:13.561233517Z",[2618,2620],{"type":2130,"score":2619},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":2188},[2622,2624,2626,2628,2629],{"type":2102,"url":2623},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-3wq7-rqq7-wx6j",{"type":2097,"url":2625},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34517",{"type":2102,"url":2627},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fcbb774f38330563422ca0c413a71021d7b944145",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":123,"slug":2632,"dossier":45,"summary":2633,"aliases":2634,"sourceIds":2637,"published":2638,"modified":2639,"checkedAt":7,"severity":2640,"references":2643,"versionKeys":2654,"packageCount":32,"repositoryCount":64},"ghsa-3x9g-8vmp-wqvf-6d03bf5f","Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient",[2635,2636],"CVE-2026-49853","PYSEC-2026-3387",[123,2636],"2026-06-15T20:20:00Z","2026-07-13T16:42:55.378655356Z",[2641],{"type":2093,"score":2642},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[2644,2646,2648,2650,2652],{"type":2108,"url":2645},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-3x9g-8vmp-wqvf",{"type":2105,"url":2647},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado",{"type":2105,"url":2649},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftornado",{"type":2097,"url":2651},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3x9g-8vmp-wqvf",{"type":2097,"url":2653},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49853",[2655,2656,2657,2658,2659],"pypi:tornado@6.4.2","pypi:tornado@6.5.1","pypi:tornado@6.5.2","pypi:tornado@6.5.4","pypi:tornado@6.5.5",{"id":124,"slug":2661,"dossier":45,"summary":2662,"aliases":2663,"sourceIds":2667,"published":2668,"modified":2669,"checkedAt":7,"severity":2670,"references":2673,"versionKeys":2686,"packageCount":32,"repositoryCount":599},"ghsa-42h5-h8qh-vv9v-4d35a1ef","MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem",[2664,2665,2666],"BIT-mlflow-2026-2614","CVE-2026-2614","PYSEC-2026-2654",[124,2666],"2026-05-11T21:31:35Z","2026-07-13T16:42:45.636199436Z",[2671],{"type":2093,"score":2672},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[2674,2676,2678,2680,2682,2684],{"type":2097,"url":2675},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2614",{"type":2108,"url":2677},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F6e801f4259d96804c73107315b24cef0f6aa115a",{"type":2105,"url":2679},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow",{"type":2108,"url":2681},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F19380271-3fbf-4beb-987e-6fd7069c55e6",{"type":2105,"url":2683},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fmlflow",{"type":2097,"url":2685},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-42h5-h8qh-vv9v",[2687,2688,2689],"pypi:mlflow@3.1.1","pypi:mlflow@3.4.0","pypi:mlflow@3.8.1",{"id":125,"slug":2691,"dossier":89,"summary":2692,"aliases":2693,"sourceIds":2697,"published":2698,"modified":2699,"checkedAt":7,"severity":2700,"references":2702,"versionKeys":2715,"packageCount":32,"repositoryCount":2416},"ghsa-45hq-cxwh-f6vc-d18d2872","Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading",[2694,2695,2696],"BIT-pillow-2026-55379","CVE-2026-55379","PYSEC-2026-2255",[125,2696],"2026-07-06T19:17:08.577Z","2026-07-22T02:59:39.058744123Z",[2701],{"type":2093,"score":2277},[2703,2705,2707,2709,2711,2713],{"type":2163,"url":2704},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-45hq-cxwh-f6vc",{"type":2097,"url":2706},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55379",{"type":2102,"url":2708},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F0a263e6264aa5399988d9acd3bbfbca2ca3ec77d",{"type":2108,"url":2710},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2255.yaml",{"type":2105,"url":2712},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow",{"type":2097,"url":2714},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fblob\u002Fmain\u002Fdocs\u002Freleasenotes\u002F12.3.0.rst",[2716,2717,2718,2719,2720,2721,2722,2723],"pypi:pillow@10.3.0","pypi:pillow@10.4.0","pypi:pillow@11.1.0","pypi:pillow@11.2.1","pypi:pillow@11.3.0","pypi:pillow@12.0.0","pypi:pillow@12.1.0","pypi:pillow@12.1.1",{"id":126,"slug":2725,"dossier":45,"summary":2726,"aliases":2727,"sourceIds":2730,"published":2731,"modified":2732,"checkedAt":7,"severity":2733,"references":2736,"versionKeys":2757,"packageCount":32,"repositoryCount":599},"ghsa-469j-vmhf-r6v7-df07d853","NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite",[2728,2729],"CVE-2026-33236","PYSEC-2026-2237",[126,2729],"2026-03-19T12:42:42Z","2026-07-13T07:26:54.270611709Z",[2734],{"type":2093,"score":2735},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:H",[2737,2739,2741,2743,2745,2747,2749,2751,2753,2755],{"type":2163,"url":2738},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-469j-vmhf-r6v7",{"type":2097,"url":2740},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33236",{"type":2102,"url":2742},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002F89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a",{"type":2105,"url":2744},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk",{"type":2108,"url":2746},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-33236",{"type":2108,"url":2748},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-33236.json",{"type":2097,"url":2750},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:10184",{"type":2097,"url":2752},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:19712",{"type":2097,"url":2754},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:37275",{"type":2465,"url":2756},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2449824",[2758,2759],"pypi:nltk@3.9.1","pypi:nltk@3.9.2",{"id":127,"slug":2761,"dossier":45,"summary":2762,"aliases":2763,"sourceIds":2767,"published":2768,"modified":2769,"checkedAt":7,"severity":2770,"references":2775,"versionKeys":2793,"packageCount":32,"repositoryCount":599},"ghsa-46r5-x6jq-v8g6-fda1ffbe","MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint",[2764,2765,2766],"BIT-mlflow-2026-33866","CVE-2026-33866","PYSEC-2026-94",[127,2766],"2026-04-07T13:16:47Z","2026-06-10T17:02:20.749690187Z",[2771,2773],{"type":2093,"score":2772},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",{"type":2130,"score":2774},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[2776,2778,2780,2782,2784,2786,2787,2789,2791],{"type":2097,"url":2777},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33866",{"type":2102,"url":2779},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F21708",{"type":2108,"url":2781},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F005b959cacda05d1423356cfcbd9ebeda8ff96a7",{"type":2163,"url":2783},"https:\u002F\u002Fafine.com\u002Fblogs\u002Fattacking-mlflow-how-ml-artifacts-become-attack-vectors",{"type":2108,"url":2785},"https:\u002F\u002Fcert.pl\u002Fen\u002Fposts\u002F2026\u002F04\u002FCVE-2026-33865",{"type":2105,"url":2679},{"type":2108,"url":2788},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fmlflow\u002FPYSEC-2026-94.yaml",{"type":2097,"url":2790},"https:\u002F\u002Fcert.pl\u002Fen\u002Fposts\u002F2026\u002F04\u002FCVE-2026-33865\u002F",{"type":2097,"url":2792},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-46r5-x6jq-v8g6",[2687,2688,2689],{"id":128,"slug":2795,"dossier":45,"summary":2796,"aliases":2797,"sourceIds":2800,"published":2801,"modified":2802,"checkedAt":7,"severity":2803,"references":2806,"versionKeys":2819,"packageCount":32,"repositoryCount":540},"ghsa-48p4-8xcf-vxj5-13f12656","urllib3 does not control redirects in browsers and Node.js",[2798,2799],"CVE-2025-50182","PYSEC-2026-1997",[128,2799],"2025-06-18T17:50:11Z","2026-07-07T17:57:08.881416805Z",[2804],{"type":2093,"score":2805},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[2807,2809,2811,2813,2814,2816,2817],{"type":2108,"url":2808},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-48p4-8xcf-vxj5",{"type":2097,"url":2810},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-50182",{"type":2102,"url":2812},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f",{"type":2105,"url":2405},{"type":2108,"url":2815},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Freleases\u002Ftag\u002F2.5.0",{"type":2105,"url":2407},{"type":2097,"url":2818},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-48p4-8xcf-vxj5",[2411,2412,2413,2414],{"id":129,"slug":2821,"dossier":45,"summary":2822,"aliases":2823,"sourceIds":2826,"published":2827,"modified":2828,"checkedAt":7,"severity":2829,"references":2833,"versionKeys":2839,"packageCount":32,"repositoryCount":2294},"ghsa-4fvr-rgm6-gqmc-c8b35c87","aiohttp: HTTP\u002F1 Pipelined Requests Queue Without Limit",[2824,2825],"CVE-2026-54273","PYSEC-2026-2107",[129,2825],"2026-06-15T20:10:32Z","2026-07-13T07:26:17.316378610Z",[2830,2832],{"type":2130,"score":2831},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":2277},[2834,2836,2838],{"type":2097,"url":2835},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-4fvr-rgm6-gqmc",{"type":2102,"url":2837},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fdfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":130,"slug":2841,"dossier":45,"summary":2842,"aliases":2843,"sourceIds":2846,"published":2847,"modified":2848,"checkedAt":7,"severity":2849,"references":2852,"versionKeys":2867,"packageCount":32,"repositoryCount":34},"ghsa-4g5m-c9r5-49xf-40cc28b0","LiteLLM: Local file read via request-supplied OIDC file references",[2844,2845],"CVE-2026-59819","PYSEC-2026-3476",[130,2845],"2026-07-22T22:38:04Z","2026-07-23T15:11:50.258485894Z",[2850],{"type":2130,"score":2851},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:H\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[2853,2855,2857,2859,2861,2863,2865],{"type":2108,"url":2854},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-4g5m-c9r5-49xf",{"type":2097,"url":2856},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59819",{"type":2108,"url":2858},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fpull\u002F25592",{"type":2105,"url":2860},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm",{"type":2108,"url":2862},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Freleases\u002Ftag\u002Fv1.83.10-stable",{"type":2105,"url":2864},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flitellm",{"type":2097,"url":2866},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4g5m-c9r5-49xf",[2868,2869,2870,2871],"pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1",{"id":131,"slug":2873,"dossier":45,"summary":2874,"aliases":2875,"sourceIds":2876,"published":2877,"modified":2878,"checkedAt":7,"severity":2879,"references":2881,"versionKeys":2891,"packageCount":32,"repositoryCount":34},"ghsa-4gmw-gg2m-w46p-58f27cb8","GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree\u002Freset\u002Fmerge_tree enables arbitrary file overwrite",[],[131],"2026-08-07T15:33:57Z","2026-08-09T02:56:50.755731198Z",[2880],{"type":2093,"score":2548},[2882,2884,2886,2888,2889],{"type":2108,"url":2883},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-4gmw-gg2m-w46p",{"type":2108,"url":2885},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2204",{"type":2108,"url":2887},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F9b5dcaf85da5946dbf69dcd53f9edba08f760b32",{"type":2105,"url":2257},{"type":2108,"url":2890},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.58",[2261,2262,2263],{"id":132,"slug":2893,"dossier":45,"summary":2894,"aliases":2895,"sourceIds":2898,"published":2899,"modified":2900,"checkedAt":7,"severity":2901,"references":2905,"versionKeys":2909,"packageCount":32,"repositoryCount":2294},"ghsa-4m7w-qmgq-4wj5-f98433d3","aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections",[2896,2897],"CVE-2026-54275","PYSEC-2026-237",[132,2897],"2026-06-15T20:11:13Z","2026-06-27T11:26:29.646102490Z",[2902,2904],{"type":2130,"score":2903},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":2277},[2906,2908],{"type":2097,"url":2907},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-4m7w-qmgq-4wj5",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":133,"slug":2911,"dossier":45,"summary":2912,"aliases":2913,"sourceIds":2916,"published":2917,"modified":2918,"checkedAt":7,"severity":2919,"references":2922,"versionKeys":2935,"packageCount":32,"repositoryCount":618},"ghsa-4w7r-h757-3r74-ca8973bc","Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer",[2914,2915],"CVE-2025-6921","PYSEC-2026-1980",[133,2915],"2025-09-23T15:31:09Z","2026-07-07T17:57:12.050585329Z",[2920],{"type":2093,"score":2921},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[2923,2925,2927,2929,2930,2932,2933],{"type":2097,"url":2924},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6921",{"type":2108,"url":2926},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F47c34fba5c303576560cb29767efb452ff12b8be",{"type":2108,"url":2928},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fd37f7517972f67e3f2194c000ed0f87f064e5099",{"type":2105,"url":2161},{"type":2108,"url":2931},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F287d15a7-6e7c-45d2-8c05-11e305776f1f",{"type":2105,"url":2509},{"type":2097,"url":2934},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4w7r-h757-3r74",[2168,2169],{"id":134,"slug":2937,"dossier":89,"summary":2938,"aliases":2939,"sourceIds":2943,"published":2944,"modified":2945,"checkedAt":7,"severity":2946,"references":2949,"versionKeys":2964,"packageCount":32,"repositoryCount":2416},"ghsa-4x4j-2g7c-83w6-326c14d2","Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path",[2940,2941,2942],"BIT-pillow-2026-55798","CVE-2026-55798","PYSEC-2026-2257",[134,2942],"2026-07-06T19:17:08.830Z","2026-07-22T02:59:40.755856576Z",[2947],{"type":2093,"score":2948},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:L",[2950,2952,2954,2956,2958,2960,2962,2963],{"type":2163,"url":2951},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-4x4j-2g7c-83w6",{"type":2097,"url":2953},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55798",{"type":2102,"url":2955},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F8404ea5fe5df40fc34aa1e51403dd6fce0778b8a",{"type":2102,"url":2957},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F88194166691b7b603529b8b036ab3ab9cedd2de4",{"type":2102,"url":2959},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fb0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f",{"type":2108,"url":2961},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2257.yaml",{"type":2105,"url":2712},{"type":2097,"url":2714},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":135,"slug":2966,"dossier":45,"summary":2967,"aliases":2968,"sourceIds":2972,"published":2973,"modified":2974,"checkedAt":7,"severity":2975,"references":2978,"versionKeys":2989,"packageCount":32,"repositoryCount":32},"ghsa-4x5p-f36r-mxxr-f02b9eff","mlflow Creates of Temporary File in Directory with Insecure Permissions",[2969,2970,2971],"BIT-mlflow-2025-10279","CVE-2025-10279","PYSEC-2026-1639",[135,2971],"2026-02-02T12:31:14Z","2026-07-07T17:56:10.135090160Z",[2976],{"type":2093,"score":2977},"CVSS:3.0\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[2979,2981,2983,2984,2986,2987],{"type":2097,"url":2980},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-10279",{"type":2108,"url":2982},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F1d7c8d4cf0a67d407499a8a4ffac387ea4f8194a",{"type":2105,"url":2679},{"type":2108,"url":2985},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F01d3b81e-13d1-43aa-b91a-443aec68bdc8",{"type":2105,"url":2683},{"type":2097,"url":2988},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4x5p-f36r-mxxr",[2687],{"id":136,"slug":2991,"dossier":45,"summary":2992,"aliases":2993,"sourceIds":2996,"published":2997,"modified":2998,"checkedAt":7,"severity":2999,"references":3002,"versionKeys":3021,"packageCount":32,"repositoryCount":599},"ghsa-4xh5-x5gv-qwph-bdb101cb","pip's fallback tar extraction doesn't check symbolic links point to extraction directory",[2994,2995],"CVE-2025-8869","PYSEC-2026-1795",[136,2995],"2025-09-24T15:31:14Z","2026-07-07T17:57:29.434622137Z",[3000],{"type":2130,"score":3001},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:A\u002FVC:N\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3003,3005,3007,3009,3011,3013,3015,3017,3019],{"type":2097,"url":3004},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-8869",{"type":2108,"url":3006},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fpull\u002F13550",{"type":2102,"url":3008},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fcommit\u002Ff2b92314da012b9fffa36b3f3e67748a37ef464a",{"type":2105,"url":3010},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip",{"type":2108,"url":3012},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F10\u002Fmsg00028.html",{"type":2108,"url":3014},"https:\u002F\u002Fmail.python.org\u002Farchives\u002Flist\u002Fsecurity-announce@python.org\u002Fthread\u002FIF5A3GCJY3VH7BVHJKOWOJFKTW7VFQEN",{"type":2108,"url":3016},"https:\u002F\u002Fpip.pypa.io\u002Fen\u002Fstable\u002Fnews\u002F#v25-2",{"type":2105,"url":3018},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fpip",{"type":2097,"url":3020},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4xh5-x5gv-qwph",[3022,3023],"pypi:pip@22.0.2","pypi:pip@25.1.1",{"id":137,"slug":3025,"dossier":45,"summary":3026,"aliases":3027,"sourceIds":3030,"published":3031,"modified":3032,"checkedAt":7,"severity":3033,"references":3038,"versionKeys":3057,"packageCount":32,"repositoryCount":34},"ghsa-4xpc-pv4p-pm3w-c72dbf83","LiteLLM: Authentication Bypass via Host Header Injection",[3028,3029],"CVE-2026-49468","PYSEC-2026-388",[137,3029],"2026-06-16T23:38:26Z","2026-07-18T17:30:30.617013067Z",[3034,3036],{"type":2093,"score":3035},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2130,"score":3037},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:H\u002FSI:H\u002FSA:H",[3039,3041,3043,3045,3047,3048,3050,3052,3054,3055],{"type":2108,"url":3040},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-4xpc-pv4p-pm3w",{"type":2097,"url":3042},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49468",{"type":2108,"url":3044},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-49468",{"type":2108,"url":3046},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2491520",{"type":2105,"url":2860},{"type":2108,"url":3049},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Freleases\u002Ftag\u002Fv1.84.0",{"type":2097,"url":3051},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-4xpc-pv4p-pm3w",{"type":2108,"url":3053},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flitellm\u002FPYSEC-2026-388.yaml",{"type":2105,"url":2864},{"type":2108,"url":3056},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-49468.json",[2868,2869,2870,2871],{"id":138,"slug":3059,"dossier":89,"summary":3060,"aliases":3061,"sourceIds":3064,"published":3065,"modified":3066,"checkedAt":7,"severity":3067,"references":3070,"versionKeys":3093,"packageCount":32,"repositoryCount":2416},"ghsa-5239-wwwm-4pmq-228840e4","Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching",[3062,3063],"CVE-2026-4539","PYSEC-2026-2987",[138,3063],"2026-03-22T06:30:15Z","2026-07-13T16:42:36.989801915Z",[3068,3069],{"type":2093,"score":2456},{"type":2130,"score":2458},[3071,3073,3075,3077,3079,3081,3083,3085,3087,3089,3091],{"type":2097,"url":3072},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-4539",{"type":2108,"url":3074},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Fissues\u002F3058",{"type":2108,"url":3076},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Fpull\u002F3064",{"type":2108,"url":3078},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Fcommit\u002F24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc",{"type":2105,"url":3080},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments",{"type":2108,"url":3082},"https:\u002F\u002Fgithub.com\u002Fpygments\u002Fpygments\u002Freleases\u002Ftag\u002F2.20.0",{"type":2108,"url":3084},"https:\u002F\u002Fvuldb.com\u002F?ctiid.352327",{"type":2108,"url":3086},"https:\u002F\u002Fvuldb.com\u002F?id.352327",{"type":2108,"url":3088},"https:\u002F\u002Fvuldb.com\u002F?submit.774685",{"type":2105,"url":3090},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fpygments",{"type":2097,"url":3092},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5239-wwwm-4pmq",[3094,3095],"pypi:pygments@2.19.1","pypi:pygments@2.19.2",{"id":139,"slug":3097,"dossier":45,"summary":3098,"aliases":3099,"sourceIds":3100,"published":3101,"modified":3102,"checkedAt":7,"severity":3103,"references":3106,"versionKeys":3114,"packageCount":32,"repositoryCount":34},"ghsa-539m-9xh6-q6rr-c4575e3c","GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file \u002F --add-virtual-file, enabling arbitrary file read via Repo.archive()",[],[139],"2026-08-03T20:14:28Z","2026-08-08T03:26:54.618366791Z",[3104],{"type":2093,"score":3105},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[3107,3109,3110,3112,3113],{"type":2108,"url":3108},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-539m-9xh6-q6rr",{"type":2108,"url":2553},{"type":2108,"url":3111},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F7a4f5dcb7bf3cbcbf6e438017efcdfe0bc0d36ca",{"type":2105,"url":2257},{"type":2108,"url":2558},[2261,2262,2263],{"id":140,"slug":3116,"dossier":45,"summary":3117,"aliases":3118,"sourceIds":3121,"published":3122,"modified":3123,"checkedAt":7,"severity":3124,"references":3127,"versionKeys":3136,"packageCount":32,"repositoryCount":34},"ghsa-53mr-6c8q-9789-034179e7","LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint",[3119,3120],"CVE-2026-35029","PYSEC-2026-2597",[140,3120],"2026-04-03T21:59:31Z","2026-07-13T16:43:01.087747831Z",[3125],{"type":2130,"score":3126},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:L\u002FSI:L\u002FSA:N",[3128,3130,3132,3133,3134],{"type":2108,"url":3129},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-53mr-6c8q-9789",{"type":2097,"url":3131},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-35029",{"type":2105,"url":2860},{"type":2105,"url":2864},{"type":2097,"url":3135},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-53mr-6c8q-9789",[2868,2869,2870,2871],{"id":141,"slug":3138,"dossier":45,"summary":3139,"aliases":3140,"sourceIds":3144,"published":3145,"modified":3146,"checkedAt":7,"severity":3147,"references":3151,"versionKeys":3161,"packageCount":32,"repositoryCount":32},"ghsa-53q9-r3pm-6pq6-6fbb0149","PyTorch: `torch.load` with `weights_only=True` leads to remote code execution",[3141,3142,3143],"BIT-pytorch-2025-32434","CVE-2025-32434","PYSEC-2025-41",[141,3143],"2025-04-18T15:19:28Z","2026-08-07T08:12:20.395044060Z",[3148,3150],{"type":2130,"score":3149},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":3035},[3152,3154,3156,3158,3160],{"type":2097,"url":3153},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fsecurity\u002Fadvisories\u002FGHSA-53q9-r3pm-6pq6",{"type":2097,"url":3155},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-32434",{"type":2108,"url":3157},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F8d4b8a920a2172523deb95bf20e8e52d50649c04",{"type":2108,"url":3159},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-41.yaml",{"type":2105,"url":2472},[2484],{"id":142,"slug":3163,"dossier":45,"summary":3164,"aliases":3165,"sourceIds":3168,"published":3169,"modified":3170,"checkedAt":7,"severity":3171,"references":3174,"versionKeys":3186,"packageCount":32,"repositoryCount":540},"ghsa-54jq-c3m8-4m76-bba4b2d3","AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components",[3166,3167],"CVE-2025-69226","PYSEC-2026-1097",[142,3167],"2026-01-05T23:09:51Z","2026-07-07T17:57:12.462419549Z",[3172],{"type":2130,"score":3173},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",[3175,3177,3179,3181,3182,3184],{"type":2108,"url":3176},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-54jq-c3m8-4m76",{"type":2097,"url":3178},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69226",{"type":2102,"url":3180},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Ff2a86fd5ac0383000d1715afddfa704413f0711e",{"type":2105,"url":2282},{"type":2105,"url":3183},"https:\u002F\u002Fpypi.org\u002Fproject\u002Faiohttp",{"type":2097,"url":3185},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-54jq-c3m8-4m76",[2286,2287,2288,2289,2290,2291,2292],{"id":143,"slug":3188,"dossier":45,"summary":3189,"aliases":3190,"sourceIds":3193,"published":3194,"modified":3195,"checkedAt":7,"severity":3196,"references":3199,"versionKeys":3212,"packageCount":32,"repositoryCount":599},"ghsa-58qw-9mgm-455v-d690efaf","pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files",[3191,3192],"CVE-2026-3219","PYSEC-2026-2875",[143,3192],"2026-04-20T18:31:48Z","2026-07-13T16:43:17.083270258Z",[3197],{"type":2130,"score":3198},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:A\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3200,3202,3204,3206,3207,3209,3210],{"type":2097,"url":3201},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-3219",{"type":2108,"url":3203},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fissues\u002F13867",{"type":2108,"url":3205},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fpull\u002F13870",{"type":2105,"url":3010},{"type":2108,"url":3208},"https:\u002F\u002Fmail.python.org\u002Farchives\u002Flist\u002Fsecurity-announce@python.org\u002Fthread\u002FQAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ",{"type":2105,"url":3018},{"type":2097,"url":3211},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-58qw-9mgm-455v",[3022,3023],{"id":144,"slug":3214,"dossier":45,"summary":3215,"aliases":3216,"sourceIds":3219,"published":3220,"modified":3221,"checkedAt":7,"severity":3222,"references":3224,"versionKeys":3235,"packageCount":32,"repositoryCount":618},"ghsa-59p9-h35m-wg4g-68657c65","Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer",[3217,3218],"CVE-2025-6638","PYSEC-2026-1981",[144,3218],"2025-09-12T12:30:23Z","2026-07-07T17:56:49.269701149Z",[3223],{"type":2093,"score":2921},[3225,3227,3228,3229,3230,3232,3233],{"type":2097,"url":3226},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6638",{"type":2108,"url":2926},{"type":2108,"url":2928},{"type":2105,"url":2161},{"type":2108,"url":3231},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F6a6c933f-9ce8-4ded-8b3b-2c1444c61f36",{"type":2105,"url":2509},{"type":2097,"url":3234},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-59p9-h35m-wg4g",[2168,2169],{"id":145,"slug":3237,"dossier":45,"summary":3238,"aliases":3239,"sourceIds":3242,"published":3243,"modified":3244,"checkedAt":7,"severity":3245,"references":3248,"versionKeys":3263,"packageCount":32,"repositoryCount":34},"ghsa-5jmr-gcrj-2c9q-651d4e44","LiteLLM: Arbitrary file write via path traversal in Skills archive extraction",[3240,3241],"CVE-2026-59820","PYSEC-2026-3477",[145,3241],"2026-07-22T22:37:15Z","2026-07-23T15:11:39.917682016Z",[3246],{"type":2130,"score":3247},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[3249,3251,3253,3255,3257,3258,3260,3261],{"type":2108,"url":3250},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-5jmr-gcrj-2c9q",{"type":2097,"url":3252},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59820",{"type":2108,"url":3254},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fpull\u002F25475",{"type":2108,"url":3256},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002F6a15adcd64137d37f73dee76dfe7481f8c2d9196",{"type":2105,"url":2860},{"type":2108,"url":3259},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Freleases\u002Ftag\u002Fv1.83.7-stable",{"type":2105,"url":2864},{"type":2097,"url":3262},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5jmr-gcrj-2c9q",[2868,2869,2870,2871],{"id":146,"slug":3265,"dossier":45,"summary":3266,"aliases":3267,"sourceIds":3271,"published":3272,"modified":3273,"checkedAt":7,"severity":3274,"references":3281,"versionKeys":3303,"packageCount":32,"repositoryCount":599},"ghsa-5qmp-p3c4-72qj-0f202987","MLflow: Deterministic sampling in dataset digest enables predictable collisions",[3268,3269,3270],"BIT-mlflow-2026-10803","CVE-2026-10803","PYSEC-2026-195",[146,3270],"2026-06-04T12:16:24.440Z","2026-07-23T15:00:15.414047693Z",[3275,3277,3279],{"type":2093,"score":3276},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:L",{"type":2130,"score":3278},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":2130,"score":3280},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[3282,3284,3286,3288,3289,3291,3293,3295,3297,3299,3301],{"type":2097,"url":3283},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-10803",{"type":2465,"url":3285},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fissues\u002F22419",{"type":2465,"url":3287},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F22420",{"type":2105,"url":2679},{"type":2108,"url":3290},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fmlflow\u002FPYSEC-2026-195.yaml",{"type":2097,"url":3292},"https:\u002F\u002Fvuldb.com\u002Fcve\u002FCVE-2026-10803",{"type":2097,"url":3294},"https:\u002F\u002Fvuldb.com\u002Fsubmit\u002F831462",{"type":2097,"url":3296},"https:\u002F\u002Fvuldb.com\u002Fvuln\u002F368252",{"type":2465,"url":3298},"https:\u002F\u002Fvuldb.com\u002Fvuln\u002F368252\u002Fcti",{"type":2108,"url":3300},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002F",{"type":2097,"url":3302},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5qmp-p3c4-72qj",[2687,2688,2689],{"id":147,"slug":3305,"dossier":45,"summary":3306,"aliases":3307,"sourceIds":3311,"published":3312,"modified":3313,"checkedAt":7,"severity":3314,"references":3318,"versionKeys":3335,"packageCount":32,"repositoryCount":599},"ghsa-5rjg-fvgr-3xxf-79d39e6b","setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write",[3308,3309,3310],"BIT-setuptools-2025-47273","CVE-2025-47273","PYSEC-2025-49",[147,3310],"2025-05-17T16:15:19Z","2026-05-11T00:26:34.671259971Z",[3315,3317],{"type":2130,"score":3316},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",{"type":2093,"score":2248},[3319,3321,3323,3325,3327,3329,3331,3333],{"type":2163,"url":3320},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fsecurity\u002Fadvisories\u002FGHSA-5rjg-fvgr-3xxf",{"type":2097,"url":3322},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-47273",{"type":2465,"url":3324},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fissues\u002F4946",{"type":2102,"url":3326},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002F250a6d17978f9f6ac3ac887091f2d32886fbbb0b",{"type":2108,"url":3328},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fsetuptools\u002FPYSEC-2025-49.yaml",{"type":2105,"url":3330},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools",{"type":2108,"url":3332},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fblob\u002F6ead555c5fb29bc57fe6105b1bffc163f56fd558\u002Fsetuptools\u002Fpackage_index.py#L810C1-L825C88",{"type":2111,"url":3334},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F05\u002Fmsg00035.html",[3336,3337,3338],"pypi:setuptools@69.2.0","pypi:setuptools@72.2.0","pypi:setuptools@75.8.0",{"id":148,"slug":3340,"dossier":89,"summary":3341,"aliases":3342,"sourceIds":3346,"published":3347,"modified":3348,"checkedAt":7,"severity":3349,"references":3351,"versionKeys":3361,"packageCount":32,"repositoryCount":2416},"ghsa-5x94-69rx-g8h2-0bc05f88","Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`",[3343,3344,3345],"BIT-pillow-2026-54060","CVE-2026-54060","PYSEC-2026-2254",[148,3345],"2026-07-06T19:17:08.270Z","2026-07-22T02:59:38.824757212Z",[3350],{"type":2093,"score":2277},[3352,3354,3356,3357,3359,3360],{"type":2163,"url":3353},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-5x94-69rx-g8h2",{"type":2097,"url":3355},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54060",{"type":2102,"url":2708},{"type":2108,"url":3358},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2254.yaml",{"type":2105,"url":2712},{"type":2097,"url":2714},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":149,"slug":3363,"dossier":45,"summary":3364,"aliases":3365,"sourceIds":3369,"published":3370,"modified":3371,"checkedAt":7,"severity":3372,"references":3376,"versionKeys":3384,"packageCount":32,"repositoryCount":40},"ghsa-5xmw-vc9v-4wf2-86a8861a","Pillow