← Scan another repo

github.com/OpenHands/OpenHands

@ 96f902a9ac14

Submitted 7/22/2026, 9:03:07 PM · Status: failed

Risk grade
·
Findings
0
4 critical141 high357 medium27 low0 info0 on CISA KEV0ATT&CK
Showing 529 of 529 findings

Findings

  • Malware in openhands-frontend
    grype
  • Manage secrets
    Viewing secrets at the cluster-scope is akin to cluster-admin in most clusters as there are typically at least one service accounts (their token stored in a secret) bound to cluster-admin directly or a role/clusterrole that gives similar permissions.
    trivykind/manifests/nginx.yaml:155
  • Manage webhookconfigurations
    Webhooks can silently intercept or actively mutate/block resources as they are being created or updated. This includes secrets and pod specs.
    trivykind/manifests/nginx.yaml:237
  • RUN using 'sudo'
    Avoid using 'RUN' with 'sudo' commands, as it can lead to unpredictable behavior.
    trivycontainers/app/Dockerfile:69
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
    grype
  • dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
    grypeCVE-2026-50271EPSS 0.8%
  • GitPython unsafe clone option gate bypass through joined short options
    grype
  • GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    grype
  • GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
    grype
  • GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
    grype
  • joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
    grypeCVE-2026-49852EPSS 0.2%
  • joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
    grypeCVE-2026-49852EPSS 0.2%
  • json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
    grype
  • json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
    grype
  • MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
    grypeCVE-2026-52870EPSS 0.2%
  • MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
    grypeCVE-2026-52870EPSS 0.2%
  • MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
    grypeCVE-2026-52869EPSS 0.3%
  • MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
    grypeCVE-2026-52869EPSS 0.3%
  • MCP Python SDK: WebSocket server transport does not support Host/Origin validation
    grypeCVE-2026-59950EPSS 0.1%
  • MCP Python SDK: WebSocket server transport does not support Host/Origin validation
    grypeCVE-2026-59950EPSS 0.1%
  • Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
    grypeCVE-2026-59928EPSS 0.4%
  • Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
    grypeCVE-2026-59925EPSS 0.4%
  • Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
    grypeCVE-2026-59922EPSS 0.4%
  • Mistune: Potential DoS via quadratic-time parsing in parse_link_text
    grypeCVE-2026-49851EPSS 0.4%
  • Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
    grypeCVE-2026-55379EPSS 0.4%
  • Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
    grypeCVE-2026-55380EPSS 0.4%
  • Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
    grypeCVE-2026-54059EPSS 0.4%
  • Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
    grypeCVE-2026-59204EPSS 0.4%
  • Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
    grypeCVE-2026-54060EPSS 0.4%
  • Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
    grypeCVE-2026-59205EPSS 0.4%
  • Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
    grypeCVE-2026-59200EPSS 0.4%
  • Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
    grypeCVE-2026-59199EPSS 0.4%
  • Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
    grypeCVE-2026-59197EPSS 0.4%
  • Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
    grypeCVE-2026-54058EPSS 0.4%
  • pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
    grypeCVE-2026-59885EPSS 0.3%
  • pyasn1: Uncontrolled resource consumption when converting decoded REAL values
    grypeCVE-2026-59886EPSS 0.3%
  • python-engineio has possible denial of service due to maximum payload size sometimes not being enforced
    grypeCVE-2026-48809
  • python-engineio has unbound thread allocation that can cause denial of service
    grypeCVE-2026-48802
  • python-socketio: Binary attachment accumulation can cause denial of service
    grypeCVE-2026-48804
  • Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
    grypeCVE-2026-49476EPSS 0.6%
  • Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
    grypeCVE-2026-49477EPSS 0.6%
  • Vulnerable OpenSSL included in cryptography wheels
    grype
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:94
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:17
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:49
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/app/Dockerfile:54
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/app/Dockerfile:25
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:59
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:33
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:7
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivycontainers/dev/Dockerfile:65
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivyenterprise/Dockerfile:11
  • Access to host ports
    According to pod security standard 'Host Ports', hostPorts should be disallowed, or at minimum restricted to a known list.
    trivykind/manifests/nginx.yaml:425
  • Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
    ## Summary Axios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and request configuration is materialized as a regular object before dispatch. Recent axios releases harden merged request config by creating…
    trivy
  • dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
    Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remo…
    trivyCVE-2026-50271
  • Exec into Pods
    The ability to exec into a container with privileged access to the host or with an attached SA with higher RBAC permissions is a common escalation path to cluster-admin.
    trivykind/manifests/role.yaml:9
  • GitPython unsafe clone option gate bypass through joined short options
    `GitPython` version `3.1.50` blocks unsafe `git clone` options such as `--upload-pack`, `-u`, `--config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/…
    trivy
  • GitPython unsafe clone option gate bypass through joined short options
    `GitPython` version `3.1.50` blocks unsafe `git clone` options such as `--upload-pack`, `-u`, `--config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/…
    trivy
  • GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    ## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython (PyPI: GitPython) **Affected:** all versions carrying the 3.1.47 blocklist fix, throug…
    trivy
  • GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    ## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython (PyPI: GitPython) **Affected:** all versions carrying the 3.1.47 blocklist fix, throug…
    trivy
  • GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
    ## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused…
    trivy
  • GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
    ## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused…
    trivy
  • GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
    ### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `…
    trivy
  • GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
    ### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `…
    trivy
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivycontainers/app/Dockerfile:100
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivycontainers/dev/Dockerfile:0
  • joserfc is a Python library that provides an implementation of several ...
    joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because…
    trivyCVE-2026-49852
  • joserfc is a Python library that provides an implementation of several ...
    joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because…
    trivyCVE-2026-49852
  • json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
