← Scan another repo

github.com/astral-sh/uv

@ a1d623902b0d

Submitted 8/4/2026, 10:25:55 AM · Status: ok

Risk grade
F
100 / 100
Findings
2354
1 critical30 high166 medium8 low2149 info0 on CISA KEV0ATT&CK
Showing 2,354 of 2,354 findings

Findings

  • h11 accepts some malformed Chunked-Encoding bodies
    grypeCVE-2025-43859EPSS 0.6%
  • Detected github-fine-grained-pat: Found a GitHub Fine-Grained Personal Access Token, risking unauthorized repository access and code manipulation
    Found a GitHub Fine-Grained Personal Access Token, risking unauthorized repository access and code manipulation.
    gitleaks
  • cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
    grypeCVE-2026-26007EPSS 0.3%
  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    grypeCVE-2026-21441EPSS 2.7%
  • Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
    grypeCVE-2026-42305EPSS 0.6%
  • GitPython unsafe clone option gate bypass through joined short options
    grype
  • GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
    grype
  • GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    grype
  • GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
    grype
  • GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
    grype
  • GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
    grype
  • GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
    grype
  • GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
    grype
  • GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
    grype
  • MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
    grype
  • MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
    grype
  • PDM wheel installation leads to Path Traversal via overridden write_to_fs
    grypeCVE-2026-47764
  • PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
    grypeCVE-2026-47781
  • Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
    grypeCVE-2026-34591EPSS 0.5%
  • setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
    grypeCVE-2025-47273EPSS 1.5%
  • Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
    grypeCVE-2026-49476EPSS 0.4%
  • Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
    grypeCVE-2026-49477EPSS 0.4%
  • urllib3 allows an unbounded number of links in the decompression chain
    grypeCVE-2025-66418EPSS 0.7%
  • urllib3 streaming API improperly handles highly compressed data
    grypeCVE-2025-66471EPSS 0.7%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • virtualenv allows command injection through activation scripts for a virtual environment
    grypeCVE-2024-53899EPSS 1.6%
  • Vulnerable OpenSSL included in cryptography wheels
    grype
  • Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
    grypeCVE-2026-24049EPSS 0.3%
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivycrates/uv-trampoline/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivycrates/uv-dev/builder.dockerfile:0

This report is public.