has a heap buffer overflow with nested list coordinates",[3366,3367,3368],"BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251",[149,3368],"2026-05-04T20:18:27Z","2026-07-13T07:26:28.768890335Z",[3373,3374],{"type":2093,"score":2460},{"type":2130,"score":3375},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[3377,3379,3381,3382],{"type":2097,"url":3378},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-5xmw-vc9v-4wf2",{"type":2097,"url":3380},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42309",{"type":2105,"url":2712},{"type":2097,"url":3383},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F12.2.0",[2719,2720,2721,2722,2723],{"id":150,"slug":3386,"dossier":89,"summary":3387,"aliases":3388,"sourceIds":3392,"published":3393,"modified":3394,"checkedAt":7,"severity":3395,"references":3398,"versionKeys":3414,"packageCount":32,"repositoryCount":2416},"ghsa-62p4-gmf7-7g93-cb81341c","Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)",[3389,3390,3391],"BIT-pillow-2026-54058","CVE-2026-54058","PYSEC-2026-3493",[150,3391],"2026-07-20T21:08:13Z","2026-07-23T15:11:42.568996050Z",[3396],{"type":2130,"score":3397},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[3399,3401,3403,3405,3407,3408,3410,3412],{"type":2108,"url":3400},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-62p4-gmf7-7g93",{"type":2097,"url":3402},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54058",{"type":2108,"url":3404},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9719",{"type":2108,"url":3406},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F6a8de891fb00968e5ea79bfa84368ed90b3cfc1d",{"type":2105,"url":2712},{"type":2108,"url":3409},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F12.3.0",{"type":2105,"url":3411},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fpillow",{"type":2097,"url":3413},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-62p4-gmf7-7g93",[2716,2717,2718,2719,2720,2721,2722,2723],{"id":151,"slug":3416,"dossier":45,"summary":3417,"aliases":3418,"sourceIds":3421,"published":3422,"modified":3423,"checkedAt":7,"severity":3424,"references":3430,"versionKeys":3441,"packageCount":32,"repositoryCount":2294},"ghsa-63hf-3vf5-4wqf-aadd9f0f","AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection\u002Fsecurity bypass",[3419,3420],"CVE-2026-34520","PYSEC-2026-2102",[151,3420],"2026-04-01T21:17:00.333Z","2026-07-15T22:00:51.319409225Z",[3425,3427,3428],{"type":2093,"score":3426},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",{"type":2130,"score":2371},{"type":2130,"score":3429},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[3431,3433,3435,3437,3438,3439],{"type":2102,"url":3432},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-63hf-3vf5-4wqf",{"type":2097,"url":3434},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34520",{"type":2102,"url":3436},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F9370b9714a7a56003cacd31a9b4ae16eab109ba4",{"type":2105,"url":2282},{"type":2097,"url":2383},{"type":2108,"url":3440},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Faiohttp\u002FPYSEC-2026-2102.yaml",[2286,2287,2288,2289,2290,2291,2292,2293],{"id":152,"slug":3443,"dossier":45,"summary":3444,"aliases":3445,"sourceIds":3448,"published":3449,"modified":3450,"checkedAt":7,"severity":3451,"references":3454,"versionKeys":3460,"packageCount":32,"repositoryCount":2294},"ghsa-63hw-fmq6-xxg2-00aac622","aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines",[3446,3447],"CVE-2026-54277","PYSEC-2026-2110",[152,3447],"2026-06-15T20:09:16Z","2026-07-13T07:26:29.010491244Z",[3452,3453],{"type":2130,"score":2831},{"type":2093,"score":2277},[3455,3457,3459],{"type":2097,"url":3456},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-63hw-fmq6-xxg2",{"type":2102,"url":3458},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F5ab61bb4cd88f19b712f12c7c9295fe262bf804d",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":153,"slug":3462,"dossier":45,"summary":3463,"aliases":3464,"sourceIds":3467,"published":3468,"modified":3469,"checkedAt":7,"severity":3470,"references":3472,"versionKeys":3513,"packageCount":32,"repositoryCount":540},"ghsa-63vm-454h-vhhq-296aa7fc","pyasn1 has a DoS vulnerability in decoder",[3465,3466],"CVE-2026-23490","PYSEC-2026-1810",[153,3466],"2026-01-16T19:19:25Z","2026-07-21T15:30:39.563600361Z",[3471],{"type":2093,"score":2277},[3473,3475,3477,3479,3481,3483,3485,3487,3489,3491,3493,3495,3497,3499,3501,3503,3505,3507,3509,3511],{"type":2108,"url":3474},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fsecurity\u002Fadvisories\u002FGHSA-63vm-454h-vhhq",{"type":2097,"url":3476},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-23490",{"type":2108,"url":3478},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002Fbe353d755f42ea36539b4f5053c652ddf56979a6",{"type":2108,"url":3480},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002F3908f144229eed4df24bd569d16e5991ace44970",{"type":2108,"url":3482},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4148",{"type":2108,"url":3484},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4147",{"type":2108,"url":3486},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4146",{"type":2108,"url":3488},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4145",{"type":2108,"url":3490},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4144",{"type":2108,"url":3492},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4143",{"type":2108,"url":3494},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4142",{"type":2108,"url":3496},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4141",{"type":2108,"url":3498},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4140",{"type":2108,"url":3500},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4139",{"type":2108,"url":3502},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4138",{"type":2108,"url":3504},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:39894",{"type":2105,"url":3506},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1",{"type":2108,"url":3508},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fblob\u002F0f07d7242a78ab4d129b26256d7474f7168cf536\u002Fpyasn1\u002Fcodec\u002Fber\u002Fdecoder.py#L496",{"type":2108,"url":3510},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Freleases\u002Ftag\u002Fv0.6.2",{"type":2108,"url":3512},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F02\u002Fmsg00002.html",[3514],"pypi:pyasn1@0.6.1",{"id":154,"slug":3516,"dossier":45,"summary":3517,"aliases":3518,"sourceIds":3522,"published":3523,"modified":3524,"checkedAt":7,"severity":3525,"references":3528,"versionKeys":3538,"packageCount":32,"repositoryCount":599},"ghsa-65h7-c7c4-mghx-fc09466d","MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability",[3519,3520,3521],"BIT-mlflow-2026-2393","CVE-2026-2393","PYSEC-2026-2219",[154,3521],"2026-05-11T18:16:31.500Z","2026-07-13T16:45:08.114491424Z",[3526],{"type":2093,"score":3527},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[3529,3531,3533,3534,3536],{"type":2097,"url":3530},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2393",{"type":2102,"url":3532},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F64aa0ab7207f9c649b59ba1a5f40d82196817389",{"type":2105,"url":2679},{"type":2163,"url":3535},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F04ef100d-06b5-4a70-95b1-b7be23aa8150",{"type":2097,"url":3537},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-65h7-c7c4-mghx",[2687,2688,2689],{"id":155,"slug":3540,"dossier":89,"summary":3541,"aliases":3542,"sourceIds":3545,"published":3546,"modified":3547,"checkedAt":7,"severity":3548,"references":3552,"versionKeys":3561,"packageCount":32,"repositoryCount":3565},"ghsa-65pc-fj4g-8rjx-9fe9e88a","Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix",[3543,3544],"CVE-2026-45409","PYSEC-2026-215",[155,3544],"2026-05-19T14:34:32Z","2026-07-08T17:45:15.021597323Z",[3549,3550],{"type":2093,"score":2188},{"type":2130,"score":3551},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[3553,3555,3557,3559],{"type":2097,"url":3554},"https:\u002F\u002Fgithub.com\u002Fkjd\u002Fidna\u002Fsecurity\u002Fadvisories\u002FGHSA-65pc-fj4g-8rjx",{"type":2097,"url":3556},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45409",{"type":2105,"url":3558},"https:\u002F\u002Fgithub.com\u002Fkjd\u002Fidna",{"type":2108,"url":3560},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fidna\u002FPYSEC-2026-215.yaml",[3562,3563,3564],"pypi:idna@3.10","pypi:idna@3.11","pypi:idna@3.7",17,{"id":156,"slug":3567,"dossier":45,"summary":3568,"aliases":3569,"sourceIds":3572,"published":3573,"modified":3574,"checkedAt":7,"severity":3575,"references":3580,"versionKeys":3590,"packageCount":32,"repositoryCount":599},"ghsa-68j8-pq59-fqgm-94af8991","NLTK has a Path Traversal issue",[3570,3571],"CVE-2026-0847","PYSEC-2026-98",[156,3571],"2026-03-04T19:16:10.683Z","2026-06-10T17:02:23.764228465Z",[3576,3578],{"type":2093,"score":3577},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:L\u002FA:L",{"type":2093,"score":3579},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[3581,3583,3584,3586,3588],{"type":2097,"url":3582},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0847",{"type":2105,"url":2744},{"type":2108,"url":3585},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fnltk\u002FPYSEC-2026-98.yaml",{"type":2163,"url":3587},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Ffc69914f-36a9-4c18-8503-10013b39f966",{"type":2097,"url":3589},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-68j8-pq59-fqgm",[2758,2759],{"id":157,"slug":3592,"dossier":45,"summary":3593,"aliases":3594,"sourceIds":3597,"published":3598,"modified":3599,"checkedAt":7,"severity":3600,"references":3605,"versionKeys":3616,"packageCount":32,"repositoryCount":64},"ghsa-68rp-wp8r-4726-c59718b4","Flask session does not add `Vary: Cookie` header when accessed in some ways",[3595,3596],"CVE-2026-27205","PYSEC-2026-2151",[157,3596],"2026-02-19T20:45:41Z","2026-07-13T07:26:21.445447696Z",[3601,3603],{"type":2130,"score":3602},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:P\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":3604},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[3606,3608,3610,3612,3614],{"type":2097,"url":3607},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fflask\u002Fsecurity\u002Fadvisories\u002FGHSA-68rp-wp8r-4726",{"type":2097,"url":3609},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-27205",{"type":2102,"url":3611},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fflask\u002Fcommit\u002F089cb86dd22bff589a4eafb7ab8e42dc357623b4",{"type":2105,"url":3613},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fflask",{"type":2097,"url":3615},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fflask\u002Freleases\u002Ftag\u002F3.1.3",[3617,3618,3619,3620],"pypi:flask@3.0.2","pypi:flask@3.0.3","pypi:flask@3.1.1","pypi:flask@3.1.2",{"id":158,"slug":3622,"dossier":45,"summary":3623,"aliases":3624,"sourceIds":3627,"published":3628,"modified":3629,"checkedAt":7,"severity":3630,"references":3632,"versionKeys":3643,"packageCount":32,"repositoryCount":540},"ghsa-69f9-5gxw-wvc2-eec14573","AIOHTTP's unicode processing of header values could cause parsing discrepancies",[3625,3626],"CVE-2025-69224","PYSEC-2026-1099",[158,3626],"2026-01-05T22:58:57Z","2026-07-07T17:56:40.774148412Z",[3631],{"type":2130,"score":2371},[3633,3635,3637,3639,3640,3641],{"type":2108,"url":3634},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-69f9-5gxw-wvc2",{"type":2097,"url":3636},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69224",{"type":2102,"url":3638},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F32677f2adfd907420c078dda6b79225c6f4ebce0",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":3642},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-69f9-5gxw-wvc2",[2286,2287,2288,2289,2290,2291,2292],{"id":159,"slug":3645,"dossier":45,"summary":3646,"aliases":3647,"sourceIds":3650,"published":3651,"modified":3652,"checkedAt":7,"severity":3653,"references":3658,"versionKeys":3670,"packageCount":32,"repositoryCount":530},"ghsa-69w3-r845-3855-1b4edc28","HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class",[3648,3649],"CVE-2026-1839","PYSEC-2026-2288",[159,3649],"2026-04-07T06:16:41.490Z","2026-07-13T16:45:06.516869221Z",[3654,3656],{"type":2093,"score":3655},"CVSS:3.0\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:H",{"type":2093,"score":3657},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[3659,3661,3663,3664,3666,3668],{"type":2097,"url":3660},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-1839",{"type":2102,"url":3662},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F03c8082ba4594c9b8d6fe190ca9bed0e5f8ca396",{"type":2105,"url":2161},{"type":2108,"url":3665},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Freleases\u002Ftag\u002Fv5.0.0rc3",{"type":2163,"url":3667},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F3c77bb97-e493-493d-9a88-c57f5c536485",{"type":2097,"url":3669},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-69w3-r845-3855",[2168,2169,2170,2171,2172,2173,2174],{"id":160,"slug":3672,"dossier":45,"summary":3673,"aliases":3674,"sourceIds":3675,"published":3676,"modified":3677,"checkedAt":7,"severity":3678,"references":3681,"versionKeys":3685,"packageCount":32,"repositoryCount":34},"ghsa-69x8-hrgq-fjj8-13befa28","LiteLLM: Password hash exposure and pass-the-hash authentication bypass",[],[160],"2026-04-08T00:04:12Z","2026-04-17T01:29:14.845270912Z",[3679],{"type":2130,"score":3680},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3682,3684],{"type":2108,"url":3683},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-69x8-hrgq-fjj8",{"type":2105,"url":2860},[2868,2869,2870,2871],{"id":161,"slug":3687,"dossier":45,"summary":3688,"aliases":3689,"sourceIds":3692,"published":3693,"modified":3694,"checkedAt":7,"severity":3695,"references":3697,"versionKeys":3707,"packageCount":32,"repositoryCount":599},"ghsa-6hm5-jgcp-p838-200e0a21","Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)",[3690,3691],"CVE-2026-12072","PYSEC-2026-3581",[161,3691],"2026-07-31T16:50:55Z","2026-08-06T15:11:53.284323541Z",[3696],{"type":2093,"score":3579},[3698,3700,3701,3703,3705],{"type":2108,"url":3699},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-6hm5-jgcp-p838",{"type":2105,"url":2744},{"type":2105,"url":3702},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fnltk",{"type":2097,"url":3704},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6hm5-jgcp-p838",{"type":2097,"url":3706},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-12072",[2758,2759],{"id":162,"slug":3709,"dossier":45,"summary":3710,"aliases":3711,"sourceIds":3714,"published":3715,"modified":3716,"checkedAt":7,"severity":3717,"references":3719,"versionKeys":3730,"packageCount":32,"repositoryCount":540},"ghsa-6jhg-hg63-jvvf-74cd77d8","AIOHTTP vulnerable to  denial of service through large payloads",[3712,3713],"CVE-2025-69228","PYSEC-2026-1100",[162,3713],"2026-01-05T23:13:14Z","2026-07-07T17:57:35.249454020Z",[3718],{"type":2130,"score":2831},[3720,3722,3724,3726,3727,3728],{"type":2108,"url":3721},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-6jhg-hg63-jvvf",{"type":2097,"url":3723},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69228",{"type":2102,"url":3725},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fb7dbd35375aedbcd712cbae8ad513d56d11cce60",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":3729},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6jhg-hg63-jvvf",[2286,2287,2288,2289,2290,2291,2292],{"id":163,"slug":3732,"dossier":45,"summary":3733,"aliases":3734,"sourceIds":3737,"published":3738,"modified":3739,"checkedAt":7,"severity":3740,"references":3742,"versionKeys":3753,"packageCount":32,"repositoryCount":540},"ghsa-6mq8-rvhq-8wgg-d94d738f","AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb",[3735,3736],"CVE-2025-69223","PYSEC-2026-1101",[163,3736],"2026-01-05T22:58:41Z","2026-07-07T17:56:11.402262091Z",[3741],{"type":2093,"score":2277},[3743,3745,3747,3749,3750,3751],{"type":2108,"url":3744},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-6mq8-rvhq-8wgg",{"type":2097,"url":3746},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69223",{"type":2102,"url":3748},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F2b920c39002cee0ec5b402581779bbaaf7c9138a",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":3752},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6mq8-rvhq-8wgg",[2286,2287,2288,2289,2290,2291,2292],{"id":164,"slug":3755,"dossier":45,"summary":3756,"aliases":3757,"sourceIds":3758,"published":3759,"modified":3760,"checkedAt":7,"severity":3761,"references":3764,"versionKeys":3774,"packageCount":32,"repositoryCount":34},"ghsa-6p8h-3wgx-97gf-635a010c","GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks",[],[164],"2026-07-24T16:42:09Z","2026-07-25T21:44:40.055637633Z",[3762],{"type":2093,"score":3763},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[3765,3767,3769,3771,3772],{"type":2108,"url":3766},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-6p8h-3wgx-97gf",{"type":2108,"url":3768},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2180",{"type":2108,"url":3770},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fffcb5359e87619f4fe4a70a4aff5f08c5580ba97",{"type":2105,"url":2257},{"type":2108,"url":3773},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.54",[2261,2262,2263],{"id":165,"slug":3776,"dossier":89,"summary":3777,"aliases":3778,"sourceIds":3782,"published":3783,"modified":3784,"checkedAt":7,"severity":3785,"references":3787,"versionKeys":3800,"packageCount":32,"repositoryCount":2416},"ghsa-6r8x-57c9-28j4-3a620dbf","Pillow: Heap out-of-bounds write `Image.paste()` \u002F `Image.crop()` via signed coordinate overflow",[3779,3780,3781],"BIT-pillow-2026-59199","CVE-2026-59199","PYSEC-2026-3451",[165,3781],"2026-07-14T16:17:01.937Z","2026-07-22T02:59:40.188047466Z",[3786],{"type":2093,"score":2277},[3788,3790,3792,3794,3796,3798,3799],{"type":2163,"url":3789},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-6r8x-57c9-28j4",{"type":2097,"url":3791},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59199",{"type":2102,"url":3793},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9703",{"type":2102,"url":3795},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",{"type":2108,"url":3797},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3451.yaml",{"type":2105,"url":2712},{"type":2097,"url":3409},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":166,"slug":3802,"dossier":45,"summary":3803,"aliases":3804,"sourceIds":3807,"published":3808,"modified":3809,"checkedAt":7,"severity":3810,"references":3812,"versionKeys":3823,"packageCount":32,"repositoryCount":32},"ghsa-6rvg-6v2m-4j46-e04ee614","Transformers Regular Expression Denial of Service (ReDoS) vulnerability",[3805,3806],"CVE-2024-12720","PYSEC-2026-1982",[166,3806],"2025-03-20T12:32:43Z","2026-07-07T17:56:13.229192922Z",[3811],{"type":2093,"score":2921},[3813,3815,3817,3818,3820,3821],{"type":2097,"url":3814},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-12720",{"type":2108,"url":3816},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fdeac971c469bcbb182c2e52da0b82fb3bf54cccf",{"type":2105,"url":2161},{"type":2108,"url":3819},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F4bed1214-7835-4252-a853-22bbad891f98",{"type":2105,"url":2509},{"type":2097,"url":3822},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6rvg-6v2m-4j46",[2168],{"id":167,"slug":3825,"dossier":45,"summary":3826,"aliases":3827,"sourceIds":3830,"published":3831,"modified":3832,"checkedAt":7,"severity":3833,"references":3836,"versionKeys":3849,"packageCount":32,"repositoryCount":599},"ghsa-6vgw-5pg2-w6jp-57c7d3f5","pip Path Traversal vulnerability",[3828,3829],"CVE-2026-1703","PYSEC-2026-1796",[167,3829],"2026-02-02T15:30:34Z","2026-07-07T17:56:16.480954738Z",[3834],{"type":2130,"score":3835},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:A\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3837,3839,3841,3843,3844,3846,3847],{"type":2097,"url":3838},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-1703",{"type":2108,"url":3840},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fpull\u002F13777",{"type":2108,"url":3842},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fcommit\u002F8e227a9be4faa9594e05d02ca05a413a2a4e7735",{"type":2105,"url":3010},{"type":2108,"url":3845},"https:\u002F\u002Fmail.python.org\u002Farchives\u002Flist\u002Fsecurity-announce@python.org\u002Fthread\u002FWIEA34D4TABF2UNQJAOMXKCICSPBE2DJ",{"type":2105,"url":3018},{"type":2097,"url":3848},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6vgw-5pg2-w6jp",[3022,3023],{"id":168,"slug":3851,"dossier":45,"summary":3852,"aliases":3853,"sourceIds":3856,"published":3857,"modified":3858,"checkedAt":7,"severity":3859,"references":3862,"versionKeys":3875,"packageCount":32,"repositoryCount":34},"ghsa-72m8-9m7m-h278-09927b5d","LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks",[3854,3855],"CVE-2026-59821","PYSEC-2026-3478",[168,3855],"2026-07-22T22:38:55Z","2026-07-23T15:11:26.912539142Z",[3860],{"type":2130,"score":3861},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:H\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[3863,3865,3867,3869,3870,3872,3873],{"type":2108,"url":3864},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-72m8-9m7m-h278",{"type":2097,"url":3866},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59821",{"type":2108,"url":3868},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002Fe50b4486d0f7aa0497185a1ebcdd2c91f1769eba",{"type":2105,"url":2860},{"type":2108,"url":3871},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Freleases\u002Ftag\u002Fv1.82.0-stable",{"type":2105,"url":2864},{"type":2097,"url":3874},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-72m8-9m7m-h278",[2868,2869,2870,2871],{"id":169,"slug":3877,"dossier":45,"summary":3878,"aliases":3879,"sourceIds":3882,"published":3883,"modified":3884,"checkedAt":7,"severity":3885,"references":3888,"versionKeys":3902,"packageCount":32,"repositoryCount":34},"ghsa-7488-6r32-c95q-deb7c5f3","LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback",[3880,3881],"CVE-2026-59822","PYSEC-2026-3479",[169,3881],"2026-07-22T22:38:33Z","2026-07-23T15:11:29.132983365Z",[3886],{"type":2130,"score":3887},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[3889,3891,3893,3895,3897,3898,3899,3900],{"type":2108,"url":3890},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-7488-6r32-c95q",{"type":2097,"url":3892},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59822",{"type":2108,"url":3894},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fpull\u002F26463",{"type":2108,"url":3896},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002F73869f0faf7d11ee21adcb5f91b8c33a340b6c2c",{"type":2105,"url":2860},{"type":2108,"url":3049},{"type":2105,"url":2864},{"type":2097,"url":3901},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7488-6r32-c95q",[2868,2869,2870,2871],{"id":170,"slug":3904,"dossier":45,"summary":3905,"aliases":3906,"sourceIds":3909,"published":3910,"modified":3911,"checkedAt":7,"severity":3912,"references":3917,"versionKeys":3925,"packageCount":32,"repositoryCount":34},"ghsa-7545-fcxq-7j24-84dd19fd","GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository",[3907,3908],"CVE-2026-44243","PYSEC-2026-2162",[170,3908],"2026-05-06T19:38:48Z","2026-07-13T07:26:30.186818349Z",[3913,3915],{"type":2093,"score":3914},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",{"type":2130,"score":3916},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[3918,3920,3922,3923],{"type":2163,"url":3919},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-7545-fcxq-7j24",{"type":2097,"url":3921},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44243",{"type":2105,"url":2257},{"type":2102,"url":3924},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.48",[2261,2262,2263],{"id":171,"slug":3927,"dossier":45,"summary":3928,"aliases":3929,"sourceIds":3933,"published":3934,"modified":3935,"checkedAt":7,"severity":3936,"references":3939,"versionKeys":3949,"packageCount":32,"repositoryCount":599},"ghsa-75cm-x2w3-8mgf-213b4d71","MLflow: unauthenticated access to certain FastAPI routes",[3930,3931,3932],"BIT-mlflow-2026-2652","CVE-2026-2652","PYSEC-2026-2221",[171,3932],"2026-05-15T03:16:23.127Z","2026-07-13T16:45:09.381556404Z",[3937],{"type":2093,"score":3938},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:H\u002FA:L",[3940,3942,3944,3945,3947],{"type":2097,"url":3941},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2652",{"type":2102,"url":3943},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002Fbb62e773263c14e9ba4d1a82fe72d0de2442c6aa",{"type":2105,"url":2679},{"type":2163,"url":3946},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F5aeff5f0-49c7-4180-b5cb-c9a046f16756",{"type":2097,"url":3948},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-75cm-x2w3-8mgf",[2687,2688,2689],{"id":172,"slug":3951,"dossier":45,"summary":3952,"aliases":3953,"sourceIds":3956,"published":3957,"modified":3958,"checkedAt":7,"severity":3959,"references":3962,"versionKeys":3975,"packageCount":32,"repositoryCount":64},"ghsa-768j-98cg-p3fv-0815ff07","fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib",[3954,3955],"CVE-2025-66034","PYSEC-2026-1389",[172,3955],"2025-12-01T19:07:00Z","2026-07-07T17:57:24.966058048Z",[3960],{"type":2093,"score":3961},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:C\u002FC:N\u002FI:H\u002FA:L",[3963,3965,3967,3969,3971,3973],{"type":2108,"url":3964},"https:\u002F\u002Fgithub.com\u002Ffonttools\u002Ffonttools\u002Fsecurity\u002Fadvisories\u002FGHSA-768j-98cg-p3fv",{"type":2097,"url":3966},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66034",{"type":2108,"url":3968},"https:\u002F\u002Fgithub.com\u002Ffonttools\u002Ffonttools\u002Fcommit\u002Fa696d5ba93270d5954f98e7cab5ddca8a02c1e32",{"type":2105,"url":3970},"https:\u002F\u002Fgithub.com\u002Ffonttools\u002Ffonttools",{"type":2105,"url":3972},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ffonttools",{"type":2097,"url":3974},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-768j-98cg-p3fv",[3976,3977,3978,3979,3980],"pypi:fonttools@4.55.3","pypi:fonttools@4.57.0","pypi:fonttools@4.58.0","pypi:fonttools@4.58.5","pypi:fonttools@4.59.2",{"id":173,"slug":3982,"dossier":45,"summary":3983,"aliases":3984,"sourceIds":3988,"published":3989,"modified":3990,"checkedAt":7,"severity":3991,"references":3997,"versionKeys":4009,"packageCount":32,"repositoryCount":64},"ghsa-78cv-mqj4-43f7-2021f695","Tornado has incomplete validation of cookie attributes",[3985,3986,3987],"CVE-2026-35536","GHSA-fqwm-6jpj-5wxc","PYSEC-2026-2287",[173,3986,3987],"2026-03-11T22:17:00Z","2026-07-13T16:45:06.531920939Z",[3992,3994,3996],{"type":2093,"score":3993},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:N",{"type":2093,"score":3995},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N",{"type":2093,"score":2373},[3998,4000,4002,4003,4005,4007],{"type":2097,"url":3999},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-78cv-mqj4-43f7",{"type":2108,"url":4001},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F24a2d96ea115f663b223887deb0060f13974c104",{"type":2105,"url":2647},{"type":2108,"url":4004},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.5",{"type":2097,"url":4006},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-35536",{"type":2097,"url":4008},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fqwm-6jpj-5wxc",[2655,2656,2657,2658],{"id":174,"slug":4011,"dossier":45,"summary":4012,"aliases":4013,"sourceIds":4016,"published":4017,"modified":4018,"checkedAt":7,"severity":4019,"references":4021,"versionKeys":4034,"packageCount":32,"repositoryCount":618},"ghsa-7cx3-6m66-7c5m-cde5125c","Tornado vulnerable to excessive logging caused by malformed multipart form data",[4014,4015],"CVE-2025-47287","PYSEC-2026-1974",[174,4015],"2025-05-16T14:12:40Z","2026-07-07T17:56:45.268719923Z",[4020],{"type":2093,"score":2277},[4022,4024,4026,4028,4029,4031,4032],{"type":2108,"url":4023},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-7cx3-6m66-7c5m",{"type":2097,"url":4025},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-47287",{"type":2108,"url":4027},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002Fb39b892bf78fe8fea01dd45199aa88307e7162f3",{"type":2105,"url":2647},{"type":2108,"url":4030},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F05\u002Fmsg00038.html",{"type":2105,"url":2649},{"type":2097,"url":4033},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7cx3-6m66-7c5m",[2655],{"id":175,"slug":4036,"dossier":45,"summary":4037,"aliases":4038,"sourceIds":4041,"published":4042,"modified":4043,"checkedAt":7,"severity":4044,"references":4046,"versionKeys":4063,"packageCount":32,"repositoryCount":568},"ghsa-7f5h-v6xp-fcq8-9393173e","Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``",[4039,4040],"CVE-2025-62727","PYSEC-2026-1942",[175,4040],"2025-10-28T20:38:01Z","2026-07-07T17:56:07.620081354Z",[4045],{"type":2093,"score":2277},[4047,4049,4051,4053,4056,4058,4060,4061],{"type":2108,"url":4048},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-7f5h-v6xp-fcq8",{"type":2097,"url":4050},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-62727",{"type":2102,"url":4052},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fcommit\u002F4ea6e22b489ec388d6004cfbca52dd5b147127c5",{"type":4054,"url":4055},"INTRODUCED","https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fcommit\u002F69ed26a85956ef4bd0161807eb27abf49be7cd3c",{"type":2105,"url":4057},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette",{"type":2108,"url":4059},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Freleases\u002Ftag\u002F0.49.1",{"type":2105,"url":2231},{"type":2097,"url":4062},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7f5h-v6xp-fcq8",[2236,2237,4064,4065],"pypi:starlette@0.47.3","pypi:starlette@0.49.0",{"id":176,"slug":4067,"dossier":45,"summary":4068,"aliases":4069,"sourceIds":4072,"published":4073,"modified":4074,"checkedAt":7,"severity":4075,"references":4078,"versionKeys":4095,"packageCount":32,"repositoryCount":40},"ghsa-7gcm-g887-7qv7-55bb9ff1","protobuf affected by a JSON recursion depth bypass",[4070,4071],"CVE-2026-0994","PYSEC-2026-1805",[176,4071],"2026-01-23T15:31:35Z","2026-07-07T17:56:36.712428283Z",[4076],{"type":2130,"score":4077},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:L",[4079,4081,4083,4085,4087,4089,4091,4093],{"type":2097,"url":4080},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0994",{"type":2108,"url":4082},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fissues\u002F25070",{"type":2108,"url":4084},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fpull\u002F25239",{"type":2108,"url":4086},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002F5ebddcb1bcbe51d1fe323baa145e85f4f23128cf",{"type":2108,"url":4088},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002Fd2b001626d137c62dfee6c88c87324102531868b",{"type":2105,"url":4090},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf",{"type":2105,"url":4092},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fprotobuf",{"type":2097,"url":4094},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7gcm-g887-7qv7",[4096,4097,4098,4099,4100,4101,4102,4103,4104],"pypi:protobuf@4.25.7","pypi:protobuf@4.25.8","pypi:protobuf@5.29.3","pypi:protobuf@5.29.4","pypi:protobuf@6.31.1","pypi:protobuf@6.32.0","pypi:protobuf@6.33.0","pypi:protobuf@6.33.1","pypi:protobuf@6.33.4",{"id":177,"slug":4106,"dossier":45,"summary":4107,"aliases":4108,"sourceIds":4111,"published":4112,"modified":4113,"checkedAt":7,"severity":4114,"references":4117,"versionKeys":4133,"packageCount":32,"repositoryCount":599},"ghsa-7p94-766c-hgjp-50b78c94","NLTK