f13/microservices/datastoreThis dossier retains 119 exact component occurrences from 3 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:6595b6f54571e9af6cc1d55f3a760e5ca4e6191eb5043f8cea081d53d833f9e6pypi:openai2.45.0pypi:aiohttp3.14.333 OSV records returnedpypi:pyjwt2.15.120 OSV records returnedpypi:urllib32.7.010 OSV records returnedpypi:cryptography50.0.09 OSV records returnedpypi:python-multipart0.0.328 OSV records returnedpypi:starlette1.3.18 OSV records returnedpypi:virtualenv21.7.15 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:mcp1.29.03 OSV records returnedpypi:requests2.34.23 OSV records returnedpypi:anyio4.14.22 OSV records returnedpypi:filelock3.32.22 OSV records returnedpypi:protobuf7.35.12 OSV records returnedpypi:certifi2026.6.171 OSV record returnedpypi:click8.4.21 OSV record returnedpypi:h110.16.01 OSV record returnedpypi:idna3.181 OSV record returnedpypi:pydantic-settings2.14.21 OSV record returnedpypi:pygments2.20.01 OSV record returnedpypi:pytest9.1.11 OSV record returnedpypi:python-dotenv1.2.21 OSV record returnedpypi:tqdm4.68.41 OSV record returnedpypi:aiohappyeyeballs2.7.1pypi:aiosignal1.4.0pypi:amqp5.3.1pypi:annotated-doc0.0.4pypi:annotated-types0.7.0pypi:ast-serialize0.6.0pypi:attrs26.1.0pypi:billiard4.2.4pypi:boolean-py5.0pypi:boto31.43.46pypi:botocore1.43.46pypi:celery5.6.3pypi:celery-types0.26.0pypi:cffi2.1.0pypi:cfgv3.5.0pypi:charset-normalizer3.4.9pypi:click-didyoumean0.3.1pypi:click-plugins1.1.1.2pypi:click-repl0.3.0pypi:colorama0.4.6pypi:coverage7.15.1pypi:distlib0.4.3pypi:distro1.9.0pypi:events0.5pypi:fastapi0.139.0pypi:fastapi-mcp0.4.0pypi:frozenlist1.8.0pypi:grpcio1.82.1pypi:httpcore1.0.9pypi:httptools0.8.0pypi:httpx0.28.1pypi:httpx-sse0.4.3pypi:identify2.6.19pypi:iniconfig2.3.0pypi:jiter0.16.0pypi:jmespath1.1.0pypi:jsonschema4.26.0pypi:jsonschema-specifications2025.9.1pypi:kombu5.6.2pypi:librt0.13.0pypi:license-expression30.4.4pypi:markdown-it-py4.2.0pypi:markupsafe3.0.3pypi:mdurl0.1.2pypi:multidict6.7.1pypi:mypy2.3.0pypi:mypy-extensions1.1.0pypi:nodeenv1.10.0pypi:opensearch-protobufs1.2.0pypi:opensearch-py3.2.0pypi:packaging26.2pypi:pathspec1.1.1pypi:platformdirs4.11.0pypi:pluggy1.6.0pypi:pre-commit4.5.1pypi:prompt-toolkit3.0.52pypi:propcache0.5.2pypi:pycparser3.0pypi:pydantic2.13.4pypi:pydantic-core2.46.4pypi:pytest-asyncio1.4.0pypi:pytest-cov7.1.0pypi:python-dateutil2.9.0.post0pypi:python-debian1.1.1pypi:python-discovery1.5.0pypi:python-magic0.4.27pypi:pywin32312pypi:pyyaml6.0.3pypi:referencing0.37.0pypi:respx0.23.1pypi:reuse6.2.0pypi:rich15.0.0pypi:rpds-py2026.6.3pypi:ruff0.15.21pypi:s3transfer0.19.1pypi:shellingham1.5.4pypi:six1.17.0pypi:sniffio1.3.1pypi:sse-starlette3.4.5pypi:tenacity9.1.4pypi:tomli2.4.1pypi:tomlkit0.15.0pypi:typer0.26.8pypi:typing-extensions4.16.0pypi:typing-inspection0.4.2pypi:tzdata2026.3pypi:tzlocal5.4.4pypi:uvicorn0.51.0pypi:uvloop0.22.1pypi:vine5.1.0pypi:watchfiles1.2.0pypi:wcwidth0.8.2pypi:websockets16.1pypi:yarl1.24.2Certifi removes GLOBALTRUST root certificate
10 Sept 2026Starlette has possible denial-of-service vector when parsing large files in multipart forms
10 Sept 2026aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
10 Sept 2026PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
30 Sept 2026AIOHTTP has CRLF injection through multipart part content type header construction
10 Sept 2026urllib3 streaming API improperly handles highly compressed data
25 Sept 2026Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
10 Sept 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
10 Sept 2026PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
30 Sept 2026urllib3 does not control redirects in browsers and Node.js
10 Sept 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
10 Sept 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
10 Sept 2026pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
10 Sept 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
10 Sept 2026virtualenv Has TOCTOU Vulnerabilities in Directory Creation
10 Sept 2026Denial of service (DoS) via deformation `multipart/form-data` boundary
10 Sept 2026AnyIO process-pool workers can block indefinitely on undrained stderr
18 Sept 2026python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
10 Sept 2026AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
10 Sept 2026aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
10 Sept 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
10 Sept 2026AIOHTTP's unicode processing of header values could cause parsing discrepancies
10 Sept 2026AIOHTTP vulnerable to denial of service through large payloads
10 Sept 2026python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
10 Sept 2026AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
10 Sept 2026pytest has vulnerable tmpdir handling
10 Sept 2026PyJWT accepts unknown `crit` header extensions
10 Sept 2026Vulnerable OpenSSL included in cryptography wheels
10 Sept 2026Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
10 Sept 2026protobuf affected by a JSON recursion depth bypass
10 Sept 2026AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
18 Sept 2026Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
10 Sept 2026Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
10 Sept 2026urllib3: HTTPS proxy TLS configuration may be ignored or overridden
30 Sept 2026protobuf-python has a potential Denial of Service issue
10 Sept 2026PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
30 Sept 2026virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
01 Oct 2026AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
10 Sept 2026AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
10 Sept 2026PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
10 Sept 2026Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
10 Sept 2026virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
01 Oct 2026Requests vulnerable to .netrc credentials leak via malicious URLs
10 Sept 2026PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
30 Sept 2026PyJWT: PyJWKClient follows redirects when fetching JWKS
30 Sept 2026Requests `Session` object does not verify requests after making first request with verify=False
10 Sept 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): Datastore — exact AI dependency evidence dossier, data state 01 Oct 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-9852/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.