    ## Circular JSON Schema `$ref` causes unbounded CPU DoS in `json_repair` ### Summary `SchemaRepairer.resolve_schema()` in `json_repair` follows JSON Schema `$ref` pointers in an unbounded `while` loop without any cycle detection. An attacker who can supply a schema containing a…
    trivy
  • json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
    ## Circular JSON Schema `$ref` causes unbounded CPU DoS in `json_repair` ### Summary `SchemaRepairer.resolve_schema()` in `json_repair` follows JSON Schema `$ref` pointers in an unbounded `while` loop without any cycle detection. An attacker who can supply a schema containing a…
    trivy
  • Manage Kubernetes networking
    The ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.
    trivykind/manifests/role.yaml:9
  • Manage Kubernetes networking
    The ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.
    trivykind/manifests/role.yaml:12
  • MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identi…
    trivyCVE-2026-52870
  • MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identi…
    trivyCVE-2026-52870
  • MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route req…
    trivyCVE-2026-52869
  • MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route req…
    trivyCVE-2026-52869
  • MCP Python SDK: WebSocket server transport does not support Host/Origin validation
    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-…
    trivyCVE-2026-59950
  • MCP Python SDK: WebSocket server transport does not support Host/Origin validation
    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-…
    trivyCVE-2026-59950
  • Mistune is a Python Markdown parser with renderers and plugins. Prior ...
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matchin…
    trivyCVE-2026-59922
  • Mistune is a Python Markdown parser with renderers and plugins. Prior ...
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matchin…
    trivyCVE-2026-59922
  • mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing den…
    trivyCVE-2026-59928
  • mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing den…
    trivyCVE-2026-59928
  • mistune: Mistune: Denial of Service via crafted Markdown input
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching cl…
    trivyCVE-2026-59925
  • mistune: Mistune: Denial of Service via crafted Markdown input
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching cl…
    trivyCVE-2026-59925
  • Mistune: Mistune: Denial of Service via crafted Markdown input
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repe…
    trivyCVE-2026-49851
  • Mistune: Mistune: Denial of Service via crafted Markdown input
    Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repe…
    trivyCVE-2026-49851
  • Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed…
    trivyCVE-2026-59205
  • Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed…
    trivyCVE-2026-59205
  • Pillow: Pillow: Denial of Service via crafted JPEG2000 image
    Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient …
    trivyCVE-2026-59204
  • Pillow: Pillow: Denial of Service via crafted JPEG2000 image
    Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient …
    trivyCVE-2026-59204
  • Pillow: Pillow: Denial of service via crafted PDF stream
    Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus…
    trivyCVE-2026-59200
  • Pillow: Pillow: Denial of service via crafted PDF stream
    Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus…
    trivyCVE-2026-59200
  • Pillow: Pillow: Denial of Service via out-of-bounds write in image processing
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v…
    trivyCVE-2026-59199
  • Pillow: Pillow: Denial of Service via out-of-bounds write in image processing
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v…
    trivyCVE-2026-59199
  • Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image
    Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t…
    trivyCVE-2026-54058
  • Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image
    Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t…
    trivyCVE-2026-54058
  • Pillow: Pillow: Native heap out-of-bounds write
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali…
    trivyCVE-2026-59197
  • Pillow: Pillow: Native heap out-of-bounds write
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali…
    trivyCVE-2026-59197
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivykind/manifests/nginx.yaml:391
  • pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent,…
    trivyCVE-2026-59886
  • pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent,…
    trivyCVE-2026-59886
  • pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per …
    trivyCVE-2026-59885
  • pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per …
    trivyCVE-2026-59885
  • python-engineio has possible denial of service due to maximum payload size sometimes not being enforced
    ### Impact There are two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio …
    trivyCVE-2026-48809
  • python-engineio has possible denial of service due to maximum payload size sometimes not being enforced
    ### Impact There are two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio …
    trivyCVE-2026-48809
  • python-engineio has unbound thread allocation that can cause denial of service
    ### Impact An attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. Note: this issue primarily aff…
    trivyCVE-2026-48802
  • python-engineio has unbound thread allocation that can cause denial of service
    ### Impact An attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. Note: this issue primarily aff…
    trivyCVE-2026-48802
  • python-pillow: Pillow: Denial of Service via crafted BDF font file
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented de…
    trivyCVE-2026-55379
  • python-pillow: Pillow: Denial of Service via crafted BDF font file
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented de…
    trivyCVE-2026-55379
  • python-pillow: Pillow: Denial of Service via crafted GD 2.x image file
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap alloca…
    trivyCVE-2026-55380
  • python-pillow: Pillow: Denial of Service via crafted GD 2.x image file
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap alloca…
    trivyCVE-2026-55380
  • python-pillow: Pillow: Denial of Service via crafted PCF font data
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause exce…
    trivyCVE-2026-54059
  • python-pillow: Pillow: Denial of Service via crafted PCF font data
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause exce…
    trivyCVE-2026-54059
  • python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during …
    trivyCVE-2026-54060
  • python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during …
    trivyCVE-2026-54060
  • python-socketio: Binary attachment accumulation can cause denial of service
    ### Impact The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit se…
    trivyCVE-2026-48804
  • python-socketio: Binary attachment accumulation can cause denial of service
    ### Impact The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit se…
    trivyCVE-2026-48804
  • python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…
    trivyCVE-2026-49476
  • python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…
    trivyCVE-2026-49476
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivykind/manifests/deployment.yaml:17
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivykind/manifests/nginx.yaml:425
  • soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…
    trivyCVE-2026-49477
  • soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…
    trivyCVE-2026-49477
  • Vulnerable OpenSSL included in cryptography wheels
    pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20…
    trivy
  • Vulnerable OpenSSL included in cryptography wheels
    pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20…
    trivy

This report is public.