has a Zip Slip Vulnerability",[4109,4110],"CVE-2025-14009","PYSEC-2026-96",[177,4110],"2026-02-18T18:24:19.410Z","2026-06-10T17:02:23.646726882Z",[4115],{"type":2093,"score":4116},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[4118,4120,4122,4124,4125,4127,4129,4131],{"type":2097,"url":4119},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-14009",{"type":2108,"url":4121},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fpull\u002F3468",{"type":2108,"url":4123},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002F1056b323af6462455571302e766b67cf300aea18",{"type":2105,"url":2744},{"type":2108,"url":4126},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fblob\u002F4154eb85e832f266660a09286c7e37e308292284\u002FChangeLog#L1",{"type":2108,"url":4128},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fnltk\u002FPYSEC-2026-96.yaml",{"type":2163,"url":4130},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F49ecbc02-054e-4470-b2e0-b267936cc4e4",{"type":2097,"url":4132},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7p94-766c-hgjp",[2758,2759],{"id":178,"slug":4135,"dossier":45,"summary":4136,"aliases":4137,"sourceIds":4140,"published":4141,"modified":4142,"checkedAt":7,"severity":4143,"references":4146,"versionKeys":4155,"packageCount":32,"repositoryCount":599},"ghsa-7qhf-v65m-g5f3-235f2d72","mlflow: FastAPI job endpoints under `\u002Fajax-api\u002F3.0\u002Fjobs\u002F*` are not protected by authentication or authorization",[4138,4139],"CVE-2026-0545","PYSEC-2026-419",[178,4139],"2026-04-03T18:31:23Z","2026-07-01T20:22:58.301401Z",[4144],{"type":2093,"score":4145},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[4147,4149,4150,4152,4153],{"type":2097,"url":4148},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0545",{"type":2105,"url":2679},{"type":2108,"url":4151},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fb2e5b028-9541-4d29-8703-a76f1a3734d8",{"type":2105,"url":2683},{"type":2097,"url":4154},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-7qhf-v65m-g5f3",[2687,2688,2689],{"id":179,"slug":4157,"dossier":45,"summary":4158,"aliases":4159,"sourceIds":4162,"published":4163,"modified":4164,"checkedAt":7,"severity":4165,"references":4167,"versionKeys":4171,"packageCount":32,"repositoryCount":530},"ghsa-82w8-qh3p-5jfq-a05ef51e","Starlette: request.form() limits silently ignored for application\u002Fx-www-form-urlencoded enable DoS",[4160,4161],"CVE-2026-54283","PYSEC-2026-249",[179,4161],"2026-06-15T20:39:53Z","2026-06-27T11:26:15.727496147Z",[4166],{"type":2093,"score":2277},[4168,4170],{"type":2097,"url":4169},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-82w8-qh3p-5jfq",{"type":2105,"url":4057},[2235,2236,2237,4064,4065,4172,4173],"pypi:starlette@0.49.3","pypi:starlette@0.50.0",{"id":180,"slug":4175,"dossier":45,"summary":4176,"aliases":4177,"sourceIds":4180,"published":4181,"modified":4182,"checkedAt":7,"severity":4183,"references":4190,"versionKeys":4208,"packageCount":32,"repositoryCount":599},"ghsa-848c-c2cx-j7qx-0ad88ce5","NLTK vulnerable to Eval Injection via collocations CLI arguments",[4178,4179],"CVE-2025-71408","PYSEC-2026-3657",[180,4179],"2026-07-24T22:16:50.063Z","2026-08-12T19:59:11.940439452Z",[4184,4186,4188],{"type":2093,"score":4185},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2130,"score":4187},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2130,"score":4189},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[4191,4193,4195,4197,4199,4200,4202,4204,4206],{"type":2097,"url":4192},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-71408",{"type":2102,"url":4194},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fpull\u002F3465",{"type":2102,"url":4196},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002F66f14096d952ec8f04934f515e027534bd4eb0ac",{"type":2108,"url":4198},"https:\u002F\u002Faydinnyunus.github.io\u002F2026\u002F06\u002F07\u002Fcommand-injection-nltk-collocations-eval",{"type":2105,"url":2744},{"type":2097,"url":4201},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Freleases\u002Ftag\u002F3.9.3",{"type":2108,"url":4203},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fnltk\u002FPYSEC-2026-3657.yaml",{"type":2102,"url":4205},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fnltk-eval-injection-via-collocations-py-command-line-arguments",{"type":2163,"url":4207},"https:\u002F\u002Faydinnyunus.github.io\u002F2026\u002F06\u002F07\u002Fcommand-injection-nltk-collocations-eval\u002F",[2758,2759],{"id":181,"slug":4210,"dossier":45,"summary":4211,"aliases":4212,"sourceIds":4216,"published":4217,"modified":4218,"checkedAt":7,"severity":4219,"references":4221,"versionKeys":4258,"packageCount":32,"repositoryCount":530},"ghsa-86qp-5c8j-p5mr-13e563cb","Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks",[4213,4214,4215],"CVE-2026-48710","PYSEC-2026-161","X41-2026-002",[181,4214],"2026-05-22T13:10:03Z","2026-08-07T12:46:17.536847233Z",[4220],{"type":2093,"score":2571},[4222,4224,4226,4228,4230,4232,4234,4236,4238,4240,4241,4243,4246,4248,4250,4252,4254,4256],{"type":2097,"url":4223},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-86qp-5c8j-p5mr",{"type":2097,"url":4225},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-48710",{"type":2102,"url":4227},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fcommit\u002F764dab0dcfb9033d75442d7a359645c9f94648c6",{"type":2108,"url":4229},"https:\u002F\u002Fwww.x41-dsec.de\u002Flab\u002Fadvisories\u002Fx41-2026-002-starlette",{"type":2111,"url":4231},"https:\u002F\u002Fwww.secwest.net\u002Fstarlette",{"type":2108,"url":4233},"https:\u002F\u002Fwww.cve.org\u002FCVERecord?id=CVE-2026-48710",{"type":2108,"url":4235},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-48710.json",{"type":2108,"url":4237},"https:\u002F\u002Fostif.org\u002Fdisclosing-the-badhost-vulnerability-in-starlette",{"type":2108,"url":4239},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fstarlette\u002FPYSEC-2026-161.yaml",{"type":2105,"url":4057},{"type":2108,"url":4242},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2481742",{"type":4244,"url":4245},"DETECTION","https:\u002F\u002Fbadhost.org\u002F",{"type":2108,"url":4247},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-48710",{"type":2108,"url":4249},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:51357",{"type":2108,"url":4251},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:44696",{"type":2108,"url":4253},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:43038",{"type":2111,"url":4255},"https:\u002F\u002Fostif.org\u002Fdisclosing-the-badhost-vulnerability-in-starlette\u002F",{"type":2097,"url":4257},"https:\u002F\u002Fwww.x41-dsec.de\u002Flab\u002Fadvisories\u002Fx41-2026-002-starlette\u002F",[2235,2236,2237,4064,4065,4172,4173],{"id":182,"slug":4260,"dossier":45,"summary":4261,"aliases":4262,"sourceIds":4265,"published":4266,"modified":4267,"checkedAt":7,"severity":4268,"references":4271,"versionKeys":4282,"packageCount":32,"repositoryCount":568},"ghsa-87hc-h4r5-73f7-c5117ca2","Werkzeug safe_join() allows Windows special device names with compound extensions",[4263,4264],"CVE-2026-21860","PYSEC-2026-2044",[182,4264],"2026-01-08T19:51:21Z","2026-07-07T17:56:19.044748151Z",[4269,4270],{"type":2093,"score":2188},{"type":2130,"score":2186},[4272,4274,4276,4278,4279,4280],{"type":2108,"url":4273},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fsecurity\u002Fadvisories\u002FGHSA-87hc-h4r5-73f7",{"type":2097,"url":4275},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-21860",{"type":2108,"url":4277},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002F7ae1d254e04a0c33e241ac1cca4783ce6c875ca3",{"type":2105,"url":2197},{"type":2105,"url":2324},{"type":2097,"url":4281},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-87hc-h4r5-73f7",[2201,2202,2203,2204],{"id":183,"slug":4284,"dossier":45,"summary":4285,"aliases":4286,"sourceIds":4290,"published":4291,"modified":4292,"checkedAt":7,"severity":4293,"references":4297,"versionKeys":4319,"packageCount":32,"repositoryCount":540},"ghsa-887c-mr87-cxwp-233a2961","PyTorch Improper Resource Shutdown or Release vulnerability",[4287,4288,4289],"BIT-pytorch-2025-3730","CVE-2025-3730","PYSEC-2026-1970",[183,4289],"2025-04-16T21:30:59Z","2026-08-07T08:11:51.496178283Z",[4294,4295],{"type":2093,"score":2456},{"type":2130,"score":4296},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[4298,4300,4302,4304,4306,4308,4309,4311,4313,4315,4317],{"type":2097,"url":4299},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3730",{"type":2108,"url":4301},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F150835",{"type":2108,"url":4303},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F150981",{"type":2108,"url":4305},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F01f226bfb8f2c343f5c614a6bbf685d91160f3af",{"type":2108,"url":4307},"https:\u002F\u002Fgithub.com\u002Ftimocafe\u002Ftewart-pytorch\u002Fcommit\u002F46fc5d8e360127361211cb237d5f9eef0223e567",{"type":2105,"url":2472},{"type":2108,"url":4310},"https:\u002F\u002Fvuldb.com\u002F?ctiid.305076",{"type":2108,"url":4312},"https:\u002F\u002Fvuldb.com\u002F?id.305076",{"type":2108,"url":4314},"https:\u002F\u002Fvuldb.com\u002F?submit.553645",{"type":2105,"url":4316},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftorch",{"type":2097,"url":4318},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-887c-mr87-cxwp",[2484,2485,2486,4320,4321],"pypi:torch@2.7.1","pypi:torch@2.7.1+cpu",{"id":184,"slug":4323,"dossier":45,"summary":4324,"aliases":4325,"sourceIds":4329,"published":4330,"modified":4331,"checkedAt":7,"severity":4332,"references":4337,"versionKeys":4353,"packageCount":32,"repositoryCount":599},"ghsa-8c7q-86fq-vvmh-be4df9cc","MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled",[4326,4327,4328],"BIT-mlflow-2026-2651","CVE-2026-2651","PYSEC-2026-2220",[184,4328],"2026-05-25T07:16:15.100Z","2026-07-14T05:30:20.380332392Z",[4333,4335],{"type":2093,"score":4334},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",{"type":2093,"score":4336},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[4338,4340,4342,4344,4346,4347,4349,4351],{"type":2097,"url":4339},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2651",{"type":2102,"url":4341},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002Fd7290811d8f3c95366d80109424edc1fb1ad966f",{"type":2108,"url":4343},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-2651",{"type":2465,"url":4345},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2481117",{"type":2105,"url":2679},{"type":2163,"url":4348},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F65beb119-d3e0-4e03-af2f-fa98f78f83dc",{"type":2108,"url":4350},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-2651.json",{"type":2097,"url":4352},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-8c7q-86fq-vvmh",[2687,2688,2689],{"id":185,"slug":4355,"dossier":45,"summary":4356,"aliases":4357,"sourceIds":4360,"published":4361,"modified":4362,"checkedAt":7,"severity":4363,"references":4365,"versionKeys":4375,"packageCount":32,"repositoryCount":530},"ghsa-8ppf-4f7h-5ppj-4d7d140d","pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service",[4358,4359],"CVE-2026-59885","PYSEC-2026-3456",[185,4359],"2026-07-14T17:17:14.880Z","2026-07-23T09:29:39.188829469Z",[4364],{"type":2093,"score":2277},[4366,4368,4370,4372,4373],{"type":2097,"url":4367},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fsecurity\u002Fadvisories\u002FGHSA-8ppf-4f7h-5ppj",{"type":2097,"url":4369},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59885",{"type":2102,"url":4371},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002F45bdb19eb7df4b3780fe9c912c63e99bffc39dd9",{"type":2105,"url":3506},{"type":2097,"url":4374},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Freleases\u002Ftag\u002Fv0.6.4",[3514,4376],"pypi:pyasn1@0.6.3",{"id":186,"slug":4378,"dossier":45,"summary":4379,"aliases":4380,"sourceIds":4383,"published":4384,"modified":4385,"checkedAt":7,"severity":4386,"references":4389,"versionKeys":4408,"packageCount":32,"repositoryCount":599},"ghsa-8qvm-5x2c-j2w7-8a075519","protobuf-python has a potential Denial of Service issue",[4381,4382],"CVE-2025-4565","PYSEC-2026-1806",[186,4382],"2025-06-16T16:02:58Z","2026-07-07T17:57:09.877491994Z",[4387],{"type":2130,"score":4388},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[4390,4392,4394,4396,4398,4399,4401,4403,4405,4406],{"type":2108,"url":4391},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fsecurity\u002Fadvisories\u002FGHSA-735f-pc8j-v9w8",{"type":2108,"url":4393},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fsecurity\u002Fadvisories\u002FGHSA-8qvm-5x2c-j2w7",{"type":2097,"url":4395},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-4565",{"type":2108,"url":4397},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fcommit\u002F17838beda2943d08b8a9d4df5b68f5f04f26d901",{"type":2105,"url":4090},{"type":2108,"url":4400},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fblob\u002Fmain\u002Fpython\u002Fgoogle\u002Fprotobuf\u002Finternal\u002Fdecoder_test.py#L87-L98",{"type":2108,"url":4402},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Fblob\u002Fmain\u002Fpython\u002Fgoogle\u002Fprotobuf\u002Finternal\u002Fmessage_test.py#L1436-L1478",{"type":2108,"url":4404},"https:\u002F\u002Fgithub.com\u002Fprotocolbuffers\u002Fprotobuf\u002Ftree\u002Fmain\u002Fpython#implementation-backends",{"type":2105,"url":4092},{"type":2097,"url":4407},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-8qvm-5x2c-j2w7",[4096,4098,4099],{"id":187,"slug":4410,"dossier":89,"summary":4411,"aliases":4412,"sourceIds":4416,"published":4417,"modified":4418,"checkedAt":7,"severity":4419,"references":4421,"versionKeys":4431,"packageCount":32,"repositoryCount":2416},"ghsa-8v84-f9pq-wr9x-6c1b185f","Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading",[4413,4414,4415],"BIT-pillow-2026-54059","CVE-2026-54059","PYSEC-2026-2253",[187,4415],"2026-07-06T19:17:08.127Z","2026-07-22T02:59:41.148041376Z",[4420],{"type":2093,"score":2277},[4422,4424,4426,4427,4429,4430],{"type":2163,"url":4423},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-8v84-f9pq-wr9x",{"type":2097,"url":4425},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54059",{"type":2102,"url":2708},{"type":2108,"url":4428},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2253.yaml",{"type":2105,"url":2712},{"type":2097,"url":2714},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":188,"slug":4433,"dossier":45,"summary":4434,"aliases":4435,"sourceIds":4438,"published":4439,"modified":4440,"checkedAt":7,"severity":4441,"references":4443,"versionKeys":4456,"packageCount":32,"repositoryCount":618},"ghsa-9356-575x-2w9m-908a1f8c","Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability",[4436,4437],"CVE-2025-5197","PYSEC-2026-1983",[188,4437],"2025-08-06T12:31:20Z","2026-07-07T17:57:12.881673492Z",[4442],{"type":2093,"score":2921},[4444,4446,4448,4450,4451,4453,4454],{"type":2097,"url":4445},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-5197",{"type":2108,"url":4447},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F701caef704e356dc2f9331cc3fd5df0eccb4720a",{"type":2108,"url":4449},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F944b56000be5e9b61af8301aa340838770ad8a0b",{"type":2105,"url":2161},{"type":2108,"url":4452},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F3f8b3fd0-166b-46e7-b60f-60dd9d2678bf",{"type":2105,"url":2509},{"type":2097,"url":4455},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9356-575x-2w9m",[2168,2169],{"id":189,"slug":4458,"dossier":45,"summary":4459,"aliases":4460,"sourceIds":4461,"published":4462,"modified":4463,"checkedAt":7,"severity":4464,"references":4466,"versionKeys":4474,"packageCount":32,"repositoryCount":34},"ghsa-94p4-4cq8-9g67-9a288a09","GitPython: Environment-variable exfiltration via Repo.create_remote() \u002F Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)",[],[189],"2026-07-24T21:45:16Z","2026-07-25T21:44:41.451010015Z",[4465],{"type":2093,"score":3579},[4467,4469,4471,4472],{"type":2108,"url":4468},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-94p4-4cq8-9g67",{"type":2108,"url":4470},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F863417457a0633db7ea5aed4fd01e0b291a41162",{"type":2105,"url":2257},{"type":2108,"url":4473},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.55",[2261,2262,2263],{"id":190,"slug":4476,"dossier":45,"summary":4477,"aliases":4478,"sourceIds":4481,"published":4482,"modified":4483,"checkedAt":7,"severity":4484,"references":4487,"versionKeys":4498,"packageCount":32,"repositoryCount":34},"ghsa-9548-qrrj-x5pj-6121f213","AIOHTTP is vulnerable to HTTP Request\u002FResponse Smuggling through incorrect parsing of chunked trailer sections",[4479,4480],"CVE-2025-53643","PYSEC-2026-1104",[190,4480],"2025-07-14T19:33:31Z","2026-07-07T17:56:52.935544397Z",[4485],{"type":2130,"score":4486},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",[4488,4490,4492,4494,4495,4496],{"type":2108,"url":4489},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-9548-qrrj-x5pj",{"type":2097,"url":4491},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-53643",{"type":2102,"url":4493},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fe8d774f635dc6d1cd3174d0e38891da5de0e2b6a",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":4497},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9548-qrrj-x5pj",[2286,2287,2288,2289],{"id":191,"slug":4500,"dossier":45,"summary":4501,"aliases":4502,"sourceIds":4504,"published":4505,"modified":4506,"checkedAt":7,"severity":4507,"references":4510,"versionKeys":4519,"packageCount":32,"repositoryCount":34},"ghsa-956x-8gvw-wg5v-f5d32b2d","GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` \u002F `Repo.blame()`",[4503],"CVE-2026-67323",[191],"2026-07-21T20:10:06Z","2026-08-02T03:56:47.832026599Z",[4508],{"type":2093,"score":4509},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[4511,4513,4515,4517,4518],{"type":2108,"url":4512},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-956x-8gvw-wg5v",{"type":2108,"url":4514},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2163",{"type":2108,"url":4516},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F701ce32fe5ba8cb622c0e0342a376a6beb47d738",{"type":2105,"url":2257},{"type":2108,"url":2259},[2261,2262,2263],{"id":192,"slug":4521,"dossier":45,"summary":4522,"aliases":4523,"sourceIds":4526,"published":4527,"modified":4528,"checkedAt":7,"severity":4529,"references":4533,"versionKeys":4542,"packageCount":32,"repositoryCount":2294},"ghsa-966j-vmvw-g2g9-dad9a989","AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect",[4524,4525],"CVE-2026-34518","PYSEC-2026-2100",[192,4525],"2026-04-01T21:17:00.020Z","2026-07-13T07:26:39.502317923Z",[4530,4532],{"type":2093,"score":4531},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",{"type":2130,"score":3173},[4534,4536,4538,4540,4541],{"type":2102,"url":4535},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-966j-vmvw-g2g9",{"type":2097,"url":4537},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34518",{"type":2102,"url":4539},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F5351c980dcec7ad385730efdf4e1f4338b24fdb6",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":193,"slug":4544,"dossier":45,"summary":4545,"aliases":4546,"sourceIds":4549,"published":4550,"modified":4551,"checkedAt":7,"severity":4552,"references":4555,"versionKeys":4574,"packageCount":32,"repositoryCount":540},"ghsa-9hjg-9r4m-mvj7-32d7b63e","Requests vulnerable to .netrc credentials leak via malicious URLs",[4547,4548],"CVE-2024-47081","PYSEC-2026-1872",[193,4548],"2025-06-09T19:06:08Z","2026-07-07T17:56:56.234172558Z",[4553],{"type":2093,"score":4554},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[4556,4558,4560,4562,4564,4566,4568,4570,4572],{"type":2108,"url":4557},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-9hjg-9r4m-mvj7",{"type":2097,"url":4559},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47081",{"type":2108,"url":4561},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fpull\u002F6965",{"type":2102,"url":4563},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002F96ba401c1296ab1dda74a2365ef36d88f7d144ef",{"type":2105,"url":4565},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests",{"type":2108,"url":4567},"https:\u002F\u002Frequests.readthedocs.io\u002Fen\u002Flatest\u002Fapi\u002F#requests.Session.trust_env",{"type":2108,"url":4569},"https:\u002F\u002Fseclists.org\u002Ffulldisclosure\u002F2025\u002FJun\u002F2",{"type":2105,"url":4571},"https:\u002F\u002Fpypi.org\u002Fproject\u002Frequests",{"type":2097,"url":4573},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9hjg-9r4m-mvj7",[4575,4576],"pypi:requests@2.31.0","pypi:requests@2.32.3",{"id":194,"slug":4578,"dossier":89,"summary":4579,"aliases":4580,"sourceIds":4584,"published":4585,"modified":4586,"checkedAt":7,"severity":4587,"references":4589,"versionKeys":4602,"packageCount":32,"repositoryCount":2416},"ghsa-9hw9-ch79-4vh6-1ebda54f","Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch",[4581,4582,4583],"BIT-pillow-2026-59205","CVE-2026-59205","PYSEC-2026-3453",[194,4583],"2026-07-14T16:17:02.370Z","2026-07-22T02:59:40.628222965Z",[4588],{"type":2093,"score":2277},[4590,4592,4594,4596,4598,4600,4601],{"type":2163,"url":4591},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-9hw9-ch79-4vh6",{"type":2097,"url":4593},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59205",{"type":2102,"url":4595},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9715",{"type":2102,"url":4597},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fa9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721",{"type":2108,"url":4599},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3453.yaml",{"type":2105,"url":2712},{"type":2097,"url":3409},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":195,"slug":4604,"dossier":45,"summary":4605,"aliases":4606,"sourceIds":4607,"published":4608,"modified":4609,"checkedAt":7,"severity":4610,"references":4612,"versionKeys":4620,"packageCount":32,"repositoryCount":34},"ghsa-9rj7-rf2p-w77r-996a0359","GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks",[],[195],"2026-08-07T15:36:43Z","2026-08-09T02:56:51.068532802Z",[4611],{"type":2093,"score":3763},[4613,4615,4616,4618,4619],{"type":2108,"url":4614},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-9rj7-rf2p-w77r",{"type":2108,"url":2885},{"type":2108,"url":4617},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fd9ddb55bdc66",{"type":2105,"url":2257},{"type":2108,"url":2890},[2261,2262,2263],{"id":196,"slug":4622,"dossier":45,"summary":4623,"aliases":4624,"sourceIds":4627,"published":4628,"modified":4629,"checkedAt":7,"severity":4630,"references":4633,"versionKeys":4650,"packageCount":32,"repositoryCount":32},"ghsa-9wx4-h78v-vm56-6a334c57","Requests `Session` object does not verify requests after making first request with verify=False",[4625,4626],"CVE-2024-35195","PYSEC-2026-1873",[196,4626],"2024-05-20T20:15:00Z","2026-07-07T17:57:17.012984050Z",[4631],{"type":2093,"score":4632},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[4634,4636,4638,4640,4642,4643,4645,4647,4648],{"type":2108,"url":4635},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-9wx4-h78v-vm56",{"type":2097,"url":4637},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-35195",{"type":2108,"url":4639},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fpull\u002F6655",{"type":2102,"url":4641},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002Fa58d7f2ffb4d00b46dca2d70a3932a0b37e22fac",{"type":2105,"url":4565},{"type":2108,"url":4644},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FIYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q",{"type":2108,"url":4646},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FN7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ",{"type":2105,"url":4571},{"type":2097,"url":4649},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-9wx4-h78v-vm56",[4575],{"id":197,"slug":4652,"dossier":45,"summary":4653,"aliases":4654,"sourceIds":4657,"published":4658,"modified":4659,"checkedAt":7,"severity":4660,"references":4664,"versionKeys":4670,"packageCount":32,"repositoryCount":2294},"ghsa-9x8q-7h8h-wcw9-af94166e","aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect",[4655,4656],"CVE-2026-54280","PYSEC-2026-2113",[197,4656],"2026-06-15T20:10:44Z","2026-07-13T07:26:14.649569270Z",[4661,4663],{"type":2130,"score":4662},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":2277},[4665,4667,4669],{"type":2097,"url":4666},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-9x8q-7h8h-wcw9",{"type":2102,"url":4668},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fa762eda5242f6490d6ba667533193f8b473ad587",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":198,"slug":4672,"dossier":45,"summary":4673,"aliases":4674,"sourceIds":4677,"published":4678,"modified":4679,"checkedAt":7,"severity":4680,"references":4684,"versionKeys":4694,"packageCount":32,"repositoryCount":568},"ghsa-c38f-wx89-p2xg-d717e000","UltraJSON has a Memory Leak in ujson.dump() on Write Failure",[4675,4676],"CVE-2026-44660","PYSEC-2026-2293",[198,4676],"2026-05-12T22:25:11Z","2026-07-13T07:26:16.152348068Z",[4681,4682],{"type":2093,"score":2277},{"type":2130,"score":4683},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[4685,4687,4689,4691,4692],{"type":2102,"url":4686},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fsecurity\u002Fadvisories\u002FGHSA-c38f-wx89-p2xg",{"type":2097,"url":4688},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44660",{"type":2102,"url":4690},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fcommit\u002F82af1d0ac01d09aa40c887b460d44b9d9f4bccd9",{"type":2105,"url":2582},{"type":2097,"url":4693},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Freleases\u002Ftag\u002F5.12.1",[2586,2587],{"id":199,"slug":4696,"dossier":45,"summary":4697,"aliases":4698,"sourceIds":4701,"published":4702,"modified":4703,"checkedAt":7,"severity":4704,"references":4708,"versionKeys":4719,"packageCount":32,"repositoryCount":2294},"ghsa-c427-h43c-vf67-fa5b38aa","AIOHTTP accepts duplicate Host headers",[4699,4700],"CVE-2026-34525","PYSEC-2026-2103",[199,4700],"2026-04-01T21:17:00.490Z","2026-07-13T07:26:42.158681139Z",[4705,4707],{"type":2130,"score":4706},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:L\u002FSI:L\u002FSA:N",{"type":2093,"score":2373},[4709,4711,4713,4715,4717,4718],{"type":2102,"url":4710},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-c427-h43c-vf67",{"type":2097,"url":4712},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34525",{"type":2102,"url":4714},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F53e2e6fc58b89c6185be7820bd2c9f40216b3000",{"type":2102,"url":4716},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fe00ca3cca92c465c7913c4beb763a72da9ed8349",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":200,"slug":4721,"dossier":45,"summary":4722,"aliases":4723,"sourceIds":4727,"published":4728,"modified":4729,"checkedAt":7,"severity":4730,"references":4735,"versionKeys":4751,"packageCount":32,"repositoryCount":618},"ghsa-c678-jfcj-6jmf-cd9a8774","PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument",[4724,4725,4726],"BIT-pytorch-2025-2148","CVE-2025-2148","PYSEC-2025-189",[200],"2025-03-10T12:30:55Z","2026-06-09T21:26:06.844649427Z",[4731,4733],{"type":2093,"score":4732},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":2130,"score":4734},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[4736,4738,4740,4742,4743,4745,4747,4749],{"type":2097,"url":4737},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2148",{"type":2108,"url":4739},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147722",{"type":2108,"url":4741},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-189.yaml",{"type":2105,"url":2472},{"type":2108,"url":4744},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fblob\u002Fb0a67c7495bb11ecb23e556058db059ba48354af\u002Ftorch\u002Fautograd\u002Fprofiler.py#L990",{"type":2108,"url":4746},"https:\u002F\u002Fvuldb.com\u002F?ctiid.299059",{"type":2108,"url":4748},"https:\u002F\u002Fvuldb.com\u002F?id.299059",{"type":2108,"url":4750},"https:\u002F\u002Fvuldb.com\u002F?submit.505959",[2484,2485],{"id":201,"slug":4753,"dossier":45,"summary":4754,"aliases":4755,"sourceIds":4758,"published":4759,"modified":4760,"checkedAt":7,"severity":4761,"references":4763,"versionKeys":4779,"packageCount":32,"repositoryCount":34},"ghsa-c8rr-9gxc-jprv-33d752b4","UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop",[4756,4757],"CVE-2026-32875","PYSEC-2026-2292",[201,4757],"2026-03-18T13:01:24Z","2026-07-13T07:26:19.649502948Z",[4762],{"type":2093,"score":2277},[4764,4766,4768,4770,4772,4773,4775,4777],{"type":2163,"url":4765},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fsecurity\u002Fadvisories\u002FGHSA-c8rr-9gxc-jprv",{"type":2097,"url":4767},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-32875",{"type":2465,"url":4769},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fissues\u002F700",{"type":2102,"url":4771},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fcommit\u002F486bd4553dc471a1de11613bc7347a6b318e37ea",{"type":2105,"url":2582},{"type":2108,"url":4774},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-32875",{"type":2108,"url":4776},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-32875.json",{"type":2465,"url":4778},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2449400",[2586],{"id":202,"slug":4781,"dossier":45,"summary":4782,"aliases":4783,"sourceIds":4786,"published":4787,"modified":4788,"checkedAt":7,"severity":4789,"references":4791,"versionKeys":4803,"packageCount":32,"repositoryCount":568},"ghsa-c98p-7wgm-6p64-ef7ac7e3","Tornado: Quadratic DoS via Repeated Header Coalescing",[4784,4785],"CVE-2025-67725","PYSEC-2025-266",[202,4785],"2025-12-12T06:15:41.380Z","2026-07-20T19:15:27.567094965Z",[4790],{"type":2093,"score":2277},[4792,4794,4796,4798,4800,4801],{"type":2097,"url":4793},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-c98p-7wgm-6p64",{"type":2097,"url":4795},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67725",{"type":2102,"url":4797},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F771472cfdaeebc0d89a9cc46e249f8891a6b29cd",{"type":2108,"url":4799},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-266.yaml",{"type":2105,"url":2647},{"type":2097,"url":4802},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.3",[2655,2656,2657],{"id":203,"slug":4805,"dossier":45,"summary":4806,"aliases":4807,"sourceIds":4811,"published":4812,"modified":4813,"checkedAt":7,"severity":4814,"references":4818,"versionKeys":4856,"packageCount":32,"repositoryCount":392},"ghsa-cfh3-3jmp-rvhc-4e95572c","Pillow affected by out-of-bounds write when loading PSD