github.com/astral-sh/uv
Submitted 8/4/2026, 10:25:55 AM · Status: ok
Risk grade
F
100 / 100
Findings
2354
1 critical30 high166 medium8 low2149 info0 on CISA KEV0ATT&CK
Showing 2,354 of 2,354 findings
Findings
- h11 accepts some malformed Chunked-Encoding bodiesgrypeCVE-2025-43859EPSS 0.6%
- Detected github-fine-grained-pat: Found a GitHub Fine-Grained Personal Access Token, risking unauthorized repository access and code manipulationFound a GitHub Fine-Grained Personal Access Token, risking unauthorized repository access and code manipulation.gitleaks
- cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT CurvesgrypeCVE-2026-26007EPSS 0.3%
- Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)grypeCVE-2026-21441EPSS 2.7%
- Dulwich has an arbitrary file write via NTFS-hostile tree entries on WindowsgrypeCVE-2026-42305EPSS 0.6%
- GitPython unsafe clone option gate bypass through joined short optionsgrype
- GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)grype
- GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistgrype
- GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`grype
- GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLgrype
- GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)grype
- GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)grype
- GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksgrype
- GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executiongrype
- MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught errorgrype
- MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught errorgrype
- PDM wheel installation leads to Path Traversal via overridden write_to_fsgrypeCVE-2026-47764
- PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI ParsinggrypeCVE-2026-47781
- Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File WritegrypeCVE-2026-34591EPSS 0.5%
- setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File WritegrypeCVE-2025-47273EPSS 1.5%
- Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector ListsgrypeCVE-2026-49476EPSS 0.4%
- Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector ParsergrypeCVE-2026-49477EPSS 0.4%
- urllib3 allows an unbounded number of links in the decompression chaingrypeCVE-2025-66418EPSS 0.7%
- urllib3 streaming API improperly handles highly compressed datagrypeCVE-2025-66471EPSS 0.7%
- urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsgrypeCVE-2026-44431EPSS 0.3%
- virtualenv allows command injection through activation scripts for a virtual environmentgrypeCVE-2024-53899EPSS 1.6%
- Vulnerable OpenSSL included in cryptography wheelsgrype
- Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpackgrypeCVE-2026-24049EPSS 0.3%
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivyDockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivycrates/uv-trampoline/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivycrates/uv-dev/builder.dockerfile:0
This report is public.