uba-ki-lab/density-mapsThis dossier retains 66 exact component occurrences from 1 published evidence files at one immutable repository commit.
Published dependency evidence does not prove deployment, productive use, procurement or runtime reachability.
project ID + commit SHA + exact evidence pathEvery file remains tied to the observed commit. A parse error stays visible and never becomes a zero.
sha256:a3585500d962f78bc6cb14fec81c1117e03be3b4ca8961149d10c8a44c3682edpypi:torch2.10.023 OSV records returnedpypi:aiohttp3.13.333 OSV records returnedpypi:pillow12.1.120 OSV records returnedpypi:jinja23.1.64 OSV records returnedpypi:setuptools82.0.13 OSV records returnedpypi:filelock3.25.22 OSV records returnedpypi:idna3.111 OSV record returnedpypi:lightning2.6.11 OSV record returnedpypi:pygments2.19.21 OSV record returnedpypi:pytest9.0.21 OSV record returnedpypi:tqdm4.67.31 OSV record returnedpypi:aiohappyeyeballs2.6.1pypi:aiosignal1.4.0pypi:albucore0.0.24pypi:albumentations2.0.8pypi:annotated-types0.7.0pypi:attrs25.4.0pypi:colorama0.4.6pypi:coverage7.13.4pypi:cuda-bindings12.9.4pypi:cuda-pathfinder1.4.2pypi:frozenlist1.8.0pypi:fsspec2026.2.0pypi:iniconfig2.3.0pypi:lightning-utilities0.15.3pypi:markupsafe3.0.3pypi:mpmath1.3.0pypi:multidict6.7.1pypi:networkx3.6.1pypi:numpy2.4.3pypi:nvidia-cublas-cu1212.8.4.1pypi:nvidia-cuda-cupti-cu1212.8.90pypi:nvidia-cuda-nvrtc-cu1212.8.93pypi:nvidia-cuda-runtime-cu1212.8.90pypi:nvidia-cudnn-cu129.10.2.21pypi:nvidia-cufft-cu1211.3.3.83pypi:nvidia-cufile-cu121.13.1.3pypi:nvidia-curand-cu1210.3.9.90pypi:nvidia-cusolver-cu1211.7.3.90pypi:nvidia-cusparse-cu1212.5.8.93pypi:nvidia-cusparselt-cu120.7.1pypi:nvidia-nccl-cu122.27.5pypi:nvidia-nvjitlink-cu1212.8.93pypi:nvidia-nvshmem-cu123.4.5pypi:nvidia-nvtx-cu1212.8.90pypi:opencv-python-headless4.13.0.92pypi:packaging26.0pypi:pluggy1.6.0pypi:propcache0.4.1pypi:pydantic2.12.5pypi:pydantic-core2.41.5pypi:pytest-cov7.0.0pypi:pytorch-lightning2.6.1pypi:pyyaml6.0.3pypi:ruff0.15.6pypi:scipy1.17.1pypi:simsimd6.5.16pypi:stringzilla4.6.0pypi:sympy1.14.0pypi:torchmetrics1.9.0pypi:torchvision0.25.0pypi:triton3.6.0pypi:ty0.0.23pypi:typing-extensions4.15.0pypi:typing-inspection0.4.2pypi:yarl1.23.0aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
13 Jul 2026AIOHTTP has CRLF injection through multipart part content type header construction
13 Jul 2026PyTorch susceptible to local Denial of Service
10 Jun 2026AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
13 Jul 2026Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22 Jul 2026aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
13 Jul 2026aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
27 Jun 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22 Jul 2026Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
13 Jul 2026PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
07 Aug 2026AIOHTTP vulnerable to brute-force leak of internal static file path components
07 Jul 2026setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
11 May 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
22 Jul 2026Pillow has a heap buffer overflow with nested list coordinates
13 Jul 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
23 Jul 2026AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
16 Jul 2026aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
13 Jul 2026Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
08 Jul 2026AIOHTTP's unicode processing of header values could cause parsing discrepancies
07 Jul 2026AIOHTTP vulnerable to denial of service through large payloads
07 Jul 2026AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
07 Jul 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
22 Jul 2026pytest has vulnerable tmpdir handling
07 Jul 2026PyTorch Improper Resource Shutdown or Release vulnerability
07 Aug 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
22 Jul 2026AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
07 Jul 2026AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
13 Jul 2026Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
22 Jul 2026aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
13 Jul 2026AIOHTTP accepts duplicate Host headers
13 Jul 2026PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
09 Jun 2026Pillow affected by out-of-bounds write when loading PSD images
13 Jul 2026Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
07 Jul 2026AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
04 Aug 2026setuptools vulnerable to Command Injection via package URL
07 Jul 2026PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
10 Jun 2026AIOHTTP Vulnerable to Cookie Parser Warning Storm
07 Jul 2026Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
23 Jul 2026aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
13 Jul 2026tqdm CLI arguments injection attack
07 Jul 2026AIOHTTP vulnerable to DoS through chunked messages
07 Jul 2026Jinja has a sandbox breakout through malicious filenames
07 Jul 2026setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
23 Jul 2026Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
07 Jul 2026AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
13 Jul 2026AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
13 Jul 2026aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
13 Jul 2026AIOHTTP is Vulnerable to Deserialization of Untrusted Data
13 Jul 2026The collector reads bounded lockfiles, SBOMs and exact double-equals pins at one immutable commit. Version ranges are never resolved by assumption.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): density-maps — exact AI dependency evidence dossier, data state 12 Aug 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/repository/opencode-9998/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.