images",[4808,4809,4810],"BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249",[203,4810],"2026-02-11T14:22:50Z","2026-07-13T07:26:49.514806069Z",[4815,4817],{"type":2130,"score":4816},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":2277},[4819,4821,4823,4825,4827,4829,4830,4832,4834,4836,4837,4839,4841,4843,4844,4846,4848,4850,4852,4854],{"type":2108,"url":4820},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-cfh3-3jmp-rvhc",{"type":2097,"url":4822},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25990",{"type":2108,"url":4824},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9427",{"type":2108,"url":4826},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F54ba4db542ad3c7b918812a4e2d69c27735a3199",{"type":2108,"url":4828},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F9000313cc5d4a31bdcdd6d7f0781101abab553aa",{"type":2105,"url":2712},{"type":2108,"url":4831},"https:\u002F\u002Fpillow.readthedocs.io\u002Fen\u002Fstable\u002Freleasenotes\u002F12.1.1.html",{"type":2108,"url":4833},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-25990",{"type":2108,"url":4835},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-25990.json",{"type":2097,"url":2750},{"type":2097,"url":4838},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:14873",{"type":2097,"url":4840},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:14874",{"type":2097,"url":4842},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16174",{"type":2097,"url":2752},{"type":2097,"url":4845},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:28385",{"type":2097,"url":4847},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:3461",{"type":2097,"url":4849},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:3462",{"type":2097,"url":4851},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4128",{"type":2097,"url":4853},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:4942",{"type":2097,"url":4855},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:5168",[2716,2717,2718,2719,2720,2721,2722],{"id":204,"slug":4858,"dossier":45,"summary":4859,"aliases":4860,"sourceIds":4863,"published":4864,"modified":4865,"checkedAt":7,"severity":4866,"references":4869,"versionKeys":4886,"packageCount":32,"repositoryCount":618},"ghsa-cpwx-vrp4-4pq7-799bdc98","Jinja2 vulnerable to sandbox breakout through attr filter selecting format method",[4861,4862],"CVE-2025-27516","PYSEC-2026-1471",[204,4862],"2025-03-05T20:40:14Z","2026-07-07T17:56:16.836141266Z",[4867],{"type":2130,"score":4868},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:P\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[4870,4872,4874,4876,4878,4880,4882,4884],{"type":2108,"url":4871},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-cpwx-vrp4-4pq7",{"type":2097,"url":4873},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-27516",{"type":2102,"url":4875},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F90457bbf33b8662926ae65cdde4c4c32e756e403",{"type":2105,"url":4877},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja",{"type":2108,"url":4879},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F04\u002Fmsg00022.html",{"type":2108,"url":4881},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2025\u002F04\u002Fmsg00045.html",{"type":2105,"url":4883},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fjinja2",{"type":2097,"url":4885},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cpwx-vrp4-4pq7",[4887,4888],"pypi:jinja2@3.1.3","pypi:jinja2@3.1.5",{"id":205,"slug":4890,"dossier":45,"summary":4891,"aliases":4892,"sourceIds":4895,"published":4896,"modified":4897,"checkedAt":7,"severity":4898,"references":4901,"versionKeys":4916,"packageCount":32,"repositoryCount":4918},"ghsa-cq5v-8q36-5273-b5e8d025","AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)",[4893,4894],"CVE-2026-69244","PYSEC-2026-3545",[205,4894],"2026-08-03T20:51:13Z","2026-08-04T21:27:00.629113523Z",[4899],{"type":2130,"score":4900},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:P\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[4902,4904,4906,4908,4909,4911,4912,4914],{"type":2108,"url":4903},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-cq5v-8q36-5273",{"type":2108,"url":4905},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fpull\u002F13223",{"type":2108,"url":4907},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F49f65d54150397892f7bcc4aae887767d51c322d",{"type":2105,"url":2282},{"type":2108,"url":4910},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Freleases\u002Ftag\u002Fv3.14.3",{"type":2105,"url":3183},{"type":2097,"url":4913},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cq5v-8q36-5273",{"type":2097,"url":4915},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-69244",[2286,2287,2288,2289,2290,2291,2292,2293,4917],"pypi:aiohttp@3.14.1",11,{"id":206,"slug":4920,"dossier":45,"summary":4921,"aliases":4922,"sourceIds":4925,"published":4926,"modified":4927,"checkedAt":7,"severity":4928,"references":4931,"versionKeys":4942,"packageCount":32,"repositoryCount":64},"ghsa-cx3h-4qpv-8hc9-3078b6fa","Tornado has out-of-bounds memory access via C extension",[4923,4924],"CVE-2026-49854","PYSEC-2026-3388",[206,4924],"2026-06-12T18:30:19Z","2026-07-13T16:43:34.663472817Z",[4929],{"type":2093,"score":4930},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[4932,4934,4935,4937,4938,4940],{"type":2108,"url":4933},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-cx3h-4qpv-8hc9",{"type":2105,"url":2647},{"type":2108,"url":4936},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Freleases\u002Ftag\u002Fv6.5.6",{"type":2105,"url":2649},{"type":2097,"url":4939},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cx3h-4qpv-8hc9",{"type":2097,"url":4941},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49854",[2655,2656,2657,2658,2659],{"id":207,"slug":4944,"dossier":45,"summary":4945,"aliases":4946,"sourceIds":4950,"published":4951,"modified":4952,"checkedAt":7,"severity":4953,"references":4958,"versionKeys":4974,"packageCount":32,"repositoryCount":32},"ghsa-cx63-2mw6-8hw5-1754ad59","setuptools vulnerable to Command Injection via package URL",[4947,4948,4949],"BIT-setuptools-2024-6345","CVE-2024-6345","PYSEC-2026-1918",[207,4949],"2024-07-15T03:30:57Z","2026-07-07T17:57:13.326243614Z",[4954,4956],{"type":2093,"score":4955},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2130,"score":4957},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:A\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[4959,4961,4963,4965,4966,4968,4970,4972],{"type":2097,"url":4960},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-6345",{"type":2108,"url":4962},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fpull\u002F4332",{"type":2108,"url":4964},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002F88807c7062788254f654ea8c03427adc859321f0",{"type":2105,"url":3330},{"type":2108,"url":4967},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fd6362117-ad57-4e83-951f-b8141c6e7ca5",{"type":2108,"url":4969},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2024\u002F09\u002Fmsg00018.html",{"type":2105,"url":4971},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fsetuptools",{"type":2097,"url":4973},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-cx63-2mw6-8hw5",[3336],{"id":208,"slug":4976,"dossier":45,"summary":4977,"aliases":4978,"sourceIds":4982,"published":4983,"modified":4984,"checkedAt":7,"severity":4985,"references":4987,"versionKeys":4999,"packageCount":32,"repositoryCount":599},"ghsa-f2m9-wcf4-cwwx-e7c3cfb2","MLFlow Creates a Temporary File With Insecure Permissions",[4979,4980,4981],"BIT-mlflow-2026-4137","CVE-2026-4137","PYSEC-2026-2655",[208,4981],"2026-05-18T21:31:53Z","2026-07-13T16:43:33.416174314Z",[4986],{"type":2093,"score":2977},[4988,4990,4992,4993,4994,4996,4997],{"type":2097,"url":4989},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-4137",{"type":2108,"url":4991},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F1dcbb0c2fbd1f446c328830e601ca13a28219b8a",{"type":2097,"url":2988},{"type":2105,"url":2679},{"type":2108,"url":4995},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F648dc30b-76c7-4433-86b8-f43d926fd8d6",{"type":2105,"url":2683},{"type":2097,"url":4998},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-f2m9-wcf4-cwwx",[2687,2688,2689],{"id":209,"slug":5001,"dossier":45,"summary":5002,"aliases":5003,"sourceIds":5007,"published":5008,"modified":5009,"checkedAt":7,"severity":5010,"references":5015,"versionKeys":5033,"packageCount":32,"repositoryCount":618},"ghsa-f4hp-rmr7-r7v8-fe038cb7","PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function",[5004,5005,5006],"BIT-pytorch-2025-2998","CVE-2025-2998","PYSEC-2025-192",[209],"2025-03-31T15:30:48Z","2026-06-09T22:11:09.050788278Z",[5011,5013],{"type":2093,"score":5012},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":2130,"score":5014},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[5016,5018,5020,5022,5024,5026,5027,5029,5031],{"type":2097,"url":5017},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2998",{"type":2108,"url":5019},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149622",{"type":2108,"url":5021},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149622#issue-2935495265",{"type":2108,"url":5023},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F494518046816d29099b7d056a74ffa5c244fdcdd",{"type":2108,"url":5025},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-192.yaml",{"type":2105,"url":2472},{"type":2108,"url":5028},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302047",{"type":2108,"url":5030},"https:\u002F\u002Fvuldb.com\u002F?id.302047",{"type":2108,"url":5032},"https:\u002F\u002Fvuldb.com\u002F?submit.524151",[2484,2485],{"id":210,"slug":5035,"dossier":45,"summary":5036,"aliases":5037,"sourceIds":5040,"published":5041,"modified":5042,"checkedAt":7,"severity":5043,"references":5047,"versionKeys":5058,"packageCount":32,"repositoryCount":32},"ghsa-f96h-pmfr-66vw-6763f20e","Starlette Denial of service (DoS) via multipart\u002Fform-data",[5038,5039],"CVE-2024-47874","PYSEC-2026-1943",[210,5039],"2024-10-15T18:12:57Z","2026-07-07T17:57:05.823442628Z",[5044,5046],{"type":2093,"score":5045},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:N",{"type":2130,"score":4683},[5048,5050,5052,5054,5055,5056],{"type":2108,"url":5049},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-f96h-pmfr-66vw",{"type":2097,"url":5051},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-47874",{"type":2102,"url":5053},"https:\u002F\u002Fgithub.com\u002Fencode\u002Fstarlette\u002Fcommit\u002Ffd038f3070c302bff17ef7d173dbb0b007617733",{"type":2105,"url":2225},{"type":2105,"url":2231},{"type":2097,"url":5057},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-f96h-pmfr-66vw",[2235],{"id":211,"slug":5060,"dossier":45,"summary":5061,"aliases":5062,"sourceIds":5065,"published":5066,"modified":5067,"checkedAt":7,"severity":5068,"references":5071,"versionKeys":5086,"packageCount":32,"repositoryCount":32},"ghsa-f9vj-2wh5-fj8j-f0f29e2a","Werkzeug safe_join not safe on Windows",[5063,5064],"CVE-2024-49766","PYSEC-2026-2045",[211,5064],"2024-10-25T19:43:41Z","2026-07-07T17:56:25.762524663Z",[5069],{"type":2130,"score":5070},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[5072,5074,5076,5078,5079,5081,5083,5084],{"type":2108,"url":5073},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fsecurity\u002Fadvisories\u002FGHSA-f9vj-2wh5-fj8j",{"type":2097,"url":5075},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49766",{"type":2102,"url":5077},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002F2767bcb10a7dd1c297d812cc5e6d11a474c1f092",{"type":2105,"url":2197},{"type":2108,"url":5080},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Freleases\u002Ftag\u002F3.0.6",{"type":2108,"url":5082},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20250131-0005",{"type":2105,"url":2324},{"type":2097,"url":5085},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-f9vj-2wh5-fj8j",[2201],{"id":212,"slug":5088,"dossier":45,"summary":5089,"aliases":5090,"sourceIds":5093,"published":5094,"modified":5095,"checkedAt":7,"severity":5096,"references":5098,"versionKeys":5107,"packageCount":32,"repositoryCount":599},"ghsa-fg7f-2386-8897-44d94e2f","Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex",[5091,5092],"CVE-2026-12061","PYSEC-2026-3582",[212,5092],"2026-07-31T16:51:09Z","2026-08-06T15:11:53.004587618Z",[5097],{"type":2093,"score":2277},[5099,5101,5102,5103,5105],{"type":2108,"url":5100},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-fg7f-2386-8897",{"type":2105,"url":2744},{"type":2105,"url":3702},{"type":2097,"url":5104},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fg7f-2386-8897",{"type":2097,"url":5106},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-12061",[2758,2759],{"id":213,"slug":5109,"dossier":45,"summary":5110,"aliases":5111,"sourceIds":5114,"published":5115,"modified":5116,"checkedAt":7,"severity":5117,"references":5122,"versionKeys":5145,"packageCount":32,"repositoryCount":530},"ghsa-fgcw-684q-jj6r-9fe55ba1","huggingface\u002Ftransformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path",[5112,5113],"CVE-2026-5241","PYSEC-2026-2290",[213,5113],"2026-06-03T14:16:46.337Z","2026-07-23T15:00:26.322865889Z",[5118,5120],{"type":2093,"score":5119},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:N",{"type":2093,"score":5121},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[5123,5125,5127,5129,5130,5132,5134,5136,5137,5139,5141,5143],{"type":2097,"url":5124},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-5241",{"type":2102,"url":5126},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F676559d5022b74aaa0cee1cee0842b7f27c5320e",{"type":2097,"url":5128},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34456",{"type":2097,"url":2754},{"type":2108,"url":5131},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:42644",{"type":2108,"url":5133},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-5241",{"type":2465,"url":5135},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2484384",{"type":2105,"url":2161},{"type":2108,"url":5138},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2026-2290.yaml",{"type":2163,"url":5140},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fceb3ce1a-4c45-497a-b25e-cb9a7685e619",{"type":2108,"url":5142},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-5241.json",{"type":2097,"url":5144},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fgcw-684q-jj6r",[2168,2169,2170,2171,2172,2173,2174],{"id":214,"slug":5147,"dossier":45,"summary":5148,"aliases":5149,"sourceIds":5152,"published":5153,"modified":5154,"checkedAt":7,"severity":5155,"references":5158,"versionKeys":5171,"packageCount":32,"repositoryCount":32},"ghsa-fh2c-86xm-pm2x-ff1ac9ef","LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request",[5150,5151],"CVE-2024-8984","PYSEC-2026-1545",[214,5151],"2025-03-20T12:32:49Z","2026-07-07T17:56:56.562714379Z",[5156],{"type":2093,"score":5157},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:H",[5159,5161,5163,5164,5166,5168,5169],{"type":2097,"url":5160},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-8984",{"type":2108,"url":5162},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002F4f49f836aa844ac9b6bfbeff27e6f6b2b9cf3f61",{"type":2105,"url":2860},{"type":2108,"url":5165},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fblob\u002F8c5ff150f6142608ffe968e4e68429f978fda187\u002Flitellm\u002Ftests\u002Ftest_spend_logs.py#L242",{"type":2108,"url":5167},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F554fc76b-3097-4223-b4cf-110b853e9355",{"type":2105,"url":2864},{"type":2097,"url":5170},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fh2c-86xm-pm2x",[2868],{"id":215,"slug":5173,"dossier":45,"summary":5174,"aliases":5175,"sourceIds":5178,"published":5179,"modified":5180,"checkedAt":7,"severity":5181,"references":5184,"versionKeys":5195,"packageCount":32,"repositoryCount":540},"ghsa-fh55-r93g-j68g-a231bc8e","AIOHTTP Vulnerable to Cookie Parser Warning Storm",[5176,5177],"CVE-2025-69230","PYSEC-2026-1105",[215,5177],"2026-01-05T23:13:46Z","2026-07-07T17:56:34.702331996Z",[5182],{"type":2130,"score":5183},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",[5185,5187,5189,5191,5192,5193],{"type":2108,"url":5186},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-fh55-r93g-j68g",{"type":2097,"url":5188},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69230",{"type":2102,"url":5190},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F64629a0834f94e46d9881f4e99c41a137e1f3326",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":5194},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fh55-r93g-j68g",[2286,2287,2288,2289,2290,2291,2292],{"id":216,"slug":5197,"dossier":45,"summary":5198,"aliases":5199,"sourceIds":5203,"published":5204,"modified":5205,"checkedAt":7,"severity":5206,"references":5211,"versionKeys":5226,"packageCount":32,"repositoryCount":599},"ghsa-fh64-r2vc-xvhr-8b7ea4aa","MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface",[5200,5201,5202],"BIT-mlflow-2026-33865","CVE-2026-33865","PYSEC-2026-93",[216,5202],"2026-04-07T13:16:46.840Z","2026-06-10T17:02:20.155874108Z",[5207,5209],{"type":2093,"score":5208},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N",{"type":2130,"score":5210},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:P\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:L\u002FSI:L\u002FSA:N",[5212,5214,5216,5218,5219,5220,5221,5223,5224],{"type":2097,"url":5213},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33865",{"type":2102,"url":5215},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F21435",{"type":2108,"url":5217},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002Faca4dd0ec88a12f7655155c224371280e9b45dda",{"type":2163,"url":2783},{"type":2108,"url":2785},{"type":2105,"url":2679},{"type":2108,"url":5222},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fmlflow\u002FPYSEC-2026-93.yaml",{"type":2097,"url":2790},{"type":2097,"url":5225},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fh64-r2vc-xvhr",[2687,2688,2689],{"id":217,"slug":5228,"dossier":45,"summary":5229,"aliases":5230,"sourceIds":5234,"published":5235,"modified":5236,"checkedAt":7,"severity":5237,"references":5240,"versionKeys":5253,"packageCount":32,"repositoryCount":599},"ghsa-fhff-qmm8-h2fp-244bab2b","Arbitrary file write via tar traversal in mlflow",[5231,5232,5233],"BIT-mlflow-2025-15031","CVE-2025-15031","PYSEC-2026-2656",[217,5233],"2026-03-19T00:30:20Z","2026-07-13T16:43:21.433539748Z",[5238],{"type":2093,"score":5239},"CVSS:3.0\u002FAV:A\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[5241,5243,5245,5246,5248,5250,5251],{"type":2097,"url":5242},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-15031",{"type":2108,"url":5244},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F3bf6d81ac4d38654c8ff012dbd0c3e9f17e7e346",{"type":2105,"url":2679},{"type":2108,"url":5247},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fblob\u002Ffe4d9be330426904283401f1d2ed914238b6fc37\u002Fmlflow\u002Fpyfunc\u002Fdbconnect_artifact_cache.py#L140",{"type":2108,"url":5249},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F09856f77-f968-446f-a930-657d126efe4e",{"type":2105,"url":2683},{"type":2097,"url":5252},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fhff-qmm8-h2fp",[2687,2688,2689],{"id":218,"slug":5255,"dossier":89,"summary":5256,"aliases":5257,"sourceIds":5261,"published":5262,"modified":5263,"checkedAt":7,"severity":5264,"references":5267,"versionKeys":5281,"packageCount":32,"repositoryCount":2416},"ghsa-fj7v-r99m-22gq-e36cfebd","Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images",[5258,5259,5260],"BIT-pillow-2026-59198","CVE-2026-59198","PYSEC-2026-3494",[218,5260],"2026-07-20T23:09:36Z","2026-07-23T15:11:28.382441947Z",[5265],{"type":2093,"score":5266},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:L",[5268,5270,5272,5274,5276,5277,5278,5279],{"type":2108,"url":5269},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-fj7v-r99m-22gq",{"type":2097,"url":5271},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59198",{"type":2108,"url":5273},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9709",{"type":2108,"url":5275},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Feada3cbd7fb9963ee90673fb7b5270124a0d5f4b",{"type":2105,"url":2712},{"type":2108,"url":3409},{"type":2105,"url":3411},{"type":2097,"url":5280},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fj7v-r99m-22gq",[2716,2717,2718,2719,2720,2721,2722,2723],{"id":219,"slug":5283,"dossier":45,"summary":5284,"aliases":5285,"sourceIds":5288,"published":5289,"modified":5290,"checkedAt":7,"severity":5291,"references":5294,"versionKeys":5305,"packageCount":32,"repositoryCount":32},"ghsa-fjcf-3j3r-78rp-3506a50a","LiteLLM Has an Improper Authorization Vulnerability",[5286,5287],"CVE-2025-0628","PYSEC-2026-1546",[219,5287],"2025-03-20T12:32:52Z","2026-07-07T17:56:36.033233141Z",[5292],{"type":2093,"score":5293},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[5295,5297,5299,5300,5302,5303],{"type":2097,"url":5296},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-0628",{"type":2108,"url":5298},"https:\u002F\u002Fgithub.com\u002Fberriai\u002Flitellm\u002Fcommit\u002F566d9354aab4215091b2e51ad0333e948125fa1b",{"type":2105,"url":2860},{"type":2108,"url":5301},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F6c0e2f75-2d03-42f9-9530-e16a973317fc",{"type":2105,"url":2864},{"type":2097,"url":5304},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fjcf-3j3r-78rp",[2868],{"id":220,"slug":5307,"dossier":45,"summary":5308,"aliases":5309,"sourceIds":5310,"published":5311,"modified":5312,"checkedAt":7,"severity":5313,"references":5315,"versionKeys":5323,"packageCount":32,"repositoryCount":34},"ghsa-fjr4-x663-mwxc-324b7aa5","GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)",[],[220],"2026-07-24T16:41:20Z","2026-07-25T21:44:39.974035175Z",[5314],{"type":2093,"score":2548},[5316,5318,5319,5321,5322],{"type":2108,"url":5317},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-fjr4-x663-mwxc",{"type":2108,"url":3768},{"type":2108,"url":5320},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F1d51b891d7f236044a6aa17498ec682b63dad6e6",{"type":2105,"url":2257},{"type":2108,"url":3773},[2261,2262,2263],{"id":221,"slug":5325,"dossier":45,"summary":3803,"aliases":5326,"sourceIds":5329,"published":5330,"modified":5331,"checkedAt":7,"severity":5332,"references":5335,"versionKeys":5346,"packageCount":32,"repositoryCount":32},"ghsa-fpwr-67px-3qhx-94f30126",[5327,5328],"CVE-2025-1194","PYSEC-2026-1984",[221,5328],"2025-04-29T12:30:21Z","2026-07-07T17:57:12.290933710Z",[5333],{"type":2093,"score":5334},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[5336,5338,5340,5341,5343,5344],{"type":2097,"url":5337},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-1194",{"type":2108,"url":5339},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F92c5ca9dd70de3ade2af2eb835c96215cc50e815",{"type":2105,"url":2161},{"type":2108,"url":5342},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F86f58dcd-683f-4adc-a735-849f51e9abb2",{"type":2105,"url":2509},{"type":2097,"url":5345},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-fpwr-67px-3qhx",[2168],{"id":222,"slug":5348,"dossier":45,"summary":5349,"aliases":5350,"sourceIds":5354,"published":5355,"modified":5356,"checkedAt":7,"severity":5357,"references":5361,"versionKeys":5377,"packageCount":32,"repositoryCount":599},"ghsa-g35p-px32-whv6-8b66e41b","MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration",[5351,5352,5353],"BIT-mlflow-2026-4035","CVE-2026-4035","PYSEC-2026-2222",[222,5353],"2026-06-03T09:16:13.083Z","2026-07-13T16:45:04.877817766Z",[5358,5360],{"type":2093,"score":5359},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:L\u002FA:L",{"type":2093,"score":2642},[5362,5364,5366,5368,5370,5371,5373,5375],{"type":2097,"url":5363},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-4035",{"type":2102,"url":5365},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F4a3f2f720cb4f058c9e0c5b883e0acc9ab64a7f3",{"type":2108,"url":5367},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-4035",{"type":2465,"url":5369},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2484318",{"type":2105,"url":2679},{"type":2163,"url":5372},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Ff8e591a0-0f19-4910-b82e-16c9956f2233",{"type":2108,"url":5374},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-4035.json",{"type":2097,"url":5376},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-g35p-px32-whv6",[2687,2688,2689],{"id":223,"slug":5379,"dossier":45,"summary":5380,"aliases":5381,"sourceIds":5384,"published":5385,"modified":5386,"checkedAt":7,"severity":5387,"references":5390,"versionKeys":5396,"packageCount":32,"repositoryCount":2294},"ghsa-g3cq-j2xw-wf74-4475e17b","aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup",[5382,5383],"CVE-2026-54278","PYSEC-2026-2111",[223,5383],"2026-06-15T20:09:51Z","2026-07-13T07:26:25.190325605Z",[5388,5389],{"type":2130,"score":2831},{"type":2093,"score":2277},[5391,5393,5394],{"type":2097,"url":5392},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-g3cq-j2xw-wf74",{"type":2105,"url":2282},{"type":2102,"url":5395},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F4f7480e474cccc6a8cc2c92ad3f17a31dedf8232",[2286,2287,2288,2289,2290,2291,2292,2293],{"id":224,"slug":5398,"dossier":45,"summary":5399,"aliases":5400,"sourceIds":5403,"published":5404,"modified":5405,"checkedAt":7,"severity":5406,"references":5408,"versionKeys":5419,"packageCount":32,"repositoryCount":599},"ghsa-g6pg-52vf-843h-da352526","MLFlow allows Tracing + Assessments Access",[5401,5402],"CVE-2025-15381","PYSEC-2026-2657",[224,5402],"2026-03-27T18:31:27Z","2026-07-13T16:43:42.935139106Z",[5407],{"type":2093,"score":5293},[5409,5411,5412,5414,5416,5417],{"type":2097,"url":5410},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-15381",{"type":2105,"url":2679},{"type":2108,"url":5413},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fblob\u002Fb569ebc74c14af593c326143bee2df44a5d59edf\u002Fmlflow\u002Fserver\u002Fauth\u002F__init__.py#L752",{"type":2108,"url":5415},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F149fb2f9-ef4b-4136-a25c-20563451904c",{"type":2105,"url":2683},{"type":2097,"url":5418},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-g6pg-52vf-843h",[2687,2688,2689],{"id":225,"slug":5421,"dossier":45,"summary":5422,"aliases":5423,"sourceIds":5426,"published":5427,"modified":5428,"checkedAt":7,"severity":5429,"references":5432,"versionKeys":5451,"packageCount":32,"repositoryCount":32},"ghsa-g7vv-2v7x-gj9p-5ef970c3","tqdm CLI arguments injection attack",[5424,5425],"CVE-2024-34062","PYSEC-2026-1976",[225,5425],"2024-05-03T19:33:28Z","2026-07-07T17:56:20.187915678Z",[5430],{"type":2093,"score":5431},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:N",[5433,5435,5437,5439,5441,5443,5445,5447,5449],{"type":2108,"url":5434},"https:\u002F\u002Fgithub.com\u002Ftqdm\u002Ftqdm\u002Fsecurity\u002Fadvisories\u002FGHSA-g7vv-2v7x-gj9p",{"type":2097,"url":5436},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-34062",{"type":2108,"url":5438},"https:\u002F\u002Fgithub.com\u002Ftqdm\u002Ftqdm\u002Fcommit\u002F4e613f84ed2ae029559f539464df83fa91feb316",{"type":2105,"url":5440},"https:\u002F\u002Fgithub.com\u002Ftqdm\u002Ftqdm",{"type":2108,"url":5442},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FPA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6",{"type":2108,"url":5444},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FQRECVQCCESHBS3UJOWNXQUIX725TKNY6",{"type":2108,"url":5446},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FVA337CYUS4SLRFV2P6MX6MZ2LKFURKJC",{"type":2105,"url":5448},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ftqdm",{"type":2097,"url":5450},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-g7vv-2v7x-gj9p",[5452],"pypi:tqdm@4.66.2",{"id":226,"slug":5454,"dossier":45,"summary":5455,"aliases":5456,"sourceIds":5459,"published":5460,"modified":5461,"checkedAt":7,"severity":5462,"references":5464,"versionKeys":5477,"packageCount":32,"repositoryCount":540},"ghsa-g84x-mcqj-x9qq-fc677e5d","AIOHTTP vulnerable to DoS through chunked messages",[5457,5458],"CVE-2025-69229","PYSEC-2026-1106",[226,5458],"2026-01-05T23:13:29Z","2026-07-07T17:56:31.463290158Z",[5463],{"type":2130,"score":2831},[5465,5467,5469,5471,5473,5474,5475],{"type":2108,"url":5466},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-g84x-mcqj-x9qq",{"type":2097,"url":5468},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69229",{"type":2108,"url":5470},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F4ed97a4e46eaf61bd0f05063245f613469700229",{"type":2108,"url":5472},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fdc3170b56904bdf814228fae70a5501a42a6c712",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":5476},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-g84x-mcqj-x9qq",[2286,2287,2288,2289,2290,2291,2292],{"id":227,"slug":5479,"dossier":89,"summary":5480,"aliases":5481,"sourceIds":5484,"published":5485,"modified":5486,"checkedAt":7,"severity":5487,"references":5492,"versionKeys":5502,"packageCount":32,"repositoryCount":5505},"ghsa-gc5v-m9x4-r6x2-b9828ad8","Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function",[5482,5483],"CVE-2026-25645","PYSEC-2026-2275",[227,5483],"2026-03-25T16:56:28Z","2026-07-13T07:26:34.091663004Z",[5488,5490],{"type":2093,"score":5489},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:N",{"type":2093,"score":5491},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:N",[5493,5495,5497,5499,5500],{"type":2097,"url":5494},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fsecurity\u002Fadvisories\u002FGHSA-gc5v-m9x4-r6x2",{"type":2097,"url":5496},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25645",{"type":2102,"url":5498},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Fcommit\u002F66d21cb07bd6255b1280291c4fafb71803cdb3b7",{"type":2105,"url":4565},{"type":2097,"url":5501},"https:\u002F\u002Fgithub.com\u002Fpsf\u002Frequests\u002Freleases\u002Ftag\u002Fv2.33.0",[4575,4576,5503,5504],"pypi:requests@2.32.4","pypi:requests@2.32.5",15,{"id":228,"slug":5507,"dossier":45,"summary":5508,"aliases":5509,"sourceIds":5512,"published":5513,"modified":5514,"checkedAt":7,"severity":5515,"references":5518,"versionKeys":5528,"packageCount":32,"repositoryCount":599},"ghsa-gfwx-w7gr-fvh7-16d22532","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk",[5510,5511],"CVE-2026-33230","PYSEC-2026-2235",[228,5511],"2026-03-18T20:23:33Z","2026-07-13T07:26:40.492720011Z",[5516],{"type":2093,"score":5517},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N",[5519,5521,5523,5525,5527],{"type":2163,"url":5520},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-gfwx-w7gr-fvh7",{"type":2097,"url":5522},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33230",{"type":2102,"url":5524},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002F1c3f799607eeb088cab2491dcf806ae83c29ad8f",{"type":2102,"url":5526},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002F40d0bc1d484a3458d6a63ecb5ba4957ab16ba14e",{"type":2105,"url":2744},[2758,2759],{"id":229,"slug":5530,"dossier":89,"summary":5531,"aliases":5532,"sourceIds":5535,"published":5536,"modified":5537,"checkedAt":7,"severity":5538,"references":5540,"versionKeys":5551,"packageCount":32,"repositoryCount":2416},"ghsa-gm62-xv2j-4w53-5befa184","urllib3 allows an unbounded number of links in the decompression chain",[5533,5534],"CVE-2025-66418","PYSEC-2026-1998",[229,5534],"2025-12-05T18:15:19Z","2026-07-07T17:57:28.931610368Z",[5539],{"type":2130,"score":2396},[5541,5543,5545,5547,5548,5549],{"type":2108,"url":5542},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-gm62-xv2j-4w53",{"type":2097,"url":5544},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66418",{"type":2102,"url":5546},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002F24d7b67eac89f94e11003424bcf0d8f7b72222a8",{"type":2105,"url":2405},{"type":2105,"url":2407},{"type":2097,"url":5550},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gm62-xv2j-4w53",[2411,2412,2413,2414,2415],{"id":230,"slug":5553,"dossier":45,"summary":5554,"aliases":5555,"sourceIds":5558,"published":5559,"modified":5560,"checkedAt":7,"severity":5561,"references":5564,"versionKeys":5579,"packageCount":32,"repositoryCount":32},"ghsa-gmj6-6f8f-6699-e3e02f35","Jinja