github.com/datawhalechina/happy-llm
Submitted 8/4/2026, 10:28:02 AM · Status: ok
Risk grade
F
100 / 100
Findings
569
4 critical131 high408 medium22 low4 info0 on CISA KEV0ATT&CK
Showing 569 of 569 findings
Findings
- NLTK has a Zip Slip VulnerabilitygrypeCVE-2025-14009EPSS 0.8%
- PyTorch: `torch.load` with `weights_only=True` leads to remote code executiongrypeCVE-2025-32434EPSS 1.9%
- nltk: Zip Slip Vulnerability in nltk Leading to Code ExecutionA critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip pack…trivyCVE-2025-14009
- PyTorch is a Python package that provides tensor computation with stro ...PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.…trivyCVE-2025-32434
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Apache Arrow: Potential use-after-free when reading IPC file with pre-bufferinggrypeCVE-2026-25087EPSS 0.8%
- Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)grypeCVE-2026-21441EPSS 2.7%
- Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)grypeCVE-2026-21441EPSS 2.7%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11394EPSS 2.4%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11393EPSS 2.9%
- Deserialization of Untrusted Data in Hugging Face TransformersgrypeCVE-2024-11392EPSS 7.1%
- FITS GZIP decompression bomb in PillowgrypeCVE-2026-40192EPSS 0.7%
- GitPython has Command Injection via Git options bypassgrypeCVE-2026-42215EPSS 0.8%
- GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repositorygrypeCVE-2026-44243EPSS 0.4%
- GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)grype
- GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistgrype
- GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`grype
- GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLgrype
- GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)grype
- GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)grype
- GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksgrype
- GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPathgrype
- GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathgrypeCVE-2026-44244EPSS 0.2%
- GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executiongrype
- GitPython: Unsafe option check validates multi_options before shlex.split transformationgrypeCVE-2026-42284EPSS 0.6%
- HuggingFace transformers vulnerable to remote code executiongrypeCVE-2026-4372EPSS 0.5%
- HuggingFace transformers vulnerable to remote code executiongrypeCVE-2026-4372EPSS 0.5%
- huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathgrypeCVE-2026-5241EPSS 0.5%
- huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathgrypeCVE-2026-5241EPSS 0.5%
- Incorrect handling of invalid surrogate pair charactersgrypeCVE-2022-31116EPSS 2.3%
- Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadgrypeCVE-2026-54293EPSS 0.6%
- NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File OverwritegrypeCVE-2026-33236EPSS 0.6%
- NLTK has a Path Traversal issuegrypeCVE-2026-0847EPSS 0.9%
- NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()grypeCVE-2026-0846EPSS 0.4%
- ntlk unsafe deserialization vulnerabilitygrypeCVE-2024-39705EPSS 1.4%
- Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadinggrypeCVE-2026-55379EPSS 0.4%
- Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`grypeCVE-2026-55380EPSS 0.4%
- Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loadinggrypeCVE-2026-54059EPSS 0.4%
- Pillow affected by out-of-bounds write when loading PSD imagesgrypeCVE-2026-25990EPSS 0.4%
- Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)grypeCVE-2026-42311EPSS 0.1%
- Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of servicegrypeCVE-2026-59204EPSS 0.4%
- Pillow vulnerability can cause write buffer overflow on BCn encodinggrypeCVE-2025-48379EPSS 0.3%
- Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`grypeCVE-2026-54060EPSS 0.4%
- Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatchgrypeCVE-2026-59205EPSS 0.4%
- Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()grypeCVE-2026-59200EPSS 0.4%
- Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowgrypeCVE-2026-59199EPSS 0.4%
- Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`grypeCVE-2026-59197EPSS 0.4%
- Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)grypeCVE-2026-54058EPSS 0.4%
- protobuf affected by a JSON recursion depth bypassgrypeCVE-2026-0994EPSS 0.7%
- Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector ListsgrypeCVE-2026-49476EPSS 0.4%
- Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector ParsergrypeCVE-2026-49477EPSS 0.4%
- tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)grypeCVE-2026-49855EPSS 0.6%
- Tornado has cookie attribute injection via .RequestHandler.set_cookiegrypeCVE-2026-35536EPSS 0.2%
- Tornado is vulnerable to DoS due to too many multipart partsgrypeCVE-2026-31958EPSS 0.4%
- Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientgrypeCVE-2026-49853EPSS 0.4%
- Tornado: Quadratic DoS via Crafted Multipart ParametersgrypeCVE-2025-67726EPSS 0.5%
- Tornado: Quadratic DoS via Repeated Header CoalescinggrypeCVE-2025-67725EPSS 0.5%
- UltraJSON has a Memory Leak in ujson.dump() on Write FailuregrypeCVE-2026-44660EPSS 0.4%
- UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loopgrypeCVE-2026-32875EPSS 0.5%
- Unauthenticated remote shutdown in nltk.app.wordnet_appgrypeCVE-2026-33231EPSS 0.9%
- urllib3 allows an unbounded number of links in the decompression chaingrypeCVE-2025-66418EPSS 0.7%
- urllib3 allows an unbounded number of links in the decompression chaingrypeCVE-2025-66418EPSS 0.7%
- urllib3 streaming API improperly handles highly compressed datagrypeCVE-2025-66471EPSS 0.7%
- urllib3 streaming API improperly handles highly compressed datagrypeCVE-2025-66471EPSS 0.7%
- urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsgrypeCVE-2026-44431EPSS 0.3%
- urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsgrypeCVE-2026-44431EPSS 0.3%
- Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpackgrypeCVE-2026-24049EPSS 0.3%
- apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC filesUse After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as B…trivyCVE-2026-25087
- GitPython is a python library used to interact with Git repositories. ...GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines …trivyCVE-2026-44244
- GitPython is a python library used to interact with Git repositories. ...GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (st…trivyCVE-2026-42284
