github.com/OpenHands/OpenHands
Submitted 7/22/2026, 9:03:07 PM · Status: failed
Risk grade
·
Findings
0
4 critical141 high357 medium27 low0 info0 on CISA KEV0ATT&CK
Showing 529 of 529 findings
Findings
- Malware in openhands-frontendgrype
- Manage secretsViewing secrets at the cluster-scope is akin to cluster-admin in most clusters as there are typically at least one service accounts (their token stored in a secret) bound to cluster-admin directly or a role/clusterrole that gives similar permissions.trivykind/manifests/nginx.yaml:155
- Manage webhookconfigurationsWebhooks can silently intercept or actively mutate/block resources as they are being created or updated. This includes secrets and pod specs.trivykind/manifests/nginx.yaml:237
- RUN using 'sudo'Avoid using 'RUN' with 'sudo' commands, as it can lead to unpredictable behavior.trivycontainers/app/Dockerfile:69
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Axios Node HTTP adapter can use an inherited proxy after interceptor config cloninggrype
- dd-trace-py: Improper parsing of W3C baggage headers may lead to DoSgrypeCVE-2026-50271EPSS 0.8%
- GitPython unsafe clone option gate bypass through joined short optionsgrype
- GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistgrype
- GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`grype
- GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLgrype
- joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)grypeCVE-2026-49852EPSS 0.2%
- joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)grypeCVE-2026-49852EPSS 0.2%
- json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoSgrype
- json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoSgrype
- MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksgrypeCVE-2026-52870EPSS 0.2%
- MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksgrypeCVE-2026-52870EPSS 0.2%
- MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalgrypeCVE-2026-52869EPSS 0.3%
- MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalgrypeCVE-2026-52869EPSS 0.3%
- MCP Python SDK: WebSocket server transport does not support Host/Origin validationgrypeCVE-2026-59950EPSS 0.1%
- MCP Python SDK: WebSocket server transport does not support Host/Origin validationgrypeCVE-2026-59950EPSS 0.1%
- Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitionsgrypeCVE-2026-59928EPSS 0.4%
- Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairsgrypeCVE-2026-59925EPSS 0.4%
- Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)grypeCVE-2026-59922EPSS 0.4%
- Mistune: Potential DoS via quadratic-time parsing in parse_link_textgrypeCVE-2026-49851EPSS 0.4%
- Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadinggrypeCVE-2026-55379EPSS 0.4%
- Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`grypeCVE-2026-55380EPSS 0.4%
- Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loadinggrypeCVE-2026-54059EPSS 0.4%
- Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of servicegrypeCVE-2026-59204EPSS 0.4%
- Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`grypeCVE-2026-54060EPSS 0.4%
- Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatchgrypeCVE-2026-59205EPSS 0.4%
- Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()grypeCVE-2026-59200EPSS 0.4%
- Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowgrypeCVE-2026-59199EPSS 0.4%
- Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`grypeCVE-2026-59197EPSS 0.4%
- Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)grypeCVE-2026-54058EPSS 0.4%
- pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of servicegrypeCVE-2026-59885EPSS 0.3%
- pyasn1: Uncontrolled resource consumption when converting decoded REAL valuesgrypeCVE-2026-59886EPSS 0.3%
- python-engineio has possible denial of service due to maximum payload size sometimes not being enforcedgrypeCVE-2026-48809
- python-engineio has unbound thread allocation that can cause denial of servicegrypeCVE-2026-48802
- python-socketio: Binary attachment accumulation can cause denial of servicegrypeCVE-2026-48804
- Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector ListsgrypeCVE-2026-49476EPSS 0.6%
- Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector ParsergrypeCVE-2026-49477EPSS 0.6%
- Vulnerable OpenSSL included in cryptography wheelsgrype
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:94
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:17
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:49
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/app/Dockerfile:54
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/app/Dockerfile:25
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:59
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:33
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:7
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivycontainers/dev/Dockerfile:65
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivyenterprise/Dockerfile:11
- Access to host portsAccording to pod security standard 'Host Ports', hostPorts should be disallowed, or at minimum restricted to a known list.trivykind/manifests/nginx.yaml:425
- Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning## Summary Axios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and request configuration is materialized as a regular object before dispatch. Recent axios releases harden merged request config by creating…trivy
- dd-trace-py: Improper parsing of W3C baggage headers may lead to DoSDatadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remo…trivyCVE-2026-50271
- Exec into PodsThe ability to exec into a container with privileged access to the host or with an attached SA with higher RBAC permissions is a common escalation path to cluster-admin.trivykind/manifests/role.yaml:9
- GitPython unsafe clone option gate bypass through joined short options`GitPython` version `3.1.50` blocks unsafe `git clone` options such as `--upload-pack`, `-u`, `--config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/…trivy
- GitPython unsafe clone option gate bypass through joined short options`GitPython` version `3.1.50` blocks unsafe `git clone` options such as `--upload-pack`, `-u`, `--config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/…trivy
- GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython (PyPI: GitPython) **Affected:** all versions carrying the 3.1.47 blocklist fix, throug…trivy
- GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython (PyPI: GitPython) **Affected:** all versions carrying the 3.1.47 blocklist fix, throug…trivy
- GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused…trivy
- GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused…trivy
- GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `…trivy
- GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `…trivy
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivycontainers/app/Dockerfile:100
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivycontainers/dev/Dockerfile:0
- joserfc is a Python library that provides an implementation of several ...joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because…trivyCVE-2026-49852
- joserfc is a Python library that provides an implementation of several ...joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because…trivyCVE-2026-49852
- json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS## Circular JSON Schema `$ref` causes unbounded CPU DoS in `json_repair` ### Summary `SchemaRepairer.resolve_schema()` in `json_repair` follows JSON Schema `$ref` pointers in an unbounded `while` loop without any cycle detection. An attacker who can supply a schema containing a…trivy
- json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS## Circular JSON Schema `$ref` causes unbounded CPU DoS in `json_repair` ### Summary `SchemaRepairer.resolve_schema()` in `json_repair` follows JSON Schema `$ref` pointers in an unbounded `while` loop without any cycle detection. An attacker who can supply a schema containing a…trivy