has a sandbox breakout through malicious filenames",[5556,5557],"CVE-2024-56201","PYSEC-2026-1472",[230,5557],"2024-12-23T17:54:12Z","2026-07-07T17:56:55.074166933Z",[5562,5563],{"type":2093,"score":2248},{"type":2130,"score":4868},[5565,5567,5569,5571,5573,5574,5576,5577],{"type":2108,"url":5566},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-gmj6-6f8f-6699",{"type":2097,"url":5568},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56201",{"type":2108,"url":5570},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fissues\u002F1792",{"type":2102,"url":5572},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F767b23617628419ae3709ccfb02f9602ae9fe51f",{"type":2105,"url":4877},{"type":2108,"url":5575},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Freleases\u002Ftag\u002F3.1.5",{"type":2105,"url":4883},{"type":2097,"url":5578},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gmj6-6f8f-6699",[4887],{"id":231,"slug":5581,"dossier":45,"summary":5582,"aliases":5583,"sourceIds":5586,"published":5587,"modified":5588,"checkedAt":7,"severity":5589,"references":5592,"versionKeys":5607,"packageCount":32,"repositoryCount":618},"ghsa-gq3w-7jj3-x7gr-f80b7f86","MLflow Use of Default Password Authentication Bypass Vulnerability",[5584,5585],"CVE-2026-2635","PYSEC-2026-421",[231,5585],"2026-02-21T00:31:43Z","2026-07-01T20:22:58.325967Z",[5590],{"type":2093,"score":5591},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[5593,5595,5597,5599,5600,5602,5604,5605],{"type":2097,"url":5594},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2635",{"type":2108,"url":5596},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F19260",{"type":2108,"url":5598},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F5bf2ec2bd4222a18d78631183ac7f6b752afe8a4",{"type":2105,"url":2679},{"type":2108,"url":5601},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Freleases\u002Ftag\u002Fv3.8.0rc0",{"type":2108,"url":5603},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-26-111",{"type":2105,"url":2683},{"type":2097,"url":5606},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-gq3w-7jj3-x7gr",[2687,2688],{"id":232,"slug":5609,"dossier":89,"summary":5610,"aliases":5611,"sourceIds":5615,"published":5616,"modified":5617,"checkedAt":7,"severity":5618,"references":5621,"versionKeys":5633,"packageCount":32,"repositoryCount":5641},"ghsa-h35f-9h28-mq5c-f3238ba1","setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC\u002FNFD) on macOS APFS\u002FHFS+",[5612,5613,5614],"BIT-setuptools-2026-59890","CVE-2026-59890","PYSEC-2026-3447",[232,5614],"2026-07-08T17:17:27.020Z","2026-07-23T09:29:39.408842775Z",[5619],{"type":2093,"score":5620},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[5622,5624,5626,5628,5630,5631],{"type":2163,"url":5623},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fsecurity\u002Fadvisories\u002FGHSA-h35f-9h28-mq5c",{"type":2097,"url":5625},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59890",{"type":2102,"url":5627},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Fcommit\u002Fdd9f436a36486b4cb8a4c70a2321548b0be09b8f",{"type":2108,"url":5629},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fsetuptools\u002FPYSEC-2026-3447.yaml",{"type":2105,"url":3330},{"type":2097,"url":5632},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fsetuptools\u002Freleases\u002Ftag\u002Fv83.0.0",[3336,3337,3338,5634,5635,5636,5637,5638,5639,5640],"pypi:setuptools@79.0.1","pypi:setuptools@80.0.1","pypi:setuptools@80.3.1","pypi:setuptools@80.4.0","pypi:setuptools@80.8.0","pypi:setuptools@80.9.0","pypi:setuptools@82.0.1",14,{"id":233,"slug":5643,"dossier":45,"summary":5644,"aliases":5645,"sourceIds":5648,"published":5649,"modified":5650,"checkedAt":7,"severity":5651,"references":5653,"versionKeys":5674,"packageCount":32,"repositoryCount":32},"ghsa-h75v-3vvj-5mfj-d8fc6bb7","Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter",[5646,5647],"CVE-2024-34064","PYSEC-2026-1474",[233,5647],"2024-05-06T14:20:59Z","2026-07-07T17:57:30.872296178Z",[5652],{"type":2093,"score":3993},[5654,5656,5658,5660,5661,5663,5665,5667,5669,5671,5672],{"type":2108,"url":5655},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-h75v-3vvj-5mfj",{"type":2097,"url":5657},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-34064",{"type":2102,"url":5659},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F0668239dc6b44ef38e7a6c9f91f312fd4ca581cb",{"type":2105,"url":4877},{"type":2108,"url":5662},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2024\u002F12\u002Fmsg00009.html",{"type":2108,"url":5664},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002F567XIGSZMABG6TSMYWD7MIYNJSUQQRUC",{"type":2108,"url":5666},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FGCLF44KY43BSVMTE6S53B4V5WP3FRRSE",{"type":2108,"url":5668},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FSSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS",{"type":2108,"url":5670},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS",{"type":2105,"url":4883},{"type":2097,"url":5673},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-h75v-3vvj-5mfj",[4887],{"id":234,"slug":5676,"dossier":45,"summary":5677,"aliases":5678,"sourceIds":5681,"published":5682,"modified":5683,"checkedAt":7,"severity":5684,"references":5687,"versionKeys":5701,"packageCount":32,"repositoryCount":599},"ghsa-h8wq-7xc4-p3qx-d8f6b020","NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()",[5679,5680],"CVE-2026-0846","PYSEC-2026-97",[234,5680],"2026-03-09T20:16:05.703Z","2026-06-10T17:02:23.828594589Z",[5685,5686],{"type":2093,"score":3577},{"type":2093,"score":3579},[5688,5690,5692,5694,5695,5697,5699],{"type":2097,"url":5689},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0846",{"type":2108,"url":5691},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fpull\u002F3485",{"type":2108,"url":5693},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002Fb2e1164bf89277f79b65406c829b99fb20ca1974",{"type":2105,"url":2744},{"type":2108,"url":5696},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fnltk\u002FPYSEC-2026-97.yaml",{"type":2163,"url":5698},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F007b84f8-418e-4300-99d0-bf504c2f97eb",{"type":2097,"url":5700},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-h8wq-7xc4-p3qx",[2758,2759],{"id":235,"slug":5703,"dossier":45,"summary":5704,"aliases":5705,"sourceIds":5708,"published":5709,"modified":5710,"checkedAt":7,"severity":5711,"references":5714,"versionKeys":5723,"packageCount":32,"repositoryCount":2294},"ghsa-hcc4-c3v8-rx92-ddf32b5c","AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector",[5706,5707],"CVE-2026-34513","PYSEC-2026-2095",[235,5707],"2026-04-01T21:16:59.267Z","2026-07-13T07:26:43.174352940Z",[5712,5713],{"type":2130,"score":2619},{"type":2093,"score":2277},[5715,5717,5719,5721,5722],{"type":2102,"url":5716},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-hcc4-c3v8-rx92",{"type":2097,"url":5718},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34513",{"type":2102,"url":5720},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fc4d77c3533122be353b8afca8e8675e3b4cbda98",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":236,"slug":5725,"dossier":45,"summary":5726,"aliases":5727,"sourceIds":5730,"published":5731,"modified":5732,"checkedAt":7,"severity":5733,"references":5737,"versionKeys":5745,"packageCount":32,"repositoryCount":2294},"ghsa-hg6j-4rv6-33pg-d0ac8db0","AIOHTTP is vulnerable to cross-origin redirect with per-request cookies",[5728,5729],"CVE-2026-47265","PYSEC-2026-2105",[236,5729],"2026-06-02T20:16:37.903Z","2026-07-13T07:26:51.969507320Z",[5734,5736],{"type":2130,"score":5735},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U",{"type":2093,"score":3579},[5738,5740,5742,5744],{"type":2102,"url":5739},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-hg6j-4rv6-33pg",{"type":2097,"url":5741},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-47265",{"type":2102,"url":5743},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Ff54c40851b0d6c4bbdab97ba518a223adda32478",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":237,"slug":5747,"dossier":45,"summary":2177,"aliases":5748,"sourceIds":5751,"published":5752,"modified":5753,"checkedAt":7,"severity":5754,"references":5756,"versionKeys":5769,"packageCount":32,"repositoryCount":568},"ghsa-hgf8-39gv-g3f2-0469b394",[5749,5750],"CVE-2025-66221","PYSEC-2026-2046",[237,5750],"2025-12-02T00:27:38Z","2026-07-07T17:57:36.044527736Z",[5755],{"type":2130,"score":2186},[5757,5759,5761,5763,5764,5766,5767],{"type":2108,"url":5758},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fsecurity\u002Fadvisories\u002FGHSA-hgf8-39gv-g3f2",{"type":2097,"url":5760},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-66221",{"type":2108,"url":5762},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002F4b833376a45c323a189cd11d2362bcffdb1c0c13",{"type":2105,"url":2197},{"type":2108,"url":5765},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Freleases\u002Ftag\u002F3.1.4",{"type":2105,"url":2324},{"type":2097,"url":5768},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-hgf8-39gv-g3f2",[2201,2202,2203,2204],{"id":238,"slug":5771,"dossier":45,"summary":5772,"aliases":5773,"sourceIds":5774,"published":5775,"modified":5776,"checkedAt":7,"severity":5777,"references":5779,"versionKeys":5787,"packageCount":32,"repositoryCount":34},"ghsa-hh9p-6wh2-4mfc-8e33cff1","GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()",[],[238],"2026-08-07T15:43:56Z","2026-08-09T02:56:50.509044228Z",[5778],{"type":2093,"score":3105},[5780,5782,5783,5785,5786],{"type":2108,"url":5781},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-hh9p-6wh2-4mfc",{"type":2108,"url":2885},{"type":2108,"url":5784},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Ff2550b65bf60ca087190981e2c7b6865e201f40c",{"type":2105,"url":2257},{"type":2108,"url":2890},[2261,2262,2263],{"id":239,"slug":5789,"dossier":45,"summary":5790,"aliases":5791,"sourceIds":5794,"published":5795,"modified":5796,"checkedAt":7,"severity":5797,"references":5799,"versionKeys":5808,"packageCount":32,"repositoryCount":530},"ghsa-hm4w-wwcw-mr6r-b3d243f3","pyasn1: Uncontrolled resource consumption when converting decoded REAL values",[5792,5793],"CVE-2026-59886","PYSEC-2026-3457",[239,5793],"2026-07-14T17:17:15.010Z","2026-07-23T09:29:38.810475714Z",[5798],{"type":2093,"score":2277},[5800,5802,5804,5806,5807],{"type":2097,"url":5801},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fsecurity\u002Fadvisories\u002FGHSA-hm4w-wwcw-mr6r",{"type":2097,"url":5803},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59886",{"type":2102,"url":5805},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002Fe60c691cb91addb8fcefa2f537e85ede6fb1e886",{"type":2105,"url":3506},{"type":2097,"url":4374},[3514,4376],{"id":240,"slug":5810,"dossier":45,"summary":5811,"aliases":5812,"sourceIds":5813,"published":5814,"modified":5815,"checkedAt":7,"severity":5816,"references":5819,"versionKeys":5830,"packageCount":32,"repositoryCount":34},"ghsa-hmq2-w58f-27jc-f0b0fe70","GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython",[],[240],"2026-08-07T15:45:39Z","2026-08-09T02:56:50.891058419Z",[5817],{"type":2093,"score":5818},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:N\u002FI:H\u002FA:L",[5820,5822,5824,5826,5828,5829],{"type":2108,"url":5821},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-hmq2-w58f-27jc",{"type":2108,"url":5823},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2202",{"type":2108,"url":5825},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F4299c990e1ca21896f9485277caf7bb0ae5b404c",{"type":2108,"url":5827},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fe4b8e7d026ca6abb4cf604f8e77093432ce23c06",{"type":2105,"url":2257},{"type":2108,"url":2890},[2261,2262,2263],{"id":241,"slug":5832,"dossier":45,"summary":5833,"aliases":5834,"sourceIds":5837,"published":5838,"modified":5839,"checkedAt":7,"severity":5840,"references":5844,"versionKeys":5850,"packageCount":32,"repositoryCount":2294},"ghsa-hpj7-wq8m-9hgp-fac25647","aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges",[5835,5836],"CVE-2026-54276","PYSEC-2026-2109",[241,5836],"2026-06-15T20:09:06Z","2026-07-13T07:26:28.701980401Z",[5841,5843],{"type":2130,"score":5842},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":5517},[5845,5847,5849],{"type":2097,"url":5846},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-hpj7-wq8m-9hgp",{"type":2102,"url":5848},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F38d16060037e1bfcd6d677abababa3c2a4bb58fa",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":242,"slug":5852,"dossier":45,"summary":5853,"aliases":5854,"sourceIds":5857,"published":5858,"modified":5859,"checkedAt":7,"severity":5860,"references":5864,"versionKeys":5880,"packageCount":32,"repositoryCount":32},"ghsa-hxxf-235m-72v3-21da19b0","Deserialization of Untrusted Data in Hugging Face Transformers",[5855,5856],"CVE-2024-11394","PYSEC-2024-229",[242,5856],"2024-11-22T22:15:07Z","2026-06-10T17:02:30.328718397Z",[5861,5863],{"type":2093,"score":5862},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2093,"score":4955},[5865,5867,5869,5871,5872,5874,5876,5878],{"type":2097,"url":5866},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-11394",{"type":2108,"url":5868},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fissues\u002F34840",{"type":2108,"url":5870},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F35296",{"type":2105,"url":2161},{"type":2108,"url":5873},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2024-229.yaml",{"type":2108,"url":5875},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1515",{"type":2097,"url":5877},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1515\u002F",{"type":2097,"url":5879},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-hxxf-235m-72v3",[2168],{"id":243,"slug":5882,"dossier":45,"summary":5883,"aliases":5884,"sourceIds":5887,"published":5888,"modified":5889,"checkedAt":7,"severity":5890,"references":5894,"versionKeys":5912,"packageCount":32,"repositoryCount":2294},"ghsa-jg22-mg44-37j8-b8064c77","AIOHTTP is Vulnerable to Deserialization of Untrusted Data",[5885,5886],"CVE-2026-34993","PYSEC-2026-2104",[243,5886],"2026-06-02T20:16:34.857Z","2026-07-13T07:26:37.684367184Z",[5891,5893],{"type":2093,"score":5892},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:C\u002FC:L\u002FI:H\u002FA:L",{"type":2093,"score":2428},[5895,5897,5899,5901,5902,5904,5906,5908,5909,5910],{"type":2102,"url":5896},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-jg22-mg44-37j8",{"type":2097,"url":5898},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34993",{"type":2102,"url":5900},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fdcf40f30637e8752c76781cf6703b5a236749a00",{"type":2105,"url":2282},{"type":2108,"url":5903},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-34993",{"type":2108,"url":5905},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-34993.json",{"type":2097,"url":5907},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24977",{"type":2097,"url":5128},{"type":2097,"url":2754},{"type":2465,"url":5911},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2484099",[2286,2287,2288,2289,2290,2291,2292,2293],{"id":244,"slug":5914,"dossier":45,"summary":5915,"aliases":5916,"sourceIds":5919,"published":5920,"modified":5921,"checkedAt":7,"severity":5922,"references":5924,"versionKeys":5934,"packageCount":32,"repositoryCount":568},"ghsa-jhmp-mqwm-3gq8-3b1c10a9","Tornado: Quadratic DoS via Crafted Multipart Parameters",[5917,5918],"CVE-2025-67726","PYSEC-2025-267",[244,5918],"2025-12-12T07:15:44.920Z","2026-07-20T19:15:27.583657512Z",[5923],{"type":2093,"score":2277},[5925,5927,5929,5930,5932,5933],{"type":2097,"url":5926},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-jhmp-mqwm-3gq8",{"type":2097,"url":5928},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67726",{"type":2102,"url":4797},{"type":2108,"url":5931},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-267.yaml",{"type":2105,"url":2647},{"type":2097,"url":4802},[2655,2656,2657],{"id":245,"slug":5936,"dossier":45,"summary":5937,"aliases":5938,"sourceIds":5941,"published":5942,"modified":5943,"checkedAt":7,"severity":5944,"references":5946,"versionKeys":5957,"packageCount":32,"repositoryCount":540},"ghsa-jj3x-wxrx-4x23-407bafac","AIOHTTP vulnerable to DoS when bypassing asserts",[5939,5940],"CVE-2025-69227","PYSEC-2026-1107",[245,5940],"2026-01-05T23:10:15Z","2026-07-07T17:57:17.782415842Z",[5945],{"type":2130,"score":2831},[5947,5949,5951,5953,5954,5955],{"type":2108,"url":5948},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-jj3x-wxrx-4x23",{"type":2097,"url":5950},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69227",{"type":2108,"url":5952},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fbc1319ec3cbff9438a758951a30907b072561259",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":5956},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jj3x-wxrx-4x23",[2286,2287,2288,2289,2290,2291,2292],{"id":246,"slug":5959,"dossier":45,"summary":5960,"aliases":5961,"sourceIds":5964,"published":5965,"modified":5966,"checkedAt":7,"severity":5967,"references":5970,"versionKeys":5979,"packageCount":32,"repositoryCount":34},"ghsa-jjhc-v7c2-5hh6-5d2c89e6","LiteLLM: Authentication bypass via OIDC userinfo cache key collision",[5962,5963],"CVE-2026-35030","PYSEC-2026-390",[246,5963],"2026-04-03T21:59:50Z","2026-07-01T20:22:56.400828Z",[5968],{"type":2130,"score":5969},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:N\u002FSC:H\u002FSI:H\u002FSA:N",[5971,5973,5975,5976,5977],{"type":2108,"url":5972},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fsecurity\u002Fadvisories\u002FGHSA-jjhc-v7c2-5hh6",{"type":2097,"url":5974},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-35030",{"type":2105,"url":2860},{"type":2105,"url":2864},{"type":2097,"url":5978},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jjhc-v7c2-5hh6",[2868,2869,2870,2871],{"id":247,"slug":5981,"dossier":89,"summary":5982,"aliases":5983,"sourceIds":5987,"published":5988,"modified":5989,"checkedAt":7,"severity":5990,"references":5992,"versionKeys":6006,"packageCount":32,"repositoryCount":2416},"ghsa-jjj6-mw9f-p565-ed2d1f46","Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()",[5984,5985,5986],"BIT-pillow-2026-59200","CVE-2026-59200","PYSEC-2026-3495",[247,5986],"2026-07-20T23:11:29Z","2026-07-23T15:11:28.034031834Z",[5991],{"type":2093,"score":2277},[5993,5995,5997,5999,6001,6002,6003,6004],{"type":2108,"url":5994},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-jjj6-mw9f-p565",{"type":2097,"url":5996},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59200",{"type":2108,"url":5998},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9718",{"type":2108,"url":6000},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Ff7a31ea75e460e108c37126da1f47812f21f6b09",{"type":2105,"url":2712},{"type":2108,"url":3409},{"type":2105,"url":3411},{"type":2097,"url":6005},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jjj6-mw9f-p565",[2716,2717,2718,2719,2720,2721,2722,2723],{"id":248,"slug":6008,"dossier":45,"summary":6009,"aliases":6010,"sourceIds":6013,"published":6014,"modified":6015,"checkedAt":7,"severity":6016,"references":6018,"versionKeys":6031,"packageCount":32,"repositoryCount":32},"ghsa-jjph-296x-mrcr-0f661d67","Transformers vulnerable to ReDoS attack through its get_imports() function",[6011,6012],"CVE-2025-3264","PYSEC-2026-1985",[248,6012],"2025-07-07T12:30:22Z","2026-07-07T17:56:51.899728258Z",[6017],{"type":2093,"score":2921},[6019,6021,6023,6025,6026,6028,6029],{"type":2097,"url":6020},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3264",{"type":2108,"url":6022},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F0720e206c6ba28887e4d60ef60a6a089f6c1cc76",{"type":2108,"url":6024},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F126abe3461762e5fc180e7e614391d1b4ab051ca",{"type":2105,"url":2161},{"type":2108,"url":6027},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F3c6f7822-9992-476d-8cf0-b0b1623427df",{"type":2105,"url":2509},{"type":2097,"url":6030},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jjph-296x-mrcr",[2168],{"id":249,"slug":6033,"dossier":45,"summary":6034,"aliases":6035,"sourceIds":6038,"published":6039,"modified":6040,"checkedAt":7,"severity":6041,"references":6043,"versionKeys":6060,"packageCount":32,"repositoryCount":599},"ghsa-jm6w-m3j8-898g-326a1845","Unauthenticated remote shutdown in nltk.app.wordnet_app",[6036,6037],"CVE-2026-33231","PYSEC-2026-2236",[249,6037],"2026-03-19T12:42:20Z","2026-07-13T07:26:55.331693381Z",[6042],{"type":2093,"score":2277},[6044,6046,6048,6050,6051,6053,6055,6056,6057,6058],{"type":2163,"url":6045},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-jm6w-m3j8-898g",{"type":2097,"url":6047},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-33231",{"type":2102,"url":6049},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fcommit\u002Fbbaae83db86a0f49e00f5b0db44a7254c268de9b",{"type":2105,"url":2744},{"type":2108,"url":6052},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-33231",{"type":2108,"url":6054},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-33231.json",{"type":2097,"url":2752},{"type":2097,"url":5907},{"type":2097,"url":2754},{"type":2465,"url":6059},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2449836",[2758,2759],{"id":250,"slug":6062,"dossier":45,"summary":6063,"aliases":6064,"sourceIds":6065,"published":6066,"modified":6067,"checkedAt":7,"severity":6068,"references":6070,"versionKeys":6078,"packageCount":32,"repositoryCount":34},"ghsa-jm78-9fvv-mhgr-2c167ddc","GitPython: git-config OPTION-name injection via =\u002F#\u002Fwhitespace bypasses name validator, enabling forged core.sshCommand\u002FhooksPath (RCE)",[],[250],"2026-08-07T15:46:35Z","2026-08-09T02:56:51.296995647Z",[6069],{"type":2093,"score":2248},[6071,6073,6074,6076,6077],{"type":2108,"url":6072},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-jm78-9fvv-mhgr",{"type":2108,"url":2885},{"type":2108,"url":6075},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fa495ccd3b547ccd60b2187215823b72a9c0188bf",{"type":2105,"url":2257},{"type":2108,"url":2890},[2261,2262,2263],{"id":251,"slug":6080,"dossier":45,"summary":6081,"aliases":6082,"sourceIds":6085,"published":6086,"modified":6087,"checkedAt":7,"severity":6088,"references":6091,"versionKeys":6104,"packageCount":32,"repositoryCount":599},"ghsa-jp4c-xjxw-mgf9-e780c8d6","pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere",[6083,6084],"CVE-2026-6357","PYSEC-2026-2876",[251,6084],"2026-04-27T15:30:52Z","2026-07-13T16:43:01.316339792Z",[6089],{"type":2130,"score":6090},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:H\u002FUI:A\u002FVC:H\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[6092,6094,6096,6098,6099,6101,6102],{"type":2097,"url":6093},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-6357",{"type":2108,"url":6095},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fpull\u002F13923",{"type":2108,"url":6097},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fcommit\u002Fb369bfc96cc524e00c267e1693290e6599c36bad",{"type":2105,"url":3010},{"type":2108,"url":6100},"https:\u002F\u002Fichard26.github.io\u002Fblog\u002F2026\u002F04\u002Fwhats-new-in-pip-26.1\u002F#security-fixes",{"type":2105,"url":3018},{"type":2097,"url":6103},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jp4c-xjxw-mgf9",[3022,3023],{"id":252,"slug":6106,"dossier":45,"summary":6107,"aliases":6108,"sourceIds":6111,"published":6112,"modified":6113,"checkedAt":7,"severity":6114,"references":6118,"versionKeys":6126,"packageCount":32,"repositoryCount":530},"ghsa-jp82-jpqv-5vv3-4d50530e","Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname",[6109,6110],"CVE-2026-54282","PYSEC-2026-248",[252,6110],"2026-06-15T20:38:08Z","2026-07-15T22:30:44.498280076Z",[6115,6117],{"type":2093,"score":6116},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",{"type":2093,"score":2373},[6119,6121,6123,6124],{"type":2097,"url":6120},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-jp82-jpqv-5vv3",{"type":2097,"url":6122},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54282",{"type":2105,"url":4057},{"type":2108,"url":6125},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fstarlette\u002FPYSEC-2026-248.yaml",[2235,2236,2237,4064,4065,4172,4173],{"id":253,"slug":6128,"dossier":45,"summary":6129,"aliases":6130,"sourceIds":6133,"published":6134,"modified":6135,"checkedAt":7,"severity":6136,"references":6139,"versionKeys":6172,"packageCount":32,"repositoryCount":540},"ghsa-jr27-m4p2-rc6r-4991bc00","Denial of Service in pyasn1 via Unbounded Recursion",[6131,6132],"CVE-2026-30922","PYSEC-2026-2263",[253,6132],"2026-03-17T16:17:33Z","2026-07-21T15:30:39.553074080Z",[6137,6138],{"type":2093,"score":5157},{"type":2093,"score":2277},[6140,6142,6144,6146,6148,6149,6151,6153,6155,6157,6158,6160,6162,6164,6166,6168,6170],{"type":2163,"url":6141},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fsecurity\u002Fadvisories\u002FGHSA-jr27-m4p2-rc6r",{"type":2097,"url":6143},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-30922",{"type":2108,"url":6145},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002F5a49bd1fe93b5b866a1210f6bf0a3924f21572c8",{"type":2102,"url":6147},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002F25ad481c19fdb006e20485ef3fc2e5b3eff30ef0",{"type":2108,"url":2750},{"type":2108,"url":6150},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22970",{"type":2108,"url":6152},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22987",{"type":2108,"url":6154},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24761",{"type":2108,"url":6156},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24762",{"type":2108,"url":2754},{"type":2108,"url":6159},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:41928",{"type":2108,"url":6161},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:6309",{"type":2108,"url":6163},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:6568",{"type":2108,"url":6165},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:6720",{"type":2108,"url":6167},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:6912",{"type":2108,"url":6169},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:6926",{"type":2108,"url":6171},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F05\u002Fmsg00001.html",[3514],{"id":254,"slug":6174,"dossier":45,"summary":6175,"aliases":6176,"sourceIds":6179,"published":6180,"modified":6181,"checkedAt":7,"severity":6182,"references":6184,"versionKeys":6195,"packageCount":32,"repositoryCount":530},"ghsa-m4p7-r5rc-7g4j-889a943d","pyasn1 BER\u002FCER\u002FDER decoder denial of service via unbounded long-form tag IDs",[6177,6178],"CVE-2026-59884","PYSEC-2026-3455",[254,6178],"2026-07-14T17:17:14.750Z","2026-08-02T02:59:55.269509518Z",[6183],{"type":2093,"score":2277},[6185,6187,6189,6191,6192,6193],{"type":2097,"url":6186},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fsecurity\u002Fadvisories\u002FGHSA-m4p7-r5rc-7g4j",{"type":2097,"url":6188},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59884",{"type":2102,"url":6190},"https:\u002F\u002Fgithub.com\u002Fpyasn1\u002Fpyasn1\u002Fcommit\u002F628e36ecbb5277a3f01572ce418ef54271b165a5",{"type":2105,"url":3506},{"type":2097,"url":4374},{"type":2108,"url":6194},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpyasn1\u002FPYSEC-2026-3455.yaml",[3514,4376],{"id":255,"slug":6197,"dossier":45,"summary":6198,"aliases":6199,"sourceIds":6202,"published":6203,"modified":6204,"checkedAt":7,"severity":6205,"references":6210,"versionKeys":6219,"packageCount":32,"repositoryCount":2294},"ghsa-m5qp-6w8w-w647-495897bd","AIOHTTP has a Multipart Header Size Bypass",[6200,6201],"CVE-2026-34516","PYSEC-2026-2098",[255,6201],"2026-04-01T21:16:59.723Z","2026-07-13T07:26:19.821892403Z",[6206,6207,6208],{"type":2093,"score":2277},{"type":2130,"score":2831},{"type":2130,"score":6209},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:U\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[6211,6213,6215,6217,6218],{"type":2102,"url":6212},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-m5qp-6w8w-w647",{"type":2097,"url":6214},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34516",{"type":2102,"url":6216},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F8a74257b3804c9aac0bf644af93070f68f6c5a6f",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":256,"slug":6221,"dossier":45,"summary":6222,"aliases":6223,"sourceIds":6226,"published":6227,"modified":6228,"checkedAt":7,"severity":6229,"references":6232,"versionKeys":6238,"packageCount":32,"repositoryCount":2294},"ghsa-m6qw-4cw2-hm4m-3f6d3ee7","aiohttp: CRLF injection in multipart headers",[6224,6225],"CVE-2026-50269","PYSEC-2026-2106",[256,6225],"2026-06-15T20:07:26Z","2026-07-13T07:26:17.983947245Z",[6230,6231],{"type":2130,"score":2371},{"type":2093,"score":2277},[6233,6235,6237],{"type":2097,"url":6234},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-m6qw-4cw2-hm4m",{"type":2102,"url":6236},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fbf88077ebb14f4c29924b8e8904cba20c55c28b8",{"type":2105,"url":2282},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":257,"slug":6240,"dossier":45,"summary":6241,"aliases":6242,"sourceIds":6245,"published":6246,"modified":6247,"checkedAt":7,"severity":6248,"references":6251,"versionKeys":6259,"packageCount":32,"repositoryCount":599},"ghsa-mf9v-mfxr-j63j-1a7db6d4","urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API",[6243,6244],"CVE-2026-44432","PYSEC-2026-142",[257,6244],"2026-05-11T14:51:45Z","2026-06-08T20:00:12.284378628Z",[6249,6250],{"type":2093,"score":2277},{"type":2130,"score":2396},[6252,6254,6256,6258],{"type":2097,"url":6253},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-mf9v-mfxr-j63j",{"type":2097,"url":6255},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44432",{"type":2108,"url":6257},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Furllib3\u002FPYSEC-2026-142.yaml",{"type":2105,"url":2405},[6260],"pypi:urllib3@2.6.3",{"id":258,"slug":6262,"dossier":45,"summary":6263,"aliases":6264,"sourceIds":6267,"published":6268,"modified":6269,"checkedAt":7,"severity":6270,"references":6273,"versionKeys":6286,"packageCount":32,"repositoryCount":4918},"ghsa-mf9w-mj56-hr94-a492e0f4","python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback",[6265,6266],"CVE-2026-28684","PYSEC-2026-2270",[258,6266],"2026-04-20T17:16:33.087Z","2026-07-13T07:26:26.604845458Z",[6271],{"type":2093,"score":6272},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:H",[6274,6276,6278,6280,6282,6284],{"type":2102,"url":6275},"https:\u002F\u002Fgithub.com\u002Ftheskumar\u002Fpython-dotenv\u002Fsecurity\u002Fadvisories\u002FGHSA-mf9w-mj56-hr94",{"type":2097,"url":6277},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-28684",{"type":2102,"url":6279},"https:\u002F\u002Fgithub.com\u002Ftheskumar\u002Fpython-dotenv\u002Fcommit\u002F790c5c02991100aa1bf41ee5330aca75edc51311",{"type":2108,"url":6281},"https:\u002F\u002Fgithub.com\u002Ftheskumar\u002Fpython-dotenv\u002Fcommit\u002F790c5c02991100aa1bf41ee5330aca75edc51311.patch",{"type":2105,"url":6283},"https:\u002F\u002Fgithub.com\u002Ftheskumar\u002Fpython-dotenv",{"type":2097,"url":6285},"https:\u002F\u002Fgithub.com\u002Ftheskumar\u002Fpython-dotenv\u002Freleases\u002Ftag\u002Fv1.2.2",[6287,6288,6289,6290],"pypi:python-dotenv@1.0.1","pypi:python-dotenv@1.1.0","pypi:python-dotenv@1.1.1","pypi:python-dotenv@1.2.1",{"id":259,"slug":6292,"dossier":45,"summary":6293,"aliases":6294,"sourceIds":6297,"published":6298,"modified":6299,"checkedAt":7,"severity":6300,"references":6303,"versionKeys":6318,"packageCount":32,"repositoryCount":4918},"ghsa-mfx4-hv73-q22v-b33d9650","AIOHTTP: