← Scan another repo

github.com/PaddlePaddle/PaddleOCR

@ 2661c7c0ef5c

Submitted 8/4/2026, 10:25:55 AM · Status: ok

Risk grade
F
100 / 100
Findings
450
3 critical53 high300 medium41 low53 info0 on CISA KEV0ATT&CK
Showing 450 of 450 findings

Findings

  • Arbitrary code execution in protobufjs
    grypeCVE-2026-41242EPSS 0.8%
  • OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG imag
    OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
    grypeCVE-2025-53644EPSS 0.4%
  • protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
    protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 an…
    trivyCVE-2026-41242
  • FITS GZIP decompression bomb in Pillow
    grypeCVE-2026-40192EPSS 0.7%
  • js-yaml: YAML merge-key chains can force quadratic CPU consumption
    grypeCVE-2026-59869EPSS 0.4%
  • LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
    grypeCVE-2026-34070EPSS 1.2%
  • LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
    grypeCVE-2026-44843EPSS 0.4%
  • LangSmith SDK TracingMiddleware: Arbitrary server-side file read
    grype
  • LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
    grypeCVE-2026-45134EPSS 0.2%
  • Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
    grypeCVE-2026-55379EPSS 0.4%
  • Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
    grypeCVE-2026-55380EPSS 0.4%
  • Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
    grypeCVE-2026-54059EPSS 0.4%
  • Pillow affected by out-of-bounds write when loading PSD images
    grypeCVE-2026-25990EPSS 0.4%
  • Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
    grypeCVE-2026-42311EPSS 0.1%
  • Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
    grypeCVE-2026-59204EPSS 0.4%
  • Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
    grypeCVE-2026-54060EPSS 0.4%
  • Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
    grypeCVE-2026-59205EPSS 0.4%
  • Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
    grypeCVE-2026-59200EPSS 0.4%
  • Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
    grypeCVE-2026-59199EPSS 0.4%
  • Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
    grypeCVE-2026-59197EPSS 0.4%
  • Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
    grypeCVE-2026-54058EPSS 0.4%
  • protobuf.js: Code generation gadget after prototype pollution
    grypeCVE-2026-44291EPSS 0.5%
  • protobuf.js: Code injection through bytes field defaults in generated toObject code
    grypeCVE-2026-44293EPSS 0.4%
  • protobuf.js: Denial of service through unbounded protobuf recursion
    grypeCVE-2026-44289EPSS 0.6%
  • protobuf.js: Process-wide denial of service through unsafe option paths
    grypeCVE-2026-44290EPSS 0.4%
  • protobufjs: Denial of service through unbounded Any expansion during JSON conversion
    grypeCVE-2026-48712EPSS 0.5%
  • Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
    grypeCVE-2026-54283EPSS 0.4%
  • Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
    grypeCVE-2026-48818EPSS 0.4%
  • UltraJSON has a Memory Leak in ujson.dump() on Write Failure
    grypeCVE-2026-44660EPSS 0.4%
  • UltraJSON has a Memory Leak parsing large integers allows DoS
    grypeCVE-2026-32874EPSS 0.5%
  • UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
    grypeCVE-2026-32875EPSS 0.5%
  • urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
    grypeCVE-2026-44432EPSS 0.7%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
    grype
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgreptest_tipc/supplementary/utils.py:135
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgreptest_tipc/supplementary/load_cifar.py:9
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppstructure/table/table_master_match.py:96
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppstructure/table/table_master_match.py:90
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppstructure/table/eval_table.py:56
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppocr/utils/save_load.py:158
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppocr/utils/save_load.py:89
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppocr/losses/text_focus_loss.py:32
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepppocr/losses/center_loss.py:46
  • subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list an
    subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list and shell=False. (First-party socbox; Apache-2.0.)
    semgreptest_tipc/compare_results.py:26
  • subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list an
    subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list and shell=False. (First-party socbox; Apache-2.0.)
    semgrepppocr/postprocess/pse_postprocess/pse/__init__.py:23
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivydeploy/paddleocr_vl_docker/accelerators/huawei-npu/vlm.Dockerfile:11
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydeploy/paddleocr_vl_docker/hps/gateway.Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydeploy/paddleocr_vl_docker/hps/pipeline.Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydeploy/docker/hubserving/gpu/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydeploy/docker/hubserving/cpu/Dockerfile:0
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents
    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…
    trivyCVE-2026-59869
  • protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors
    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a no…
    trivyCVE-2026-44293
  • protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution
    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted,…
    trivyCVE-2026-44291
  • protobufjs: protobufjs: Denial of Service via crafted schema
    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause optio…
    trivyCVE-2026-44290
  • protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding
    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields.…
    trivyCVE-2026-44289
  • protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload
    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protob…
    trivyCVE-2026-48712

This report is public.