- Manage Kubernetes networkingThe ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.trivykind/manifests/role.yaml:9
- Manage Kubernetes networkingThe ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.trivykind/manifests/role.yaml:12
- MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identi…trivyCVE-2026-52870
- MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasksThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identi…trivyCVE-2026-52870
- MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route req…trivyCVE-2026-52869
- MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principalThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route req…trivyCVE-2026-52869
- MCP Python SDK: WebSocket server transport does not support Host/Origin validationThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-…trivyCVE-2026-59950
- MCP Python SDK: WebSocket server transport does not support Host/Origin validationThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-…trivyCVE-2026-59950
- Mistune is a Python Markdown parser with renderers and plugins. Prior ...Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matchin…trivyCVE-2026-59922
- Mistune is a Python Markdown parser with renderers and plugins. Prior ...Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matchin…trivyCVE-2026-59922
- mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitionsMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing den…trivyCVE-2026-59928
- mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitionsMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing den…trivyCVE-2026-59928
- mistune: Mistune: Denial of Service via crafted Markdown inputMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching cl…trivyCVE-2026-59925
- mistune: Mistune: Denial of Service via crafted Markdown inputMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching cl…trivyCVE-2026-59925
- Mistune: Mistune: Denial of Service via crafted Markdown inputMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repe…trivyCVE-2026-49851
- Mistune: Mistune: Denial of Service via crafted Markdown inputMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repe…trivyCVE-2026-49851
- Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply APIPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed…trivyCVE-2026-59205
- Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply APIPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed…trivyCVE-2026-59205
- Pillow: Pillow: Denial of Service via crafted JPEG2000 imagePillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient …trivyCVE-2026-59204
- Pillow: Pillow: Denial of Service via crafted JPEG2000 imagePillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient …trivyCVE-2026-59204
- Pillow: Pillow: Denial of service via crafted PDF streamPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus…trivyCVE-2026-59200
- Pillow: Pillow: Denial of service via crafted PDF streamPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus…trivyCVE-2026-59200
- Pillow: Pillow: Denial of Service via out-of-bounds write in image processingPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v…trivyCVE-2026-59199
- Pillow: Pillow: Denial of Service via out-of-bounds write in image processingPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v…trivyCVE-2026-59199
- Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA imagePillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t…trivyCVE-2026-54058
- Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA imagePillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t…trivyCVE-2026-54058
- Pillow: Pillow: Native heap out-of-bounds writePillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali…trivyCVE-2026-59197
- Pillow: Pillow: Native heap out-of-bounds writePillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali…trivyCVE-2026-59197
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivykind/manifests/nginx.yaml:391
- pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL valuespyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent,…trivyCVE-2026-59886
- pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL valuespyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent,…trivyCVE-2026-59886
- pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIERpyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per …trivyCVE-2026-59885
- pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIERpyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per …trivyCVE-2026-59885
- python-engineio has possible denial of service due to maximum payload size sometimes not being enforced### Impact There are two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio …trivyCVE-2026-48809
- python-engineio has possible denial of service due to maximum payload size sometimes not being enforced### Impact There are two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio …trivyCVE-2026-48809
- python-engineio has unbound thread allocation that can cause denial of service### Impact An attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. Note: this issue primarily aff…trivyCVE-2026-48802
- python-engineio has unbound thread allocation that can cause denial of service### Impact An attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. Note: this issue primarily aff…trivyCVE-2026-48802
- python-pillow: Pillow: Denial of Service via crafted BDF font filePillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented de…trivyCVE-2026-55379
- python-pillow: Pillow: Denial of Service via crafted BDF font filePillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented de…trivyCVE-2026-55379
- python-pillow: Pillow: Denial of Service via crafted GD 2.x image filePillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap alloca…trivyCVE-2026-55380
- python-pillow: Pillow: Denial of Service via crafted GD 2.x image filePillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap alloca…trivyCVE-2026-55380
- python-pillow: Pillow: Denial of Service via crafted PCF font dataPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause exce…trivyCVE-2026-54059
- python-pillow: Pillow: Denial of Service via crafted PCF font dataPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause exce…trivyCVE-2026-54059
- python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font filesPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during …trivyCVE-2026-54060
- python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font filesPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during …trivyCVE-2026-54060
- python-socketio: Binary attachment accumulation can cause denial of service### Impact The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit se…trivyCVE-2026-48804
- python-socketio: Binary attachment accumulation can cause denial of service### Impact The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit se…trivyCVE-2026-48804
- python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…trivyCVE-2026-49476
- python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…trivyCVE-2026-49476
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivykind/manifests/deployment.yaml:17
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivykind/manifests/nginx.yaml:425
- soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringsSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…trivyCVE-2026-49477
- soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringsSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…trivyCVE-2026-49477
- Vulnerable OpenSSL included in cryptography wheelspyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20…trivy
- Vulnerable OpenSSL included in cryptography wheelspyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20…trivy
This report is public.