HTTP request smuggling via WebSocket upgrade",[6295,6296],"CVE-2026-69243","PYSEC-2026-3546",[259,6296],"2026-08-03T20:46:10Z","2026-08-04T21:26:59.595519014Z",[6301],{"type":2130,"score":6302},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[6304,6306,6308,6310,6311,6313,6314,6316],{"type":2108,"url":6305},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-mfx4-hv73-q22v",{"type":2108,"url":6307},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fpull\u002F13017",{"type":2108,"url":6309},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F6ae358f0983c3f4d6f67692b2f8e65dc8e091c98",{"type":2105,"url":2282},{"type":2108,"url":6312},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Freleases\u002Ftag\u002Fv3.14.2",{"type":2105,"url":3183},{"type":2097,"url":6315},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mfx4-hv73-q22v",{"type":2097,"url":6317},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-69243",[2286,2287,2288,2289,2290,2291,2292,2293,4917],{"id":260,"slug":6320,"dossier":45,"summary":6321,"aliases":6322,"sourceIds":6325,"published":6326,"modified":6327,"checkedAt":7,"severity":6328,"references":6330,"versionKeys":6339,"packageCount":32,"repositoryCount":64},"ghsa-mgf9-4vpg-hj56-00729355","tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)",[6323,6324],"CVE-2026-49855","PYSEC-2026-3389",[260,6324],"2026-06-15T20:19:28Z","2026-07-13T16:43:27.241564365Z",[6329],{"type":2093,"score":2277},[6331,6333,6334,6335,6337],{"type":2108,"url":6332},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-mgf9-4vpg-hj56",{"type":2105,"url":2647},{"type":2105,"url":2649},{"type":2097,"url":6336},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mgf9-4vpg-hj56",{"type":2097,"url":6338},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-49855",[2655,2656,2657,2658,2659],{"id":261,"slug":6341,"dossier":45,"summary":6342,"aliases":6343,"sourceIds":6346,"published":6347,"modified":6348,"checkedAt":7,"severity":6349,"references":6355,"versionKeys":6382,"packageCount":32,"repositoryCount":32},"ghsa-mq26-g339-26xf-ed024c7e","Command Injection in pip when used with Mercurial",[6344,6345],"CVE-2023-5752","PYSEC-2023-228",[261,6345],"2023-10-25T18:17:00Z","2026-06-10T17:01:27.606909654Z",[6350,6351,6353],{"type":2093,"score":5491},{"type":2130,"score":6352},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":6354},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",[6356,6358,6360,6362,6364,6365,6366,6368,6370,6372,6374,6376,6378,6380],{"type":2097,"url":6357},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-5752",{"type":2102,"url":6359},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fpull\u002F12306",{"type":2108,"url":6361},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fcommit\u002F389cb799d0da9a840749fcd14878928467ed49b4",{"type":2108,"url":6363},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpip\u002FPYSEC-2023-228.yaml",{"type":2105,"url":3010},{"type":2108,"url":3012},{"type":2108,"url":6367},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002F622OZXWG72ISQPLM5Y57YCVIMWHD4C3U",{"type":2108,"url":6369},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002F65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH",{"type":2108,"url":6371},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FFXUVMJM25PUAZRQZBF54OFVKTY3MINPW",{"type":2108,"url":6373},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FKFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E",{"type":2108,"url":6375},"https:\u002F\u002Flists.fedoraproject.org\u002Farchives\u002Flist\u002Fpackage-announce@lists.fedoraproject.org\u002Fmessage\u002FYBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ",{"type":2108,"url":6377},"https:\u002F\u002Fmail.python.org\u002Farchives\u002Flist\u002Fsecurity-announce@python.org\u002Fthread\u002FF4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL",{"type":2097,"url":6379},"https:\u002F\u002Fmail.python.org\u002Farchives\u002Flist\u002Fsecurity-announce@python.org\u002Fthread\u002FF4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL\u002F",{"type":2097,"url":6381},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mq26-g339-26xf",[3022],{"id":262,"slug":6384,"dossier":45,"summary":6385,"aliases":6386,"sourceIds":6389,"published":6390,"modified":6391,"checkedAt":7,"severity":6392,"references":6394,"versionKeys":6407,"packageCount":32,"repositoryCount":4918},"ghsa-mq44-7p77-q5h7-6bd0337a","AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate",[6387,6388],"CVE-2026-59881","PYSEC-2026-3547",[262,6388],"2026-08-03T20:40:55Z","2026-08-04T21:27:00.153248525Z",[6393],{"type":2130,"score":3551},[6395,6397,6399,6401,6403,6404,6405],{"type":2108,"url":6396},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-mq44-7p77-q5h7",{"type":2097,"url":6398},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59881",{"type":2108,"url":6400},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fpull\u002F12978",{"type":2108,"url":6402},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":6406},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mq44-7p77-q5h7",[2286,2287,2288,2289,2290,2291,2292,2293,4917],{"id":263,"slug":6409,"dossier":45,"summary":6410,"aliases":6411,"sourceIds":6414,"published":6415,"modified":6416,"checkedAt":7,"severity":6417,"references":6419,"versionKeys":6430,"packageCount":32,"repositoryCount":540},"ghsa-mqqc-3gqh-h2x8-6d702daf","AIOHTTP has unicode match groups in regexes for ASCII protocol elements",[6412,6413],"CVE-2025-69225","PYSEC-2026-1109",[263,6413],"2026-01-05T23:09:30Z","2026-07-07T17:56:18.569417663Z",[6418],{"type":2130,"score":2371},[6420,6422,6424,6426,6427,6428],{"type":2108,"url":6421},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-mqqc-3gqh-h2x8",{"type":2097,"url":6423},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69225",{"type":2102,"url":6425},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002Fc7b7a044f88c71cefda95ec75cdcfaa4792b3b96",{"type":2105,"url":2282},{"type":2105,"url":3183},{"type":2097,"url":6429},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-mqqc-3gqh-h2x8",[2286,2287,2288,2289,2290,2291,2292],{"id":264,"slug":6432,"dossier":45,"summary":6433,"aliases":6434,"sourceIds":6436,"published":6437,"modified":6438,"checkedAt":7,"severity":6439,"references":6441,"versionKeys":6447,"packageCount":32,"repositoryCount":34},"ghsa-mv93-w799-cj2w-4413137a","GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath",[6435],"CVE-2026-67326",[264],"2026-05-08T23:19:02Z","2026-08-02T03:56:45.346497199Z",[6440],{"type":2093,"score":2598},[6442,6444,6446],{"type":2108,"url":6443},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-mv93-w799-cj2w",{"type":2097,"url":6445},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rpm5-65cw-6hj4",{"type":2105,"url":2257},[2261,2262,2263],{"id":265,"slug":6449,"dossier":45,"summary":6450,"aliases":6451,"sourceIds":6454,"published":6455,"modified":6456,"checkedAt":7,"severity":6457,"references":6460,"versionKeys":6469,"packageCount":32,"repositoryCount":2294},"ghsa-mwh4-6h8g-pg8w-881420d8","AIOHTTP has HTTP response splitting via \\r in reason phrase",[6452,6453],"CVE-2026-34519","PYSEC-2026-2101",[265,6453],"2026-04-01T21:17:00.170Z","2026-07-13T07:26:39.246105773Z",[6458,6459],{"type":2130,"score":2371},{"type":2093,"score":2373},[6461,6463,6465,6467,6468],{"type":2102,"url":6462},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-mwh4-6h8g-pg8w",{"type":2097,"url":6464},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34519",{"type":2102,"url":6466},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F53b35a2f8869c37a133e60bf1a82a1c01642ba2b",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":266,"slug":6471,"dossier":45,"summary":6472,"aliases":6473,"sourceIds":6476,"published":6477,"modified":6478,"checkedAt":7,"severity":6479,"references":6481,"versionKeys":6498,"packageCount":32,"repositoryCount":599},"ghsa-p4gq-832x-fm9v-9f1db448","Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read",[6474,6475],"CVE-2026-54293","PYSEC-2026-2078",[266,6475],"2026-06-16T14:34:15Z","2026-07-21T12:46:29.659855804Z",[6480],{"type":2093,"score":3579},[6482,6484,6486,6488,6489,6491,6493,6494,6496],{"type":2163,"url":6483},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-p4gq-832x-fm9v",{"type":2097,"url":6485},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-54293",{"type":2102,"url":6487},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fpull\u002F3575",{"type":2108,"url":5131},{"type":2108,"url":6490},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-54293",{"type":2465,"url":6492},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2491486",{"type":2105,"url":2744},{"type":2108,"url":6495},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fnltk\u002FPYSEC-2026-2078.yaml",{"type":2108,"url":6497},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-54293.json",[2758,2759],{"id":267,"slug":6500,"dossier":45,"summary":6501,"aliases":6502,"sourceIds":6503,"published":6504,"modified":6505,"checkedAt":7,"severity":6506,"references":6509,"versionKeys":6519,"packageCount":32,"repositoryCount":34},"ghsa-p538-c434-8v24-c303e516","GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count",[],[267],"2026-08-03T20:23:17Z","2026-08-08T03:26:54.523343843Z",[6507],{"type":2093,"score":6508},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:L",[6510,6512,6514,6516,6517],{"type":2108,"url":6511},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-p538-c434-8v24",{"type":2108,"url":6513},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2184",{"type":2108,"url":6515},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F38553b6fddc7f6a667cdb45a6762343a08fc72b2",{"type":2105,"url":2257},{"type":2108,"url":6518},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.56",[2261,2262,2263],{"id":268,"slug":6521,"dossier":45,"summary":6522,"aliases":6523,"sourceIds":6526,"published":6527,"modified":6528,"checkedAt":7,"severity":6529,"references":6532,"versionKeys":6541,"packageCount":32,"repositoryCount":2294},"ghsa-p998-jp59-783m-17c88f0d","AIOHTTP affected by UNC SSRF\u002FNTLMv2 Credential Theft\u002FLocal File Read in static resource handler on Windows",[6524,6525],"CVE-2026-34515","PYSEC-2026-2097",[268,6525],"2026-04-01T21:16:59.570Z","2026-07-13T07:26:55.790859426Z",[6530,6531],{"type":2130,"score":5735},{"type":2093,"score":3579},[6533,6535,6537,6539,6540],{"type":2102,"url":6534},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-p998-jp59-783m",{"type":2097,"url":6536},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34515",{"type":2102,"url":6538},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F0ae2aa076c84573df83fc1fdc39eec0f5862fe3d",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":269,"slug":6543,"dossier":45,"summary":6544,"aliases":6545,"sourceIds":6549,"published":6550,"modified":6551,"checkedAt":7,"severity":6552,"references":6555,"versionKeys":6568,"packageCount":32,"repositoryCount":34},"ghsa-pg7v-jwj7-p798-7c77aab5","Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service",[6546,6547,6548],"BIT-pillow-2026-59203","CVE-2026-59203","PYSEC-2026-3452",[269,6548],"2026-07-14T16:17:02.063Z","2026-07-22T02:59:40.501589790Z",[6553,6554],{"type":2093,"score":2188},{"type":2093,"score":2277},[6556,6558,6560,6562,6564,6566,6567],{"type":2163,"url":6557},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-pg7v-jwj7-p798",{"type":2097,"url":6559},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59203",{"type":2102,"url":6561},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9708",{"type":2102,"url":6563},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F03992618118b4a76b6163cd72ab5ecd684133b83",{"type":2108,"url":6565},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-3452.yaml",{"type":2105,"url":2712},{"type":2097,"url":3409},[2721,2722,2723],{"id":270,"slug":6570,"dossier":45,"summary":6571,"aliases":6572,"sourceIds":6576,"published":6577,"modified":6578,"checkedAt":7,"severity":6579,"references":6582,"versionKeys":6595,"packageCount":32,"repositoryCount":618},"ghsa-pgqp-8h46-6x4j-303ca0ec","MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation",[6573,6574,6575],"BIT-mlflow-2025-14279","CVE-2025-14279","PYSEC-2026-1656",[270,6575],"2026-01-12T09:30:31Z","2026-07-07T17:56:18.060826978Z",[6580],{"type":2093,"score":6581},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[6583,6585,6587,6589,6590,6592,6593],{"type":2097,"url":6584},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-14279",{"type":2108,"url":6586},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F17910",{"type":2108,"url":6588},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002Fb0ffd289e9b0d0cc32c9e3a9b9f3843ae83dbec3",{"type":2105,"url":2679},{"type":2108,"url":6591},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fef478f72-2e4f-44dc-8055-fc06bef03108",{"type":2105,"url":2683},{"type":2097,"url":6594},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pgqp-8h46-6x4j",[2687,2688],{"id":271,"slug":6597,"dossier":45,"summary":6598,"aliases":6599,"sourceIds":6602,"published":6014,"modified":6603,"checkedAt":7,"severity":6604,"references":6607,"versionKeys":6620,"packageCount":32,"repositoryCount":618},"ghsa-phhr-52qp-3mj4-6f5d82e3","Transformers's Improper Input Validation vulnerability can be exploited through username injection",[6600,6601],"CVE-2025-3777","PYSEC-2026-1986",[271,6601],"2026-07-07T17:56:47.225461188Z",[6605],{"type":2093,"score":6606},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[6608,6610,6612,6613,6615,6617,6618],{"type":2097,"url":6609},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3777",{"type":2108,"url":6611},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F4dda5f71b35fb70cf602187eef84bb17a50b9082",{"type":2105,"url":2161},{"type":2108,"url":6614},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fblame\u002Fa7d2bbaaa8aac64f7c1ee8c1421cfe84b38359a4\u002Fsrc\u002Ftransformers\u002Fimage_utils.py",{"type":2108,"url":6616},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fccba0730-9248-4853-b7ff-5c20e6364f09",{"type":2105,"url":2509},{"type":2097,"url":6619},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-phhr-52qp-3mj4",[2168,2169],{"id":272,"slug":6622,"dossier":89,"summary":6623,"aliases":6624,"sourceIds":6628,"published":6629,"modified":6630,"checkedAt":7,"severity":6631,"references":6633,"versionKeys":6644,"packageCount":32,"repositoryCount":2416},"ghsa-phj9-mv4w-65pm-481e7dc3","Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`",[6625,6626,6627],"BIT-pillow-2026-55380","CVE-2026-55380","PYSEC-2026-2256",[272,6627],"2026-07-06T19:17:08.703Z","2026-07-22T02:59:41.562749940Z",[6632],{"type":2093,"score":2277},[6634,6636,6638,6640,6642,6643],{"type":2163,"url":6635},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-phj9-mv4w-65pm",{"type":2097,"url":6637},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55380",{"type":2102,"url":6639},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Ff39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675",{"type":2108,"url":6641},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-2256.yaml",{"type":2105,"url":2712},{"type":2097,"url":2714},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":273,"slug":6646,"dossier":45,"summary":6647,"aliases":6648,"sourceIds":6651,"published":6652,"modified":6653,"checkedAt":7,"severity":6654,"references":6656,"versionKeys":6668,"packageCount":32,"repositoryCount":540},"ghsa-pq67-6m6q-mj2v-3522d1d4","urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation",[6649,6650],"CVE-2025-50181","PYSEC-2026-1999",[273,6650],"2025-06-18T17:50:00Z","2026-07-07T17:56:41.872294653Z",[6655],{"type":2093,"score":2805},[6657,6659,6661,6663,6664,6665,6666],{"type":2108,"url":6658},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-pq67-6m6q-mj2v",{"type":2097,"url":6660},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-50181",{"type":2102,"url":6662},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fcommit\u002Ff05b1329126d5be6de501f9d1e3e36738bc08857",{"type":2105,"url":2405},{"type":2108,"url":2815},{"type":2105,"url":2407},{"type":2097,"url":6667},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pq67-6m6q-mj2v",[2411,2412,2413,2414],{"id":274,"slug":6670,"dossier":45,"summary":6671,"aliases":6672,"sourceIds":6675,"published":6676,"modified":6677,"checkedAt":7,"severity":6678,"references":6681,"versionKeys":6692,"packageCount":32,"repositoryCount":568},"ghsa-pr2v-jx2c-wg9f-1ca6d67c","Tornado vulnerable to Header Injection and XSS via reason argument",[6673,6674],"CVE-2025-67724","PYSEC-2025-265",[274,6674],"2025-12-12T06:15:41.213Z","2026-07-20T19:00:24.953994999Z",[6679,6680],{"type":2093,"score":3993},{"type":2093,"score":5517},[6682,6684,6686,6688,6690,6691],{"type":2097,"url":6683},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-pr2v-jx2c-wg9f",{"type":2097,"url":6685},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-67724",{"type":2102,"url":6687},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F9c163aebeaad9e6e7d28bac1f33580eb00b0e421",{"type":2108,"url":6689},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2025-265.yaml",{"type":2105,"url":2647},{"type":2097,"url":4802},[2655,2656,2657],{"id":275,"slug":6694,"dossier":45,"summary":6695,"aliases":6696,"sourceIds":6697,"published":6698,"modified":6699,"checkedAt":7,"severity":6700,"references":6703,"versionKeys":6707,"packageCount":32,"repositoryCount":64},"ghsa-pw6j-qg29-8w7f-fb4d7ed6","Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse",[],[275],"2026-06-15T20:37:24Z","2026-06-16T22:59:25.768721886Z",[6701],{"type":2093,"score":6702},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[6704,6706],{"type":2108,"url":6705},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-pw6j-qg29-8w7f",{"type":2105,"url":2647},[2655,2656,2657,2658,2659],{"id":276,"slug":6709,"dossier":89,"summary":6710,"aliases":6711,"sourceIds":6715,"published":6716,"modified":6717,"checkedAt":7,"severity":6718,"references":6721,"versionKeys":6733,"packageCount":32,"repositoryCount":2416},"ghsa-pwv6-vv43-88gr-c5f811d0","Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)",[6712,6713,6714],"BIT-pillow-2026-42311","CVE-2026-42311","PYSEC-2026-2252",[276,6714],"2026-05-04T20:20:31Z","2026-07-13T07:26:52.198871129Z",[6719,6720],{"type":2130,"score":4816},{"type":2093,"score":3657},[6722,6723,6725,6727,6729,6731,6732],{"type":2108,"url":4820},{"type":2102,"url":6724},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-pwv6-vv43-88gr",{"type":2097,"url":6726},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42311",{"type":2102,"url":6728},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9520",{"type":2102,"url":6730},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F58f9a1d166dcb0c274807d4423522d205b0c35ea",{"type":2105,"url":2712},{"type":2097,"url":3383},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":277,"slug":6735,"dossier":45,"summary":6736,"aliases":6737,"sourceIds":6740,"published":5587,"modified":6741,"checkedAt":7,"severity":6742,"references":6745,"versionKeys":6757,"packageCount":32,"repositoryCount":618},"ghsa-q2r8-vmq7-fpx2-63c75ef0","MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability",[6738,6739],"CVE-2026-2033","PYSEC-2026-2658",[277,6739],"2026-07-13T16:43:16.528255849Z",[6743],{"type":2093,"score":6744},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[6746,6748,6749,6750,6751,6752,6754,6755],{"type":2097,"url":6747},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2033",{"type":2108,"url":5596},{"type":2108,"url":5598},{"type":2105,"url":2679},{"type":2108,"url":5601},{"type":2108,"url":6753},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-26-105",{"type":2105,"url":2683},{"type":2097,"url":6756},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q2r8-vmq7-fpx2",[2687,2688],{"id":278,"slug":6759,"dossier":45,"summary":6760,"aliases":6761,"sourceIds":6764,"published":6014,"modified":6765,"checkedAt":7,"severity":6766,"references":6768,"versionKeys":6779,"packageCount":32,"repositoryCount":32},"ghsa-q2wp-rjmx-x6x9-43135d3d","Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking",[6762,6763],"CVE-2025-3263","PYSEC-2026-1987",[278,6763],"2026-07-07T17:56:57.889099913Z",[6767],{"type":2093,"score":2921},[6769,6771,6772,6773,6774,6776,6777],{"type":2097,"url":6770},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3263",{"type":2108,"url":6022},{"type":2108,"url":6024},{"type":2105,"url":2161},{"type":2108,"url":6775},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fc7a69150-54f8-4e81-8094-791e7a2a0f29",{"type":2105,"url":2509},{"type":2097,"url":6778},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q2wp-rjmx-x6x9",[2168],{"id":279,"slug":6781,"dossier":45,"summary":6782,"aliases":6783,"sourceIds":6786,"published":6787,"modified":6788,"checkedAt":7,"severity":6789,"references":6792,"versionKeys":6805,"packageCount":32,"repositoryCount":32},"ghsa-q2x7-8rv6-6q7h-1113a288","Jinja has a sandbox breakout through indirect reference to format method",[6784,6785],"CVE-2024-56326","PYSEC-2026-1475",[279,6785],"2024-12-23T17:56:08Z","2026-07-07T17:56:44.376174317Z",[6790,6791],{"type":2093,"score":4185},{"type":2130,"score":4868},[6793,6795,6797,6799,6800,6801,6802,6803],{"type":2108,"url":6794},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fsecurity\u002Fadvisories\u002FGHSA-q2x7-8rv6-6q7h",{"type":2097,"url":6796},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-56326",{"type":2102,"url":6798},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fjinja\u002Fcommit\u002F48b0687e05a5466a91cd5812d604fa37ad0943b4",{"type":2105,"url":4877},{"type":2108,"url":5575},{"type":2108,"url":4879},{"type":2105,"url":4883},{"type":2097,"url":6804},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q2x7-8rv6-6q7h",[4887],{"id":280,"slug":6807,"dossier":45,"summary":6808,"aliases":6809,"sourceIds":6813,"published":6814,"modified":6815,"checkedAt":7,"severity":6816,"references":6819,"versionKeys":6839,"packageCount":32,"repositoryCount":32},"ghsa-q34m-jh98-gwm2-76f8ef0b","Werkzeug possible resource exhaustion when parsing file data in forms",[6810,6811,6812],"CVE-2024-49767","PYSEC-2026-1860","PYSEC-2026-3417",[280,6812],"2024-10-25T19:44:43Z","2026-07-13T16:43:34.482065524Z",[6817,6818],{"type":2093,"score":2277},{"type":2130,"score":3551},[6820,6822,6824,6826,6828,6830,6832,6833,6834,6836,6837],{"type":2108,"url":6821},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fsecurity\u002Fadvisories\u002FGHSA-q34m-jh98-gwm2",{"type":2097,"url":6823},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-49767",{"type":2108,"url":6825},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fquart\u002Fcommit\u002F5e78c4169b8eb66b91ead3e62d44721b9e1644ee",{"type":2108,"url":6827},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fquart\u002Fcommit\u002Fabb04a512496206de279225340ed022852fbf51f",{"type":2108,"url":6829},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002F50cfeebcb0727e18cc52ffbeb125f4a66551179b",{"type":2108,"url":6831},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fwerkzeug\u002Fcommit\u002Fcbb446fdcada7685fce936ded01b76c08dbd6eb5",{"type":2105,"url":2197},{"type":2108,"url":5080},{"type":2108,"url":6835},"https:\u002F\u002Fsecurity.netapp.com\u002Fadvisory\u002Fntap-20250103-0007",{"type":2105,"url":2324},{"type":2097,"url":6838},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q34m-jh98-gwm2",[2201],{"id":281,"slug":6841,"dossier":89,"summary":6842,"aliases":6843,"sourceIds":6846,"published":6847,"modified":6848,"checkedAt":7,"severity":6849,"references":6853,"versionKeys":6859,"packageCount":32,"repositoryCount":5505},"ghsa-qccp-gfcp-xxvc-0d988969","urllib3: Sensitive headers forwarded across origins in proxied low-level redirects",[6844,6845],"CVE-2026-44431","PYSEC-2026-141",[281,6845],"2026-05-11T14:51:20Z","2026-05-20T09:19:20.983812Z",[6850,6851],{"type":2093,"score":4531},{"type":2130,"score":6852},"CVSS:4.0\u002FAV:N\u002FAC:H\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[6854,6856,6858],{"type":2097,"url":6855},"https:\u002F\u002Fgithub.com\u002Furllib3\u002Furllib3\u002Fsecurity\u002Fadvisories\u002FGHSA-qccp-gfcp-xxvc",{"type":2097,"url":6857},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44431",{"type":2105,"url":2405},[2411,2412,2413,2414,2415,6260],{"id":282,"slug":6861,"dossier":45,"summary":6862,"aliases":6863,"sourceIds":6867,"published":6868,"modified":6869,"checkedAt":7,"severity":6870,"references":6874,"versionKeys":6892,"packageCount":32,"repositoryCount":2294},"ghsa-qfhq-4f3w-5fph-33bc3f14","PyTorch is vulnerable to memory corruption through its torch.lstm_cell function",[6864,6865,6866],"BIT-pytorch-2025-3001","CVE-2025-3001","PYSEC-2025-195",[282],"2025-03-31T18:31:08Z","2026-06-10T18:26:26.736808954Z",[6871,6872],{"type":2093,"score":5012},{"type":2130,"score":6873},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[6875,6877,6879,6881,6883,6885,6886,6888,6890],{"type":2097,"url":6876},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3001",{"type":2108,"url":6878},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149626",{"type":2108,"url":6880},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149626#issue-2935860995",{"type":2108,"url":6882},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002F999d94b5ede5f4ec111ba7dd144129e2c2725b03",{"type":2108,"url":6884},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-195.yaml",{"type":2105,"url":2472},{"type":2108,"url":6887},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302050",{"type":2108,"url":6889},"https:\u002F\u002Fvuldb.com\u002F?id.302050",{"type":2108,"url":6891},"https:\u002F\u002Fvuldb.com\u002F?submit.524212",[2484,2485,2486,4320,4321,6893,6894,6895],"pypi:torch@2.8.0","pypi:torch@2.9.1","pypi:torch@2.9.1+cpu",{"id":283,"slug":6897,"dossier":45,"summary":6898,"aliases":6899,"sourceIds":6902,"published":6903,"modified":6904,"checkedAt":7,"severity":6905,"references":6908,"versionKeys":6921,"packageCount":32,"repositoryCount":64},"ghsa-qjxf-f2mg-c6mc-58d52008","Tornado is vulnerable to DoS due to too many multipart parts",[6900,6901],"CVE-2026-31958","PYSEC-2026-140",[283,6901],"2026-03-11T20:16:16.617Z","2026-06-08T20:00:14.385003861Z",[6906,6907],{"type":2093,"score":2277},{"type":2130,"score":4683},[6909,6911,6913,6915,6917,6918,6919],{"type":2097,"url":6910},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fsecurity\u002Fadvisories\u002FGHSA-qjxf-f2mg-c6mc",{"type":2097,"url":6912},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-31958",{"type":2108,"url":6914},"https:\u002F\u002Fgithub.com\u002Ftornadoweb\u002Ftornado\u002Fcommit\u002F119a195e290c43ad2d63a2cf012c29d43d6ed839",{"type":2108,"url":6916},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftornado\u002FPYSEC-2026-140.yaml",{"type":2105,"url":2647},{"type":2108,"url":4004},{"type":2108,"url":6920},"https:\u002F\u002Flists.debian.org\u002Fdebian-lts-announce\u002F2026\u002F04\u002Fmsg00000.html",[2655,2656,2657,2658],{"id":284,"slug":6923,"dossier":45,"summary":6924,"aliases":6925,"sourceIds":6928,"published":6929,"modified":6930,"checkedAt":7,"severity":6931,"references":6934,"versionKeys":6949,"packageCount":32,"repositoryCount":40},"ghsa-qmgc-5h2g-mvrw-199eacc8","filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock",[6926,6927],"CVE-2026-22701","PYSEC-2026-1374",[284,6927],"2026-01-13T18:44:55Z","2026-07-07T17:56:19.485233787Z",[6932],{"type":2093,"score":6933},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:H",[6935,6937,6939,6941,6943,6945,6947],{"type":2108,"url":6936},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fsecurity\u002Fadvisories\u002FGHSA-qmgc-5h2g-mvrw",{"type":2097,"url":6938},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22701",{"type":2108,"url":6940},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F255ed068bc85d1ef406e50a135e1459170dd1bf0",{"type":2108,"url":6942},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F41b42dd2c72aecf7da83dbda5903b8087dddc4d5",{"type":2105,"url":6944},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock",{"type":2105,"url":6946},"https:\u002F\u002Fpypi.org\u002Fproject\u002Ffilelock",{"type":2097,"url":6948},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qmgc-5h2g-mvrw",[6950,6951,6952,6953],"pypi:filelock@3.16.1","pypi:filelock@3.18.0","pypi:filelock@3.19.1","pypi:filelock@3.20.0",{"id":285,"slug":6955,"dossier":45,"summary":6956,"aliases":6957,"sourceIds":6960,"published":6961,"modified":6962,"checkedAt":7,"severity":6963,"references":6966,"versionKeys":6980,"packageCount":32,"repositoryCount":32},"ghsa-qq3j-4f4f-9583-cd76c72c","Hugging Face Transformers Regular Expression Denial of Service",[6958,6959],"CVE-2025-2099","PYSEC-2025-40",[285,6959],"2025-05-19T12:15:19Z","2026-06-10T17:02:48.111891265Z",[6964,6965],{"type":2093,"score":2921},{"type":2093,"score":2277},[6967,6969,6971,6973,6974,6976,6978],{"type":2097,"url":6968},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2099",{"type":2108,"url":6970},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F36648",{"type":2102,"url":6972},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F8cb522b4190bd556ce51be04942720650b1a3e57",{"type":2105,"url":2161},{"type":2108,"url":6975},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2025-40.yaml",{"type":2108,"url":6977},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F97b780f3-ffca-424f-ad5d-0e1c57a5bde4",{"type":2097,"url":6979},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qq3j-4f4f-9583",[2168],{"id":286,"slug":6982,"dossier":45,"summary":6983,"aliases":6984,"sourceIds":6987,"published":6988,"modified":6989,"checkedAt":7,"severity":6990,"references":6994,"versionKeys":7017,"packageCount":32,"repositoryCount":34},"ghsa-qrc4-49gv-mv9m-c7358be2","LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit",[6985,6986],"CVE-2026-47101","PYSEC-2026-2598",[286,6986],"2026-05-21T21:30:36Z","2026-07-13T16:42:56.741599701Z",[6991,6992],{"type":2093,"score":2248},{"type":2130,"score":6993},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N",[6995,6997,6999,7001,7003,7005,7006,7008,7010,7012,7014,7015],{"type":2097,"url":6996},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-47101",{"type":2108,"url":6998},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002F2220f3076ac89bd2a2e3439acf57dcfbec2434c9",{"type":2108,"url":7000},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002F5190bd07eb23a037745d86328096f54378f1614a",{"type":2108,"url":7002},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002Fd910a95661fce3cdd36f3b06c03ecf9c46c6457c",{"type":2108,"url":7004},"https:\u002F\u002Fgist.github.com\u002F13ph03nix\u002F9ec616e1fdc77b3673509c60206e827f",{"type":2105,"url":2860},{"type":2108,"url":7007},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Freleases\u002Ftag\u002Fv1.83.14-stable",{"type":2108,"url":7009},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F8e75edfb-ff05-4e63-bfca-2d93d03fb3b9",{"type":2108,"url":7011},"https:\u002F\u002Fwww.obsidiansecurity.com\u002Fblog\u002Flitellm-privilege-escalation-rce",{"type":2108,"url":7013},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Flitellm-privilege-escalation-via-api-key-generation",{"type":2105,"url":2864},{"type":2097,"url":7016},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qrc4-49gv-mv9m",[2868,2869,2870,2871],{"id":287,"slug":7019,"dossier":45,"summary":7020,"aliases":7021,"sourceIds":7024,"published":7025,"modified":7026,"checkedAt":7,"severity":7027,"references":7030,"versionKeys":7039,"packageCount":32,"repositoryCount":599},"ghsa-qvv7-cg9c-w4x3-da2ef5e7","Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download \u002F nltk.data.load) defeats ENFORCE mode",[7022,7023],"CVE-2026-12075","PYSEC-2026-3583",[287,7023],"2026-07-31T16:51:29Z","2026-08-06T15:11:52.346921403Z",[7028],{"type":2093,"score":7029},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[7031,7033,7034,7035,7037],{"type":2108,"url":7032},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-qvv7-cg9c-w4x3",{"type":2105,"url":2744},{"type":2105,"url":3702},{"type":2097,"url":7036},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qvv7-cg9c-w4x3",{"type":2097,"url":7038},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-12075",[2758,2759],{"id":288,"slug":7041,"dossier":45,"summary":5853,"aliases":7042,"sourceIds":7045,"published":7046,"modified":7047,"checkedAt":7,"severity":7048,"references":7052,"versionKeys":7066,"packageCount":32,"repositoryCount":32},"ghsa-qxrp-vhvm-j765-63c6e9a2",[7043,7044],"CVE-2024-11392","PYSEC-2024-227",[288,7044],"2024-11-22T22:15:06Z","2026-06-10T17:02:35.857656186Z",[7049,7051],{"type":2093,"score":7050},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2093,"score":4955},[7053,7055,7056,7057,7058,7060,7062,7064],{"type":2097,"url":7054},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-11392",{"type":2108,"url":5868},{"type":2108,"url":5870},{"type":2105,"url":2161},{"type":2108,"url":7059},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2024-227.yaml",{"type":2108,"url":7061},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1513",{"type":2097,"url":7063},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1513\u002F",{"type":2097,"url":7065},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-qxrp-vhvm-j765",[2168],{"id":289,"slug":7068,"dossier":45,"summary":7069,"aliases":7070,"sourceIds":7074,"published":7075,"modified":7076,"checkedAt":7,"severity":7077,"references":7079,"versionKeys":7092,"packageCount":32,"repositoryCount":618},"ghsa-r23q-823p-vmf7-9a5ef709","MLflow Command Injection vulnerability",[7071,7072,7073],"BIT-mlflow-2025-15379","CVE-2025-15379","PYSEC-2026-423",[289,7073],"2026-03-30T09:31:28Z","2026-07-01T20:22:58.350388Z",[7078],{"type":2093,"score":4116},[7080,7082,7084,7086,7087,7089,7090],{"type":2097,"url":7081},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-15379",{"type":2108,"url":7083},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F361b6f620adf98385c6721e384fb5ef9a30bb05e",{"type":2108,"url":7085},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002Fa22ce7157f646bdce4c95106fc38ccc9ca289205",{"type":2105,"url":2679},{"type":2108,"url":7088},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fdc9c1c20-7879-4050-87df-4d095fe5ca75",{"type":2105,"url":2683},{"type":2097,"url":7091},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-r23q-823p-vmf7",[2687,2688],{"id":290,"slug":7094,"dossier":45,"summary":7095,"aliases":7096,"sourceIds":7100,"published":7101,"modified":7102,"checkedAt":7,"severity":7103,"references":7106,"versionKeys":7117,"packageCount":32,"repositoryCount":599},"ghsa-r5m9-wm49-959f-62964e46","MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions",[7097,7098,7099],"BIT-mlflow-2026-3198","CVE-2026-3198","PYSEC-2026-2659",[290,7099],"2026-06-02T06:30:26Z","2026-07-13T16:42:37.733340178Z",[7104],{"type":2093,"score":7105},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[7107,7109,7111,7112,7114,7115],{"type":2097,"url":7108},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-3198",{"type":2108,"url":7110},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F6989066af33fdcb03588fd71a1a67f8fc5ef12c9",{"type":2105,"url":2679},{"type":2108,"url":7113},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fe57db731-97d3-40c3-a429-831ee959807f",{"type":2105,"url":2683},{"type":2097,"url":7116},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-r5m9-wm49-959f",[2687,2688,2689],{"id":291,"slug":7119,"dossier":45,"summary":7120,"aliases":7121,"sourceIds":7125,"published":7126,"modified":7127,"checkedAt":7,"severity":7128,"references":7131,"versionKeys":7145,"packageCount":32,"repositoryCount":2416},"ghsa-r73j-pqj5-w3x7-8d4d543f","Pillow has a PDF Parsing Trailer Infinite Loop (DoS)",[7122,7123,7124],"BIT-pillow-2026-42310","CVE-2026-42310","PYSEC-2026-2874",[291,7124],"2026-05-04T20:19:30Z","2026-07-13T16:42:37.358429541Z",[7129,7130],{"type":2093,"score":2460},{"type":2130,"score":3375},[7132,7134,7136,7138,7140,7141,7142,7143],{"type":2108,"url":7133},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-r73j-pqj5-w3x7",{"type":2097,"url":7135},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42310",{"type":2108,"url":7137},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9519",{"type":2108,"url":7139},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F3bf614e4b8615d0ce1d5039efaf6db447fe7c468",{"type":2105,"url":2712},{"type":2108,"url":3383},{"type":2105,"url":3411},{"type":2097,"url":7144},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-r73j-pqj5-w3x7",[2716,2717,2718,2719,2720,2721,2722,2723],{"id":292,"slug":7147,"dossier":45,"summary":7148,"aliases":7149,"sourceIds":7150,"published":7151,"modified":7152,"checkedAt":7,"severity":7153,"references":7155,"versionKeys":7163,"packageCount":32,"repositoryCount":34},"ghsa-r9mr-m37c-5fr3-d43000fc","GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution",[],[292],"2026-07-24T16:42:57Z","2026-07-25T21:44:41.709665254Z",[7154],{"type":2093,"score":2248},[7156,7158,7159,7161,7162],{"type":2108,"url":7157},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-r9mr-m37c-5fr3",{"type":2108,"url":3768},{"type":2108,"url":7160},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002Fe8d0fbf774d1f6baa3b481adfe48bd262e43b453",{"type":2105,"url":2257},{"type":2108,"url":3773},[2261,2262,2263],{"id":293,"slug":7165,"dossier":45,"summary":7166,"aliases":7167,"sourceIds":7170,"published":7171,"modified":7172,"checkedAt":7,"severity":7173,"references":7175,"versionKeys":7190,"packageCount":32,"repositoryCount":618},"ghsa-rcv9-qm8p-9p6j-edc1db04","Hugging Face Transformers library has Regular Expression Denial of Service",[7168,7169],"CVE-2025-6051","PYSEC-2026-1988",[293,7169],"2025-09-14T18:30:26Z","2026-07-07T17:56:51.178415128Z",[7174],{"type":2093,"score":2921},[7176,7178,7180,7182,7184,7185,7187,7188],{"type":2097,"url":7177},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6051",{"type":2108,"url":7179},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fpull\u002F38844",{"type":2108,"url":7181},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002F54a02160eb030da9be18231c77791f2eb3a52216",{"type":2108,"url":7183},"https:\u002F\u002Fgithub.com\u002Fhuggingface\u002Ftransformers\u002Fcommit\u002Fba8eaba9865618253f997784aa565b96206426f0",{"type":2105,"url":2161},{"type":2108,"url":7186},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Faf929523-7b59-418a-bf55-301830b2ac9d",{"type":2105,"url":2509},{"type":2097,"url":7189},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rcv9-qm8p-9p6j",[2168,2169],{"id":294,"slug":7192,"dossier":45,"summary":7193,"aliases":7194,"sourceIds":7195,"published":7196,"modified":7197,"checkedAt":7,"severity":7198,"references":7200,"versionKeys":7204,"packageCount":32,"repositoryCount":599},"ghsa-rf74-v2fm-23pw-dfe729f1","Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS",[],[294],"2026-03-18T20:17:43Z","2026-03-25T23:29:13.324989Z",[7199],{"type":2130,"score":3375},[7201,7203],{"type":2108,"url":7202},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-rf74-v2fm-23pw",{"type":2105,"url":2744},[2758,2759],{"id":295,"slug":7206,"dossier":45,"summary":7207,"aliases":7208,"sourceIds":7211,"published":7212,"modified":7213,"checkedAt":7,"severity":7214,"references":7217,"versionKeys":7230,"packageCount":32,"repositoryCount":40},"ghsa-rgxp-2hwp-jwgg-76cdda06","Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering",[7209,7210],"CVE-2026-25087","PYSEC-2026-113",[295,7210],"2026-02-17T14:16:01.947Z","2026-06-12T10:29:15.451071539Z",[7215],{"type":2093,"score":7216},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:H",[7218,7220,7222,7224,7226,7228],{"type":2097,"url":7219},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-25087",{"type":2102,"url":7221},"https:\u002F\u002Fgithub.com\u002Fapache\u002Farrow\u002Fpull\u002F48925",{"type":2105,"url":7223},"https:\u002F\u002Fgithub.com\u002Fapache\u002Farrow",{"type":2108,"url":7225},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpyarrow\u002FPYSEC-2026-113.yaml",{"type":2097,"url":7227},"https:\u002F\u002Flists.apache.org\u002Fthread\u002Fmpm4ld1qony30tchfpjtk5b11tcyvmwh",{"type":2097,"url":7229},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rgxp-2hwp-jwgg",[7231,7232,7233,7234],"pypi:pyarrow@18.1.0","pypi:pyarrow@20.0.0","pypi:pyarrow@21.0.0","pypi:pyarrow@22.0.0",{"id":296,"slug":7236,"dossier":45,"summary":7237,"aliases":7238,"sourceIds":7241,"published":7242,"modified":7243,"checkedAt":7,"severity":7244,"references":7246,"versionKeys":7254,"packageCount":32,"repositoryCount":34},"ghsa-rpm5-65cw-6hj4-6c97dd77","GitPython has Command Injection via Git options bypass",[7239,7240],"CVE-2026-42215","PYSEC-2026-2160",[296,7240],"2026-04-25T23:42:16Z","2026-07-13T07:26:42.486885613Z",[7245],{"type":2093,"score":2248},[7247,7249,7251,7252],{"type":2163,"url":7248},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-rpm5-65cw-6hj4",{"type":2097,"url":7250},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42215",{"type":2105,"url":2257},{"type":2102,"url":7253},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.47",[2261,2262,2263],{"id":297,"slug":7256,"dossier":45,"summary":7257,"aliases":7258,"sourceIds":7262,"published":5008,"modified":7263,"checkedAt":7,"severity":7264,"references":7267,"versionKeys":7285,"packageCount":32,"repositoryCount":40},"ghsa-rrmf-rvhw-rf47-389d8330","PyTorch is vulnerable to memory corruption through its torch.jit.script function",[7259,7260,7261],"BIT-pytorch-2025-3000","CVE-2025-3000","PYSEC-2025-194",[297],"2026-07-17T17:15:51.452848951Z",[7265,7266],{"type":2093,"score":5012},{"type":2130,"score":6873},[7268,7270,7272,7274,7276,7278,7279,7281,7283],{"type":2097,"url":7269},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-3000",{"type":2108,"url":7271},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149623",{"type":2108,"url":7273},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F149623#issue-2935703015",{"type":2108,"url":7275},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcommit\u002Fb90c94991cdf8b87c8f7439f79518e0ef2c4ca4f",{"type":2108,"url":7277},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-194.yaml",{"type":2105,"url":2472},{"type":2108,"url":7280},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302049",{"type":2108,"url":7282},"https:\u002F\u002Fvuldb.com\u002F?id.302049",{"type":2108,"url":7284},"https:\u002F\u002Fvuldb.com\u002F?submit.524197",[7286,2484,2485,2486,4320,4321,6893,6894,6895],"pypi:torch@2.10.0",{"id":298,"slug":7288,"dossier":45,"summary":7289,"aliases":7290,"sourceIds":7294,"published":7295,"modified":7296,"checkedAt":7,"severity":7297,"references":7300,"versionKeys":7313,"packageCount":32,"repositoryCount":599},"ghsa-rvhj-8chj-8v3c-edfd1899","Mlflow: Command Injection when serving models with enable_mlserver=True",[7291,7292,7293],"BIT-mlflow-2026-0596","CVE-2026-0596","PYSEC-2026-424",[298,7293],"2026-03-31T15:31:56Z","2026-07-01T20:22:58.365246Z",[7298],{"type":2093,"score":7299},"CVSS:3.0\u002FAV:A\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[7301,7303,7305,7307,7308,7310,7311],{"type":2097,"url":7302},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0596",{"type":2108,"url":7304},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F19738",{"type":2108,"url":7306},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F202fac4c83ccc8544c087c142b80196d0e60695c",{"type":2105,"url":2679},{"type":2108,"url":7309},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F2e905add-f9f5-4309-a3db-b17de5981285",{"type":2105,"url":2683},{"type":2097,"url":7312},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-rvhj-8chj-8v3c",[2687,2688,2689],{"id":299,"slug":7315,"dossier":45,"summary":7316,"aliases":7317,"sourceIds":7319,"published":7320,"modified":7321,"checkedAt":7,"severity":7322,"references":7324,"versionKeys":7334,"packageCount":32,"repositoryCount":34},"ghsa-rwj8-pgh3-r573-0bf779f8","GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL",[7318],"CVE-2026-67322",[299],"2026-07-21T22:06:09Z","2026-08-02T03:56:46.931996040Z",[7323],{"type":2093,"score":3579},[7325,7327,7329,7331,7332],{"type":2108,"url":7326},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-rwj8-pgh3-r573",{"type":2108,"url":7328},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fpull\u002F2172",{"type":2108,"url":7330},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F8ac5a30519b6f4af85398b9b9d7064ff4d452da2",{"type":2105,"url":2257},{"type":2108,"url":7333},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.52",[2261,2262,2263],{"id":300,"slug":7336,"dossier":45,"summary":7337,"aliases":7338,"sourceIds":7341,"published":7342,"modified":7343,"checkedAt":7,"severity":7344,"references":7346,"versionKeys":7354,"packageCount":32,"repositoryCount":34},"ghsa-v87r-6q3f-2j67-81913ca6","GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath",[7339,7340],"CVE-2026-44244","PYSEC-2026-2163",[300,7340],"2026-05-06T21:58:00Z","2026-07-13T07:26:38.585123077Z",[7345],{"type":2093,"score":4185},[7347,7349,7351,7352],{"type":2163,"url":7348},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-v87r-6q3f-2j67",{"type":2097,"url":7350},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44244",{"type":2105,"url":2257},{"type":2102,"url":7353},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Freleases\u002Ftag\u002F3.1.49",[2261,2262,2263],{"id":301,"slug":7356,"dossier":45,"summary":7357,"aliases":7358,"sourceIds":7361,"published":7362,"modified":7363,"checkedAt":7,"severity":7364,"references":7368,"versionKeys":7380,"packageCount":32,"repositoryCount":568},"ghsa-v92g-xgxw-vvmm-8ea08169","Mako: Path traversal via double-slash URI prefix in TemplateLookup",[7359,7360],"CVE-2026-41205","PYSEC-2026-88",[301,7360],"2026-04-16T21:16:40Z","2026-06-05T14:16:15.268937299Z",[7365,7366],{"type":2093,"score":3579},{"type":2130,"score":7367},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[7369,7371,7373,7375,7377,7378],{"type":2097,"url":7370},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Fsecurity\u002Fadvisories\u002FGHSA-v92g-xgxw-vvmm",{"type":2097,"url":7372},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41205",{"type":2108,"url":7374},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Fcommit\u002Fe05ac61989a7fb9dd7dcde6cfd72dc48328719a3",{"type":2108,"url":7376},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fmako\u002FPYSEC-2026-88.yaml",{"type":2105,"url":2350},{"type":2108,"url":7379},"https:\u002F\u002Fgithub.com\u002Fsqlalchemy\u002Fmako\u002Freleases\u002Ftag\u002Frel_1_3_11",[2358,2359],{"id":302,"slug":7382,"dossier":45,"summary":7383,"aliases":7384,"sourceIds":7388,"published":5008,"modified":7389,"checkedAt":7,"severity":7390,"references":7393,"versionKeys":7408,"packageCount":32,"repositoryCount":530},"ghsa-vgrw-7cvw-pwgx-766c6098","PyTorch is vulnerable to memory corruption through its unpack_sequence function",[7385,7386,7387],"BIT-pytorch-2025-2999","CVE-2025-2999","PYSEC-2025-193",[302],"2026-06-10T17:41:15.774477397Z",[7391,7392],{"type":2093,"score":5012},{"type":2130,"score":5014},[7394,7396,7397,7398,7399,7401,7402,7404,7406],{"type":2097,"url":7395},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2999",{"type":2108,"url":5019},{"type":2108,"url":5021},{"type":2108,"url":5023},{"type":2108,"url":7400},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-193.yaml",{"type":2105,"url":2472},{"type":2108,"url":7403},"https:\u002F\u002Fvuldb.com\u002F?ctiid.302048",{"type":2108,"url":7405},"https:\u002F\u002Fvuldb.com\u002F?id.302048",{"type":2108,"url":7407},"https:\u002F\u002Fvuldb.com\u002F?submit.524198",[2484,2485,2486,4320,4321,6893],{"id":303,"slug":7410,"dossier":45,"summary":7411,"aliases":7412,"sourceIds":7416,"published":7417,"modified":7418,"checkedAt":7,"severity":7419,"references":7422,"versionKeys":7432,"packageCount":32,"repositoryCount":599},"ghsa-vhcx-3pq2-4fvc-4147c43c","MLFlow path traversal vulnerability",[7413,7414,7415],"BIT-mlflow-2025-15036","CVE-2025-15036","PYSEC-2026-425",[303,7415],"2026-03-30T03:30:19Z","2026-07-01T20:22:58.380148Z",[7420],{"type":2093,"score":7421},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[7423,7425,7426,7427,7429,7430],{"type":2097,"url":7424},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-15036",{"type":2108,"url":5244},{"type":2105,"url":2679},{"type":2108,"url":7428},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F36c314cf-fd6e-4fb0-b9b0-1b47bcdf0eb0",{"type":2105,"url":2683},{"type":2097,"url":7431},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vhcx-3pq2-4fvc",[2687,2688,2689],{"id":304,"slug":7434,"dossier":45,"summary":7435,"aliases":7436,"sourceIds":7440,"published":7441,"modified":7442,"checkedAt":7,"severity":7443,"references":7445,"versionKeys":7459,"packageCount":32,"repositoryCount":2416},"ghsa-vjc4-5qp5-m44j-08063b19","Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service",[7437,7438,7439],"BIT-pillow-2026-59204","CVE-2026-59204","PYSEC-2026-3496",[304,7439],"2026-07-20T23:18:32Z","2026-07-23T15:11:20.720915099Z",[7444],{"type":2130,"score":4683},[7446,7448,7450,7452,7454,7455,7456,7457],{"type":2108,"url":7447},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-vjc4-5qp5-m44j",{"type":2097,"url":7449},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59204",{"type":2108,"url":7451},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9704",{"type":2108,"url":7453},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F13ada41172142f2fd9f0906f615a00ea623a11ca",{"type":2105,"url":2712},{"type":2108,"url":3409},{"type":2105,"url":3411},{"type":2097,"url":7458},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vjc4-5qp5-m44j",[2716,2717,2718,2719,2720,2721,2722,2723],{"id":305,"slug":7461,"dossier":45,"summary":7462,"aliases":7463,"sourceIds":7466,"published":7467,"modified":7468,"checkedAt":7,"severity":7469,"references":7472,"versionKeys":7485,"packageCount":32,"repositoryCount":599},"ghsa-vqfr-h8mv-ghfj-49515033","h11 accepts some malformed Chunked-Encoding bodies",[7464,7465],"CVE-2025-43859","PYSEC-2026-348",[305,7465],"2025-04-24T16:07:56Z","2026-07-01T20:22:54.082067Z",[7470],{"type":2093,"score":7471},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[7473,7475,7477,7479,7481,7483],{"type":2108,"url":7474},"https:\u002F\u002Fgithub.com\u002Fpython-hyper\u002Fh11\u002Fsecurity\u002Fadvisories\u002FGHSA-vqfr-h8mv-ghfj",{"type":2097,"url":7476},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-43859",{"type":2108,"url":7478},"https:\u002F\u002Fgithub.com\u002Fpython-hyper\u002Fh11\u002Fcommit\u002F114803a29ce50116dc47951c690ad4892b1a36ed",{"type":2105,"url":7480},"https:\u002F\u002Fgithub.com\u002Fpython-hyper\u002Fh11",{"type":2105,"url":7482},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fh11",{"type":2097,"url":7484},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vqfr-h8mv-ghfj",[7486],"pypi:h11@0.14.0",{"id":306,"slug":7488,"dossier":45,"summary":7489,"aliases":7490,"sourceIds":7493,"published":7494,"modified":7495,"checkedAt":7,"severity":7496,"references":7498,"versionKeys":7509,"packageCount":32,"repositoryCount":599},"ghsa-vvw2-h478-xwr3-e8568ce6","DSPy does not properly restrict file reads",[7491,7492],"CVE-2025-12695","PYSEC-2026-1318",[306,7492],"2025-11-04T15:31:35Z","2026-07-07T17:57:24.503135806Z",[7497],{"type":2093,"score":6702},[7499,7501,7503,7505,7507],{"type":2097,"url":7500},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-12695",{"type":2105,"url":7502},"https:\u002F\u002Fgithub.com\u002Fstanfordnlp\u002Fdspy",{"type":2108,"url":7504},"https:\u002F\u002Fresearch.jfrog.com\u002Fvulnerabilities\u002Fdspy-sandbox-escape-arbitrary-file-read-jfsa-2025-001495652",{"type":2105,"url":7506},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fdspy",{"type":2097,"url":7508},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-vvw2-h478-xwr3",[7510,7511,7512],"pypi:dspy@2.5.43","pypi:dspy@2.6.23","pypi:dspy@2.6.27",{"id":307,"slug":7514,"dossier":45,"summary":7515,"aliases":7516,"sourceIds":7519,"published":7520,"modified":7521,"checkedAt":7,"severity":7522,"references":7526,"versionKeys":7535,"packageCount":32,"repositoryCount":2294},"ghsa-w2fm-2cpv-w7v5-c2f7701a","aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage",[7517,7518],"CVE-2026-22815","PYSEC-2026-2094",[307,7518],"2026-04-01T19:45:17Z","2026-07-13T07:26:28.950069528Z",[7523,7524],{"type":2130,"score":3551},{"type":2130,"score":7525},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:N\u002FVI:N\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",[7527,7529,7531,7533,7534],{"type":2102,"url":7528},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-w2fm-2cpv-w7v5",{"type":2097,"url":7530},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-22815",{"type":2102,"url":7532},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F0c2e9da51126238a421568eb7c5b53e5b5d17b36",{"type":2105,"url":2282},{"type":2097,"url":2383},[2286,2287,2288,2289,2290,2291,2292,2293],{"id":308,"slug":7537,"dossier":45,"summary":7538,"aliases":7539,"sourceIds":7543,"published":7544,"modified":7545,"checkedAt":7,"severity":7546,"references":7548,"versionKeys":7558,"packageCount":32,"repositoryCount":599},"ghsa-w5xq-c4pf-ghq7-a926672a","MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks",[7540,7541,7542],"BIT-mlflow-2026-2734","CVE-2026-2734","PYSEC-2026-2660",[308,7542],"2026-05-21T06:31:31Z","2026-07-13T16:43:34.965176091Z",[7547],{"type":2093,"score":7105},[7549,7551,7552,7553,7555,7556],{"type":2097,"url":7550},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-2734",{"type":2108,"url":7110},{"type":2105,"url":2679},{"type":2108,"url":7554},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fd632f783-b2c7-4a3b-af5e-1d693e841c08",{"type":2105,"url":2683},{"type":2097,"url":7557},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-w5xq-c4pf-ghq7",[2687,2688,2689],{"id":309,"slug":7560,"dossier":45,"summary":7561,"aliases":7562,"sourceIds":7565,"published":7566,"modified":7567,"checkedAt":7,"severity":7568,"references":7571,"versionKeys":7588,"packageCount":32,"repositoryCount":40},"ghsa-w853-jp5j-5j7f-2786386f","filelock has a TOCTOU race condition which allows symlink attacks during lock file creation",[7563,7564],"CVE-2025-68146","PYSEC-2026-1375",[309,7564],"2025-12-16T20:52:55Z","2026-07-07T17:56:10.949145470Z",[7569],{"type":2093,"score":7570},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:H\u002FA:H",[7572,7574,7576,7577,7579,7581,7583,7584,7586],{"type":2108,"url":7573},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fsecurity\u002Fadvisories\u002FGHSA-w853-jp5j-5j7f",{"type":2108,"url":7575},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Fcommit\u002F4724d7f8c3393ec1f048c93933e6e3e6ec321f0e",{"type":2105,"url":6944},{"type":2108,"url":7578},"https:\u002F\u002Fgithub.com\u002Ftox-dev\u002Ffilelock\u002Freleases\u002Ftag\u002F3.20.1",{"type":2108,"url":7580},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Ffileio\u002Ffile-attribute-constants",{"type":2108,"url":7582},"https:\u002F\u002Fpubs.opengroup.org\u002Fonlinepubs\u002F9699919799\u002Ffunctions\u002Fopen.html",{"type":2105,"url":6946},{"type":2097,"url":7585},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-w853-jp5j-5j7f",{"type":2097,"url":7587},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68146",[6950,6951,6952,6953],{"id":310,"slug":7590,"dossier":45,"summary":7591,"aliases":7592,"sourceIds":7595,"published":7596,"modified":7597,"checkedAt":7,"severity":7598,"references":7601,"versionKeys":7612,"packageCount":32,"repositoryCount":64},"ghsa-w8v5-vhqr-4h9v-05062d37","DiskCache has unsafe pickle deserialization",[7593,7594],"CVE-2025-69872","PYSEC-2026-2447",[310,7594],"2026-02-11T21:30:39Z","2026-07-13T16:43:29.892158838Z",[7599],{"type":2130,"score":7600},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:A\u002FVC:H\u002FVI:H\u002FVA:H\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:P",[7602,7604,7606,7608,7610],{"type":2097,"url":7603},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-69872",{"type":2108,"url":7605},"https:\u002F\u002Fgithub.com\u002FEthanKim88\u002Fethan-cve-disclosures\u002Fblob\u002Fmain\u002FCVE-2025-69872-DiskCache-Pickle-Deserialization.md",{"type":2105,"url":7607},"https:\u002F\u002Fgithub.com\u002Fgrantjenks\u002Fpython-diskcache",{"type":2105,"url":7609},"https:\u002F\u002Fpypi.org\u002Fproject\u002Fdiskcache",{"type":2097,"url":7611},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-w8v5-vhqr-4h9v",[7613],"pypi:diskcache@5.6.3",{"id":311,"slug":7615,"dossier":45,"summary":7616,"aliases":7617,"sourceIds":7621,"published":7622,"modified":7623,"checkedAt":7,"severity":7624,"references":7626,"versionKeys":7635,"packageCount":32,"repositoryCount":618},"ghsa-wf7f-8fxf-xfxc-07509bf2","MLFlow unsafe deserialization",[7618,7619,7620],"BIT-mlflow-2024-37059","CVE-2024-37059","PYSEC-2026-1660",[311,7620],"2024-06-04T12:31:05Z","2026-07-07T17:56:49.672624556Z",[7625],{"type":2093,"score":4955},[7627,7629,7630,7632,7633],{"type":2097,"url":7628},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-37059",{"type":2105,"url":2679},{"type":2108,"url":7631},"https:\u002F\u002Fhiddenlayer.com\u002Fsai-security-advisory\u002Fmlflow-june2024",{"type":2105,"url":2683},{"type":2097,"url":7634},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wf7f-8fxf-xfxc",[2687,2688],{"id":312,"slug":7637,"dossier":45,"summary":7638,"aliases":7639,"sourceIds":7642,"published":7643,"modified":7644,"checkedAt":7,"severity":7645,"references":7651,"versionKeys":7686,"packageCount":32,"repositoryCount":599},"ghsa-wf93-45jw-7689-98dc514d","pip: Path traversal in console_scripts\u002Fgui_scripts entry point names allows installing scripts outside of target directory",[7640,7641],"CVE-2026-8643","PYSEC-2026-196",[312,7641],"2026-06-01T17:17:35.770Z","2026-07-14T02:29:29.982772188Z",[7646,7648,7650],{"type":2093,"score":7647},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2130,"score":7649},"CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:L\u002FUI:A\u002FVC:N\u002FVI:H\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",{"type":2093,"score":5491},[7652,7654,7656,7658,7660,7662,7664,7666,7668,7670,7672,7673,7675,7677,7679,7681,7682,7684],{"type":2097,"url":7653},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-8643",{"type":2102,"url":7655},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fpip\u002Fpull\u002F14000",{"type":2108,"url":7657},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:33313",{"type":2108,"url":7659},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34776",{"type":2108,"url":7661},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34777",{"type":2108,"url":7663},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34778",{"type":2108,"url":7665},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34780",{"type":2108,"url":7667},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:34891",{"type":2108,"url":7669},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:36193",{"type":2108,"url":7671},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:36315",{"type":2108,"url":2754},{"type":2108,"url":7674},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:37283",{"type":2108,"url":7676},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-8643",{"type":2108,"url":7678},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2460927",{"type":2108,"url":7680},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpip\u002FPYSEC-2026-196.yaml",{"type":2105,"url":3010},{"type":2097,"url":7683},"https:\u002F\u002Fmail.python.org\u002Farchives\u002Flist\u002Fsecurity-announce@python.org\u002Fthread\u002FYV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ\u002F",{"type":2097,"url":7685},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wf93-45jw-7689",[3022,3023],{"id":313,"slug":7688,"dossier":45,"summary":7689,"aliases":7690,"sourceIds":7693,"published":7694,"modified":7695,"checkedAt":7,"severity":7696,"references":7698,"versionKeys":7714,"packageCount":32,"repositoryCount":34},"ghsa-wgvc-ghv9-3pmm-9038f7ef","UltraJSON has a Memory Leak parsing large integers allows DoS",[7691,7692],"CVE-2026-32874","PYSEC-2026-2291",[313,7692],"2026-03-18T13:01:15Z","2026-07-13T07:26:54.389124194Z",[7697],{"type":2093,"score":2277},[7699,7701,7703,7705,7706,7708,7710,7712],{"type":2097,"url":7700},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fsecurity\u002Fadvisories\u002FGHSA-wgvc-ghv9-3pmm",{"type":2097,"url":7702},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-32874",{"type":2102,"url":7704},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Fcommit\u002F4baeb950df780092bd3c89fc702a868e99a3a1d2",{"type":2105,"url":2582},{"type":2097,"url":7707},"https:\u002F\u002Fgithub.com\u002Fultrajson\u002Fultrajson\u002Freleases\u002Ftag\u002F5.12.0",{"type":2108,"url":7709},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-32874",{"type":2108,"url":7711},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-32874.json",{"type":2465,"url":7713},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2449411",[2586],{"id":314,"slug":7716,"dossier":45,"summary":7717,"aliases":7718,"sourceIds":7722,"published":7723,"modified":7724,"checkedAt":7,"severity":7725,"references":7728,"versionKeys":7766,"packageCount":32,"repositoryCount":2416},"ghsa-whj4-6x5x-4v2j-eb5fc6a1","FITS GZIP decompression bomb in Pillow",[7719,7720,7721],"BIT-pillow-2026-40192","CVE-2026-40192","PYSEC-2026-2250",[314,7721],"2026-04-13T19:22:35Z","2026-07-13T07:26:24.246094941Z",[7726,7727],{"type":2093,"score":2277},{"type":2130,"score":4683},[7729,7731,7733,7735,7737,7738,7740,7742,7744,7746,7748,7750,7751,7753,7755,7757,7758,7760,7762,7764],{"type":2108,"url":7730},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-whj4-6x5x-4v2j",{"type":2097,"url":7732},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40192",{"type":2108,"url":7734},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9521",{"type":2108,"url":7736},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002F3cb854e8b2bab43f40e342e665f9340d861aa628",{"type":2105,"url":2712},{"type":2108,"url":7739},"https:\u002F\u002Fpillow.readthedocs.io\u002Fen\u002Fstable\u002Freleasenotes\u002F12.2.0.html#prevent-fits-decompression-bomb",{"type":2108,"url":7741},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-40192",{"type":2108,"url":7743},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-40192.json",{"type":2097,"url":7745},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16008",{"type":2097,"url":7747},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16009",{"type":2097,"url":7749},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:16030",{"type":2097,"url":4842},{"type":2097,"url":7752},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:17609",{"type":2097,"url":7754},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:17611",{"type":2097,"url":7756},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:19375",{"type":2097,"url":2752},{"type":2097,"url":7759},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:21017",{"type":2097,"url":7761},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22465",{"type":2097,"url":7763},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22629",{"type":2097,"url":7765},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:22840",[2716,2717,2718,2719,2720,2721,2722,2723],{"id":315,"slug":7768,"dossier":45,"summary":7769,"aliases":7770,"sourceIds":7774,"published":7775,"modified":7776,"checkedAt":7,"severity":7777,"references":7780,"versionKeys":7789,"packageCount":32,"repositoryCount":2416},"ghsa-wjx4-4jcj-g98j-e937161b","Pillow has an integer overflow when processing fonts",[7771,7772,7773],"BIT-pillow-2026-42308","CVE-2026-42308","PYSEC-2026-165",[315,7773],"2026-05-04T20:18:45Z","2026-06-08T23:45:16.414580348Z",[7778,7779],{"type":2093,"score":2460},{"type":2130,"score":3375},[7781,7783,7785,7787,7788],{"type":2097,"url":7782},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-wjx4-4jcj-g98j",{"type":2097,"url":7784},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42308",{"type":2108,"url":7786},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2026-165.yaml",{"type":2105,"url":2712},{"type":2097,"url":3383},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":316,"slug":7791,"dossier":45,"summary":7792,"aliases":7793,"sourceIds":7796,"published":7797,"modified":7798,"checkedAt":7,"severity":7799,"references":7802,"versionKeys":7821,"packageCount":32,"repositoryCount":34},"ghsa-wpfp-gwwc-vwq6-53d5ec36","LiteLLM allows a user to modify their own user_role via the \u002Fuser\u002Fupdate endpoint",[7794,7795],"CVE-2026-47102","PYSEC-2026-2600",[316,7795],"2026-05-21T21:30:37Z","2026-07-13T16:43:25.135559552Z",[7800,7801],{"type":2093,"score":2248},{"type":2130,"score":6993},[7803,7805,7807,7809,7811,7812,7813,7814,7815,7816,7818,7819],{"type":2097,"url":7804},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-47102",{"type":2108,"url":7806},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fpull\u002F25541",{"type":2108,"url":7808},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002F128d32d2494b759c5d15da3452452af4c6a34c01",{"type":2108,"url":7810},"https:\u002F\u002Fgithub.com\u002FBerriAI\u002Flitellm\u002Fcommit\u002Fe6f18ce75b111c9b93dc15c72894cbdeb53177ce",{"type":2108,"url":7004},{"type":2105,"url":2860},{"type":2108,"url":2862},{"type":2108,"url":7009},{"type":2108,"url":7011},{"type":2108,"url":7817},"https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Flitellm-privilege-escalation-via-user-update",{"type":2105,"url":2864},{"type":2097,"url":7820},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wpfp-gwwc-vwq6",[2868,2869,2870,2871],{"id":317,"slug":7823,"dossier":45,"summary":7824,"aliases":7825,"sourceIds":7828,"published":7829,"modified":7830,"checkedAt":7,"severity":7831,"references":7833,"versionKeys":7855,"packageCount":32,"repositoryCount":530},"ghsa-wqp7-x3pw-xc5r-4caabf81","Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows",[7826,7827],"CVE-2026-48818","PYSEC-2026-2281",[317,7827],"2026-06-15T20:16:30Z","2026-07-13T07:26:44.976412482Z",[7832],{"type":2093,"score":3579},[7834,7836,7837,7839,7841,7843,7845,7847,7849,7851,7853],{"type":2097,"url":7835},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-wqp7-x3pw-xc5r",{"type":2105,"url":4057},{"type":2108,"url":7838},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-48818",{"type":2108,"url":7840},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-48818.json",{"type":2097,"url":7842},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:30087",{"type":2097,"url":7844},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:30088",{"type":2097,"url":7846},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:30089",{"type":2097,"url":7848},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Freleases\u002Ftag\u002F1.1.0",{"type":2465,"url":7850},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2490020",{"type":2102,"url":7852},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fcommit\u002Ffd53168a7767b6b55ba5af787fd88f49e33cabc5",{"type":2102,"url":7854},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fpull\u002F3287",[2235,2236,2237,4064,4065,4172,4173],{"id":318,"slug":7857,"dossier":45,"summary":5853,"aliases":7858,"sourceIds":7861,"published":5858,"modified":7862,"checkedAt":7,"severity":7863,"references":7866,"versionKeys":7880,"packageCount":32,"repositoryCount":32},"ghsa-wrfc-pvp9-mr9g-c6b03ddf",[7859,7860],"CVE-2024-11393","PYSEC-2024-228",[318,7860],"2026-06-10T17:00:13.252500033Z",[7864,7865],{"type":2093,"score":5862},{"type":2093,"score":4955},[7867,7869,7870,7871,7872,7874,7876,7878],{"type":2097,"url":7868},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-11393",{"type":2108,"url":5868},{"type":2108,"url":5870},{"type":2105,"url":2161},{"type":2108,"url":7873},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftransformers\u002FPYSEC-2024-228.yaml",{"type":2108,"url":7875},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1514",{"type":2097,"url":7877},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-24-1514\u002F",{"type":2097,"url":7879},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-wrfc-pvp9-mr9g",[2168],{"id":319,"slug":7882,"dossier":45,"summary":7883,"aliases":7884,"sourceIds":7885,"published":7886,"modified":7887,"checkedAt":7,"severity":7888,"references":7890,"versionKeys":7898,"packageCount":32,"repositoryCount":34},"ghsa-wvpp-8hx9-p66j-188b3951","GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution",[],[319],"2026-08-07T15:49:07Z","2026-08-09T02:56:51.363626854Z",[7889],{"type":2093,"score":2248},[7891,7893,7894,7896,7897],{"type":2108,"url":7892},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-wvpp-8hx9-p66j",{"type":2108,"url":2885},{"type":2108,"url":7895},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fcommit\u002F96a888f4d782cb2f80452148e48e60ce4af6d541",{"type":2105,"url":2257},{"type":2108,"url":2890},[2261,2262,2263],{"id":320,"slug":7900,"dossier":45,"summary":7901,"aliases":7902,"sourceIds":7905,"published":7906,"modified":7907,"checkedAt":7,"severity":7908,"references":7912,"versionKeys":7921,"packageCount":32,"repositoryCount":34},"ghsa-x2qx-6953-8485-107f8fe2","GitPython: Unsafe option check validates multi_options before shlex.split transformation",[7903,7904],"CVE-2026-42284","PYSEC-2026-2161",[320,7904],"2026-04-25T23:41:49Z","2026-07-13T07:26:44.494568822Z",[7909,7911],{"type":2093,"score":7910},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":2093,"score":3035},[7913,7915,7917,7918,7919],{"type":2163,"url":7914},"https:\u002F\u002Fgithub.com\u002Fgitpython-developers\u002FGitPython\u002Fsecurity\u002Fadvisories\u002FGHSA-x2qx-6953-8485",{"type":2097,"url":7916},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-42284",{"type":2105,"url":2257},{"type":2102,"url":7253},{"type":2108,"url":7920},"https:\u002F\u002Fwww.tenable.com\u002Fcve\u002FCVE-2026-32686",[2261,2262,2263],{"id":321,"slug":7923,"dossier":45,"summary":7924,"aliases":7925,"sourceIds":7929,"published":7930,"modified":7931,"checkedAt":7,"severity":7932,"references":7937,"versionKeys":7953,"packageCount":32,"repositoryCount":618},"ghsa-x3gm-94wq-g975-a197ba31","PyTorch: Manipulation of the argument scale\u002Fzero_point leads to improper initialization via Quantized Sigmoid Module",[7926,7927,7928],"BIT-pytorch-2025-2149","CVE-2025-2149","PYSEC-2025-190",[321],"2025-03-10T15:30:47Z","2026-06-09T22:11:08.734544854Z",[7933,7935],{"type":2093,"score":7934},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N",{"type":2130,"score":7936},"CVSS:4.0\u002FAV:L\u002FAC:H\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:N\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[7938,7940,7942,7944,7946,7947,7949,7951],{"type":2097,"url":7939},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-2149",{"type":2108,"url":7941},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147818",{"type":2108,"url":7943},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147818#issue-2877301660",{"type":2108,"url":7945},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Ftorch\u002FPYSEC-2025-190.yaml",{"type":2105,"url":2472},{"type":2108,"url":7948},"https:\u002F\u002Fvuldb.com\u002F?ctiid.299060",{"type":2108,"url":7950},"https:\u002F\u002Fvuldb.com\u002F?id.299060",{"type":2108,"url":7952},"https:\u002F\u002Fvuldb.com\u002F?submit.506563",[2484,2485],{"id":322,"slug":7955,"dossier":45,"summary":7956,"aliases":7957,"sourceIds":7960,"published":7961,"modified":7962,"checkedAt":7,"severity":7963,"references":7965,"versionKeys":7972,"packageCount":32,"repositoryCount":530},"ghsa-x746-7m8f-x49c-c0349d3f","Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`",[7958,7959],"CVE-2026-48817","PYSEC-2026-2280",[322,7959],"2026-06-15T20:16:05Z","2026-07-13T07:26:54.069698774Z",[7964],{"type":2093,"score":2373},[7966,7968,7970,7971],{"type":2097,"url":7967},"https:\u002F\u002Fgithub.com\u002FKludex\u002Fstarlette\u002Fsecurity\u002Fadvisories\u002FGHSA-x746-7m8f-x49c",{"type":2097,"url":7969},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-48817",{"type":2105,"url":4057},{"type":2097,"url":7848},[2235,2236,2237,4064,4065,4172,4173],{"id":323,"slug":7974,"dossier":45,"summary":7975,"aliases":7976,"sourceIds":7979,"published":7980,"modified":7981,"checkedAt":7,"severity":7982,"references":7985,"versionKeys":7991,"packageCount":32,"repositoryCount":2294},"ghsa-xcgm-r5h9-7989-77bcbc26","aiohttp: Incomplete websocket frame payloads bypass memory limits",[7977,7978],"CVE-2026-54274","PYSEC-2026-2108",[323,7978],"2026-06-15T20:11:22Z","2026-07-13T07:26:54.330692251Z",[7983,7984],{"type":2130,"score":2831},{"type":2093,"score":2277},[7986,7988,7989],{"type":2097,"url":7987},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fsecurity\u002Fadvisories\u002FGHSA-xcgm-r5h9-7989",{"type":2105,"url":2282},{"type":2102,"url":7990},"https:\u002F\u002Fgithub.com\u002Faio-libs\u002Faiohttp\u002Fcommit\u002F14b6ee851fb16ec199acb950de0c82d476799e7d",[2286,2287,2288,2289,2290,2291,2292,2293],{"id":324,"slug":7993,"dossier":45,"summary":7994,"aliases":7995,"sourceIds":7999,"published":8000,"modified":8001,"checkedAt":7,"severity":8002,"references":8004,"versionKeys":8018,"packageCount":32,"repositoryCount":618},"ghsa-xch3-2f9x-wh9f-70e88660","MLflow has a command injection in mlflow\u002Fsagemaker\u002F__init__.py",[7996,7997,7998],"BIT-mlflow-2025-14287","CVE-2025-14287","PYSEC-2026-2661",[324,7998],"2026-03-16T15:30:41Z","2026-07-13T16:42:49.591762139Z",[8003],{"type":2093,"score":7050},[8005,8007,8009,8011,8012,8013,8015,8016],{"type":2097,"url":8006},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-14287",{"type":2108,"url":8008},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fpull\u002F19277",{"type":2108,"url":8010},"https:\u002F\u002Fgithub.com\u002Fmlflow\u002Fmlflow\u002Fcommit\u002F8b8792a7034fb33a14b0b31cabcaa9b912d3485f",{"type":2105,"url":2679},{"type":2108,"url":5601},{"type":2108,"url":8014},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F229cd526-41aa-4819-b6f0-e2d0371c89e3",{"type":2105,"url":2683},{"type":2097,"url":8017},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-xch3-2f9x-wh9f",[2687,2688],{"id":325,"slug":8020,"dossier":45,"summary":8021,"aliases":8022,"sourceIds":8023,"published":8024,"modified":8025,"checkedAt":7,"severity":8026,"references":8028,"versionKeys":8035,"packageCount":32,"repositoryCount":599},"ghsa-xf7x-x43h-rpqh-c5648b04","json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS",[],[325],"2026-07-13T23:41:39Z","2026-07-13T23:45:11.773964507Z",[8027],{"type":2093,"score":2277},[8029,8031,8033],{"type":2108,"url":8030},"https:\u002F\u002Fgithub.com\u002Fmangiucugna\u002Fjson_repair\u002Fsecurity\u002Fadvisories\u002FGHSA-xf7x-x43h-rpqh",{"type":2105,"url":8032},"https:\u002F\u002Fgithub.com\u002Fmangiucugna\u002Fjson_repair",{"type":2108,"url":8034},"https:\u002F\u002Fgithub.com\u002Fmangiucugna\u002Fjson_repair\u002Freleases\u002Ftag\u002Fv0.60.1",[8036,8037,8038],"pypi:json-repair@0.35.0","pypi:json-repair@0.44.1","pypi:json-repair@0.47.6",{"id":326,"slug":8040,"dossier":45,"summary":8041,"aliases":8042,"sourceIds":8046,"published":8047,"modified":8048,"checkedAt":7,"severity":8049,"references":8051,"versionKeys":8065,"packageCount":32,"repositoryCount":34},"ghsa-xg8h-j46f-w952-da36a616","Pillow vulnerability can cause write buffer overflow on BCn encoding",[8043,8044,8045],"BIT-pillow-2025-48379","CVE-2025-48379","PYSEC-2025-61",[326,8045],"2025-07-01T17:29:37Z","2026-02-04T03:49:31.268130Z",[8050],{"type":2093,"score":3914},[8052,8054,8056,8058,8060,8062,8063],{"type":2097,"url":8053},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-xg8h-j46f-w952",{"type":2097,"url":8055},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-48379",{"type":2108,"url":8057},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9041",{"type":2102,"url":8059},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fef98b3510e3e4f14b547762764813d7e5ca3c5a4",{"type":2108,"url":8061},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fpillow\u002FPYSEC-2025-61.yaml",{"type":2105,"url":2712},{"type":2108,"url":8064},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Freleases\u002Ftag\u002F11.3.0",[2719],{"id":327,"slug":8067,"dossier":45,"summary":8068,"aliases":8069,"sourceIds":8072,"published":8073,"modified":8074,"checkedAt":7,"severity":8075,"references":8077,"versionKeys":8086,"packageCount":32,"repositoryCount":599},"ghsa-xh95-f55m-82fw-6e557f3c","Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)",[8070,8071],"CVE-2026-12074","PYSEC-2026-3584",[327,8071],"2026-07-31T16:50:41Z","2026-08-06T15:11:52.598451868Z",[8076],{"type":2093,"score":3579},[8078,8080,8081,8082,8084],{"type":2108,"url":8079},"https:\u002F\u002Fgithub.com\u002Fnltk\u002Fnltk\u002Fsecurity\u002Fadvisories\u002FGHSA-xh95-f55m-82fw",{"type":2105,"url":2744},{"type":2105,"url":3702},{"type":2097,"url":8083},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-xh95-f55m-82fw",{"type":2097,"url":8085},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-12074",[2758,2759],{"id":328,"slug":8088,"dossier":45,"summary":8089,"aliases":8090,"sourceIds":8094,"published":8095,"modified":8096,"checkedAt":7,"severity":8097,"references":8100,"versionKeys":8111,"packageCount":32,"repositoryCount":2416},"ghsa-xj96-63gp-2gmr-85e1cf15","Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`",[8091,8092,8093],"BIT-pillow-2026-59197","CVE-2026-59197","PYSEC-2026-3454",[328,8093],"2026-07-14T17:17:14.487Z","2026-07-22T11:11:36.231472645Z",[8098],{"type":2093,"score":8099},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:H",[8101,8103,8105,8107,8109,8110],{"type":2163,"url":8102},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fsecurity\u002Fadvisories\u002FGHSA-xj96-63gp-2gmr",{"type":2097,"url":8104},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59197",{"type":2102,"url":8106},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fpull\u002F9695",{"type":2102,"url":8108},"https:\u002F\u002Fgithub.com\u002Fpython-pillow\u002FPillow\u002Fcommit\u002Fcce3bdb867c77a3420261ed1bfdb6b0787ec8fc1",{"type":2105,"url":2712},{"type":2097,"url":3409},[2716,2717,2718,2719,2720,2721,2722,2723],{"id":329,"slug":8113,"dossier":45,"summary":381,"aliases":8114,"sourceIds":8117,"published":8118,"modified":8119,"checkedAt":7,"severity":8120,"references":8122,"versionKeys":8131,"packageCount":32,"repositoryCount":618},"pysec-2025-198-62b25ed4",[8115,8116],"BIT-pytorch-2025-46148","CVE-2025-46148",[329],"2025-09-25T15:16:12.007Z","2026-05-20T09:19:19.437232Z",[8121],{"type":2093,"score":4531},[8123,8125,8127,8129],{"type":2097,"url":8124},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F4bcefba4004f8271e64b5185c95a248a",{"type":2097,"url":8126},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F65a587a579dfdff887b9b35bb79b9093",{"type":2465,"url":8128},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151198",{"type":2102,"url":8130},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F152993",[2484,2485],{"id":330,"slug":8133,"dossier":45,"summary":381,"aliases":8134,"sourceIds":8137,"published":8138,"modified":8139,"checkedAt":7,"severity":8140,"references":8142,"versionKeys":8148,"packageCount":32,"repositoryCount":32},"pysec-2025-199-c528cb5a",[8135,8136],"BIT-pytorch-2025-46149","CVE-2025-46149",[330],"2025-09-25T15:16:12.153Z","2026-05-20T09:19:19.498677Z",[8141],{"type":2093,"score":4531},[8143,8144,8146],{"type":2097,"url":8124},{"type":2465,"url":8145},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147848",{"type":2102,"url":8147},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F147961",[2485],{"id":331,"slug":8150,"dossier":45,"summary":381,"aliases":8151,"sourceIds":8154,"published":8155,"modified":8156,"checkedAt":7,"severity":8157,"references":8159,"versionKeys":8167,"packageCount":32,"repositoryCount":32},"pysec-2025-200-d11172cd",[8152,8153],"BIT-pytorch-2025-46150","CVE-2025-46150",[331],"2025-09-25T15:16:12.303Z","2026-05-20T09:19:19.559970Z",[8158],{"type":2093,"score":4531},[8160,8161,8163,8165],{"type":2097,"url":8124},{"type":2465,"url":8162},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F141538",{"type":2465,"url":8164},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F141538#issuecomment-2537424658",{"type":2102,"url":8166},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F144395",[2485],{"id":332,"slug":8169,"dossier":45,"summary":381,"aliases":8170,"sourceIds":8173,"published":8174,"modified":8175,"checkedAt":7,"severity":8176,"references":8178,"versionKeys":8184,"packageCount":32,"repositoryCount":32},"pysec-2025-201-c002b022",[8171,8172],"BIT-pytorch-2025-46152","CVE-2025-46152",[332],"2025-09-25T15:16:12.470Z","2026-05-20T09:19:19.618679Z",[8177],{"type":2093,"score":2188},[8179,8180,8182],{"type":2097,"url":8124},{"type":2465,"url":8181},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F143555",{"type":2102,"url":8183},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F143635",[2485],{"id":333,"slug":8186,"dossier":45,"summary":381,"aliases":8187,"sourceIds":8190,"published":8191,"modified":8192,"checkedAt":7,"severity":8193,"references":8195,"versionKeys":8205,"packageCount":32,"repositoryCount":32},"pysec-2025-202-f0ff1751",[8188,8189],"BIT-pytorch-2025-46153","CVE-2025-46153",[333],"2025-09-25T15:16:12.603Z","2026-05-20T09:19:19.678555Z",[8194],{"type":2093,"score":4531},[8196,8198,8199,8201,8203],{"type":2108,"url":8197},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fcompare\u002Fv2.6.0...v2.7.0",{"type":2097,"url":8124},{"type":2097,"url":8200},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002Fe636f2e7a306105b7e96809e2b85c28a",{"type":2465,"url":8202},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F142853",{"type":2102,"url":8204},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F143460",[2485],{"id":334,"slug":8207,"dossier":45,"summary":381,"aliases":8208,"sourceIds":8211,"published":8212,"modified":8213,"checkedAt":7,"severity":8214,"references":8216,"versionKeys":8221,"packageCount":32,"repositoryCount":530},"pysec-2025-203-2febb201",[8209,8210],"BIT-pytorch-2025-55551","CVE-2025-55551",[334],"2025-09-25T15:16:12.887Z","2026-05-20T09:19:19.739357Z",[8215],{"type":2093,"score":2277},[8217,8219],{"type":2097,"url":8218},"https:\u002F\u002Fgist.github.com\u002Fshaoyuyoung\u002F0e7d2a586297ae9c8ed14d8706749efc",{"type":2465,"url":8220},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151401",[2484,2485,2486,4320,4321,6893],{"id":335,"slug":8223,"dossier":45,"summary":381,"aliases":8224,"sourceIds":8227,"published":8228,"modified":8229,"checkedAt":7,"severity":8230,"references":8232,"versionKeys":8236,"packageCount":32,"repositoryCount":530},"pysec-2025-204-cdae47da",[8225,8226],"BIT-pytorch-2025-55552","CVE-2025-55552",[335],"2025-09-25T16:15:34.320Z","2026-05-20T09:19:19.802802Z",[8231],{"type":2093,"score":2277},[8233,8234],{"type":2097,"url":8218},{"type":2465,"url":8235},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F147847",[2484,2485,2486,4320,4321,6893],{"id":336,"slug":8238,"dossier":45,"summary":381,"aliases":8239,"sourceIds":8242,"published":8243,"modified":8244,"checkedAt":7,"severity":8245,"references":8247,"versionKeys":8253,"packageCount":32,"repositoryCount":599},"pysec-2025-205-fd5e58fd",[8240,8241],"BIT-pytorch-2025-55553","CVE-2025-55553",[336],"2025-09-25T16:15:34.460Z","2026-05-20T09:19:19.866970Z",[8246],{"type":2093,"score":2277},[8248,8249,8251],{"type":2097,"url":8218},{"type":2465,"url":8250},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151432",{"type":2102,"url":8252},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F154645",[2484,2485,2486],{"id":337,"slug":8255,"dossier":45,"summary":381,"aliases":8256,"sourceIds":8259,"published":8260,"modified":8261,"checkedAt":7,"severity":8262,"references":8264,"versionKeys":8268,"packageCount":32,"repositoryCount":530},"pysec-2025-206-58322476",[8257,8258],"BIT-pytorch-2025-55554","CVE-2025-55554",[337],"2025-09-25T16:15:34.593Z","2026-05-20T09:19:19.928295Z",[8263],{"type":2093,"score":2188},[8265,8266],{"type":2097,"url":8218},{"type":2465,"url":8267},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151510",[2484,2485,2486,4320,4321,6893],{"id":338,"slug":8270,"dossier":45,"summary":381,"aliases":8271,"sourceIds":8274,"published":8275,"modified":8276,"checkedAt":7,"severity":8277,"references":8279,"versionKeys":8285,"packageCount":32,"repositoryCount":599},"pysec-2025-207-2abef3fc",[8272,8273],"BIT-pytorch-2025-55557","CVE-2025-55557",[338],"2025-09-25T16:15:34.833Z","2026-05-20T09:19:19.989717Z",[8278],{"type":2093,"score":2277},[8280,8281,8283],{"type":2097,"url":8218},{"type":2465,"url":8282},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151738",{"type":2102,"url":8284},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151931",[2484,2485,2486],{"id":339,"slug":8287,"dossier":45,"summary":381,"aliases":8288,"sourceIds":8291,"published":8292,"modified":8293,"checkedAt":7,"severity":8294,"references":8296,"versionKeys":8302,"packageCount":32,"repositoryCount":599},"pysec-2025-208-6e93fe9d",[8289,8290],"BIT-pytorch-2025-55558","CVE-2025-55558",[339],"2025-09-25T16:15:34.960Z","2026-05-20T09:19:20.054109Z",[8295],{"type":2093,"score":2277},[8297,8298,8300],{"type":2097,"url":8218},{"type":2465,"url":8299},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151523",{"type":2102,"url":8301},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151887",[2484,2485,2486],{"id":340,"slug":8304,"dossier":45,"summary":381,"aliases":8305,"sourceIds":8308,"published":8309,"modified":8310,"checkedAt":7,"severity":8311,"references":8313,"versionKeys":8319,"packageCount":32,"repositoryCount":599},"pysec-2025-209-e6f352b0",[8306,8307],"BIT-pytorch-2025-55560","CVE-2025-55560",[340],"2025-09-25T16:15:35.197Z","2026-05-20T09:19:20.117285Z",[8312],{"type":2093,"score":2277},[8314,8315,8317],{"type":2097,"url":8218},{"type":2465,"url":8316},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F151522",{"type":2102,"url":8318},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F151897",[2484,2485,2486],{"id":341,"slug":8321,"dossier":45,"summary":381,"aliases":8322,"sourceIds":8324,"published":8325,"modified":8326,"checkedAt":7,"severity":8327,"references":8329,"versionKeys":8332,"packageCount":32,"repositoryCount":599},"pysec-2025-211-d8bd15de",[8323],"CVE-2025-14920",[341],"2025-12-23T21:15:47.183Z","2026-05-21T15:00:32.080516132Z",[8328],{"type":2093,"score":2154},[8330],{"type":2097,"url":8331},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1150\u002F",[2168,2169,2170],{"id":342,"slug":8334,"dossier":45,"summary":381,"aliases":8335,"sourceIds":8337,"published":8338,"modified":8339,"checkedAt":7,"severity":8340,"references":8342,"versionKeys":8345,"packageCount":32,"repositoryCount":599},"pysec-2025-212-a011b97d",[8336],"CVE-2025-14921",[342],"2025-12-23T21:15:47.340Z","2026-05-21T15:00:32.052313357Z",[8341],{"type":2093,"score":2154},[8343],{"type":2097,"url":8344},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1149\u002F",[2168,2169,2170],{"id":343,"slug":8347,"dossier":45,"summary":381,"aliases":8348,"sourceIds":8350,"published":8351,"modified":8352,"checkedAt":7,"severity":8353,"references":8355,"versionKeys":8358,"packageCount":32,"repositoryCount":599},"pysec-2025-213-9043dc9b",[8349],"CVE-2025-14924",[343],"2025-12-23T21:15:47.600Z","2026-05-21T15:00:32.048516839Z",[8354],{"type":2093,"score":2154},[8356],{"type":2097,"url":8357},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1141\u002F",[2168,2169,2170],{"id":344,"slug":8360,"dossier":45,"summary":381,"aliases":8361,"sourceIds":8363,"published":8364,"modified":8365,"checkedAt":7,"severity":8366,"references":8368,"versionKeys":8371,"packageCount":32,"repositoryCount":599},"pysec-2025-214-eb241255",[8362],"CVE-2025-14926",[344],"2025-12-23T21:15:47.857Z","2026-05-21T15:00:32.929011749Z",[8367],{"type":2093,"score":2154},[8369],{"type":2097,"url":8370},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1147\u002F",[2168,2169,2170],{"id":345,"slug":8373,"dossier":45,"summary":381,"aliases":8374,"sourceIds":8376,"published":8377,"modified":8378,"checkedAt":7,"severity":8379,"references":8381,"versionKeys":8384,"packageCount":32,"repositoryCount":599},"pysec-2025-215-6064f491",[8375],"CVE-2025-14927",[345],"2025-12-23T21:15:47.987Z","2026-05-21T15:00:32.888290877Z",[8380],{"type":2093,"score":2154},[8382],{"type":2097,"url":8383},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1148\u002F",[2168,2169,2170],{"id":346,"slug":8386,"dossier":45,"summary":381,"aliases":8387,"sourceIds":8389,"published":8390,"modified":8391,"checkedAt":7,"severity":8392,"references":8394,"versionKeys":8397,"packageCount":32,"repositoryCount":599},"pysec-2025-216-5708ed01",[8388],"CVE-2025-14928",[346],"2025-12-23T21:15:48.110Z","2026-05-21T15:00:32.939311939Z",[8393],{"type":2093,"score":2154},[8395],{"type":2097,"url":8396},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1146\u002F",[2168,2169,2170],{"id":347,"slug":8399,"dossier":45,"summary":381,"aliases":8400,"sourceIds":8402,"published":8403,"modified":8404,"checkedAt":7,"severity":8405,"references":8407,"versionKeys":8410,"packageCount":32,"repositoryCount":530},"pysec-2025-217-2c1ad388",[8401],"CVE-2025-14929",[347],"2025-12-23T21:15:48.240Z","2026-05-21T15:00:24.271970226Z",[8406],{"type":2093,"score":2154},[8408],{"type":2097,"url":8409},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1144\u002F",[2168,2169,2170,2171,2172,2173,2174],{"id":348,"slug":8412,"dossier":45,"summary":381,"aliases":8413,"sourceIds":8415,"published":8416,"modified":8417,"checkedAt":7,"severity":8418,"references":8420,"versionKeys":8423,"packageCount":32,"repositoryCount":568},"pysec-2025-218-39811fc3",[8414],"CVE-2025-14930",[348],"2025-12-23T21:15:48.367Z","2026-05-21T15:00:33.791364554Z",[8419],{"type":2093,"score":2154},[8421],{"type":2097,"url":8422},"https:\u002F\u002Fwww.zerodayinitiative.com\u002Fadvisories\u002FZDI-25-1145\u002F",[2168,2169,2170,2171],{"id":349,"slug":8425,"dossier":45,"summary":381,"aliases":8426,"sourceIds":8429,"published":8430,"modified":8431,"checkedAt":7,"severity":8432,"references":8434,"versionKeys":8445,"packageCount":32,"repositoryCount":40},"pysec-2026-139-96951ff6",[8427,8428],"BIT-pytorch-2026-4538","CVE-2026-4538",[349],"2026-03-22T05:16:20.273Z","2026-05-21T15:00:31.962442644Z",[8433],{"type":2093,"score":4185},[8435,8437,8439,8441,8443],{"type":2108,"url":8436},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002F",{"type":2097,"url":8438},"https:\u002F\u002Fvuldb.com\u002F?id.352326",{"type":2097,"url":8440},"https:\u002F\u002Fvuldb.com\u002F?submit.774681",{"type":2465,"url":8442},"https:\u002F\u002Fvuldb.com\u002F?ctiid.352326",{"type":2102,"url":8444},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fpull\u002F176791",[7286,2484,2485,2486,4320,4321,6893,6894,6895],{"id":350,"slug":8447,"dossier":45,"summary":381,"aliases":8448,"sourceIds":8450,"published":8451,"modified":8452,"checkedAt":7,"severity":8453,"references":8455,"versionKeys":8458,"packageCount":32,"repositoryCount":599},"pysec-2026-2085-e081ac1d",[8449],"CVE-2026-12252",[350],"2026-07-04T02:16:23.603Z","2026-07-09T12:00:05.700183399Z",[8454],{"type":2093,"score":2154},[8456],{"type":2163,"url":8457},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Ff5c93982-0cc9-4e2e-bb85-1b6ab29a2efb",[2758,2759],{"id":351,"slug":8460,"dossier":89,"summary":381,"aliases":8461,"sourceIds":8464,"published":8465,"modified":8466,"checkedAt":7,"severity":8467,"references":8470,"versionKeys":8483,"packageCount":32,"repositoryCount":5641},"pysec-2026-2132-627bf7c7",[8462,8463],"CVE-2026-7246","GHSA-47fr-3ffg-hgmw",[351],"2026-04-30T14:16:36.433Z","2026-07-13T07:15:21.899333658Z",[8468],{"type":2093,"score":8469},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:H\u002FUI:R\u002FS:C\u002FC:H\u002FI:H\u002FA:H",[8471,8473,8475,8476,8477,8479,8481],{"type":2108,"url":8472},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-7246",{"type":2108,"url":8474},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-7246.json",{"type":2097,"url":6154},{"type":2097,"url":6156},{"type":2465,"url":8478},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2464121",{"type":2102,"url":8480},"https:\u002F\u002Fgithub.com\u002Fpallets\u002Fclick\u002Freleases\u002Ftag\u002F8.3.3",{"type":2163,"url":8482},"https:\u002F\u002Fgithub.com\u002Ftsigouris007\u002Fsecurity-advisories\u002Fsecurity\u002Fadvisories\u002FGHSA-47fr-3ffg-hgmw",[8484,8485,8486,8487,8488,8489],"pypi:click@8.1.7","pypi:click@8.1.8","pypi:click@8.2.0","pypi:click@8.2.1","pypi:click@8.3.0","pypi:click@8.3.1",{"id":352,"slug":8491,"dossier":45,"summary":381,"aliases":8492,"sourceIds":8497,"published":8498,"modified":8499,"checkedAt":7,"severity":8500,"references":8502,"versionKeys":8518,"packageCount":32,"repositoryCount":2294},"pysec-2026-2286-8795b007",[8493,8494,8495,8496],"BIT-pytorch-2026-24747","CVE-2026-24747","GHSA-63cw-57p8-fm3p","PYSEC-2026-1856",[352],"2026-01-27T22:15:56.470Z","2026-07-13T07:26:23.701611780Z",[8501],{"type":2093,"score":4955},[8503,8505,8507,8508,8510,8512,8514,8516],{"type":2108,"url":8504},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-24747",{"type":2108,"url":8506},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-24747.json",{"type":2097,"url":5907},{"type":2097,"url":8509},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Freleases\u002Ftag\u002Fv2.10.0",{"type":2097,"url":8511},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fsecurity\u002Fadvisories\u002FGHSA-63cw-57p8-fm3p",{"type":2465,"url":8513},"https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2433612",{"type":2465,"url":8515},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002Fissues\u002F163105",{"type":2102,"url":8517},"https:\u002F\u002Fgithub.com\u002Fpytorch\u002Fpytorch\u002F163122\u002Fcommit\u002F954dc5183ee9205cbe79876ad05dd2d9ae752139",[2484,2485,2486,4320,4321,6893,6894,6895],{"id":353,"slug":8520,"dossier":45,"summary":381,"aliases":8521,"sourceIds":8523,"published":8524,"modified":8525,"checkedAt":7,"severity":8526,"references":8528,"versionKeys":8531,"packageCount":32,"repositoryCount":599},"pysec-2026-597-f85c09cd",[8522],"CVE-2026-12243",[353],"2026-06-30T01:16:29.063Z","2026-07-01T18:15:06.027046365Z",[8527],{"type":2093,"score":2672},[8529],{"type":2163,"url":8530},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F39aa9354-54ca-4e77-96da-580eb1fe6ed1",[2758,2759],{"id":354,"slug":8533,"dossier":45,"summary":381,"aliases":8534,"sourceIds":8536,"published":8537,"modified":8538,"checkedAt":7,"severity":8539,"references":8541,"versionKeys":8544,"packageCount":32,"repositoryCount":599},"pysec-2026-99-2c63e84f",[8535],"CVE-2026-0848",[354],"2026-03-05T21:16:14.263Z","2026-05-20T09:19:09.284207Z",[8540],{"type":2093,"score":4116},[8542],{"type":2163,"url":8543},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F08b109bb-ac24-403f-9422-1c246ce60202",[2758,2759],1786588639074]