- GitPython is a python library used to interact with Git repositories. ...GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass tha…trivyCVE-2026-42215
- GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)## Summary `Diffable.diff()` forwards `**kwargs` straight into `diff`/`diff_tree` with **no** `check_unsafe_options` guard. `Diffable` is mixed into `Commit`, `Tree`, `IndexFile`, and `Submodule`, giving a broad surface. `git diff --output=<path>` writes real patch content to an …trivy
- GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython (PyPI: GitPython) **Affected:** all versions carrying the 3.1.47 blocklist fix, throug…trivy
- GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused…trivy
- GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `…trivy
- GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)## Summary The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `Repo.clone_from()` from running caller-supplied URLs through `os.path.expandvars()`, but it guarded only that one caller. `Remote.crea…trivy
- GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)### Summary In GitPython `<= 3.1.52`, the config writer neutralizes only CR, LF, and NUL in configuration **names**, but writes section names into the `[...]` header with no other escaping. A section/subsection name that contains `] [ "` closes the intended header and opens a se…trivy
- GitPython: GitPython: Arbitrary file write via crafted reference pathsGitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository…trivyCVE-2026-44243
- GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks## Summary GitPython's `unsafe_git_clone_options` denylist omits `--template`. `git clone --template=<dir>` copies `<dir>/hooks/` into the new repository and runs them (`post-checkout` fires during clone), so a caller who can influence clone options can achieve arbitrary command …trivy
- GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPathSummary The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to writ…trivy
- GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution## Summary GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling a…trivy
- HuggingFace transformers vulnerable to remote code executionA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…trivyCVE-2026-4372
- HuggingFace transformers vulnerable to remote code executionA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…trivyCVE-2026-4372
- NLTK through 3.8.1 allows remote code execution if untrusted packages ...NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.trivyCVE-2024-39705
- nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index filesNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processi…trivyCVE-2026-33236
- nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` functionA vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensit…trivyCVE-2026-0846
- nltk: NLTK: Arbitrary file read via path traversal vulnerabilityA vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file pa…trivyCVE-2026-0847
- nltk: NLTK: Denial of Service via unauthenticated remote shutdownNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet B…trivyCVE-2026-33231
- nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and…trivyCVE-2026-54293
- Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply APIPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed…trivyCVE-2026-59205
- Pillow: Pillow: Denial of Service via crafted JPEG2000 imagePillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient …trivyCVE-2026-59204
- Pillow: Pillow: Denial of service via crafted PDF streamPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus…trivyCVE-2026-59200
- Pillow: Pillow: Denial of Service via decompression bomb in FITS image processingPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadi…trivyCVE-2026-40192
- Pillow: Pillow: Denial of Service via out-of-bounds write in image processingPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v…trivyCVE-2026-59199
- Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA imagePillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t…trivyCVE-2026-54058
- Pillow: Pillow: Native heap out-of-bounds writePillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali…trivyCVE-2026-59197
- pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD ImagePillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.trivyCVE-2026-25990
- Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processingPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.trivyCVE-2026-42311
- python-pillow: Pillow: Denial of Service via crafted BDF font filePillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented de…trivyCVE-2026-55379
- python-pillow: Pillow: Denial of Service via crafted GD 2.x image filePillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap alloca…trivyCVE-2026-55380
- python-pillow: Pillow: Denial of Service via crafted PCF font dataPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause exce…trivyCVE-2026-54059
- python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font filesPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during …trivyCVE-2026-54060
- python-pillow: pillow: Pillow DDS Heap Buffer OverflowPillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only aff…trivyCVE-2025-48379
- python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…trivyCVE-2026-49476
- python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…trivyCVE-2026-49476
- python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…trivyCVE-2026-5241
- python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…trivyCVE-2026-5241
- python-ujson: improper decoding of escaped surrogate characters may lead to string corruption, key confusion or value overwritingUltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly.…trivyCVE-2022-31116
- python-ujson: UltraJSON: Memory leak leading to Denial of ServiceUltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each fa…trivyCVE-2026-44660
- python: protobuf: Protobuf: Denial of Service due to recursion depth bypassA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling l…trivyCVE-2026-0994
- soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringsSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…trivyCVE-2026-49477
- soupsieve: Soupsieve: Denial of Service via crafted CSS selector stringsSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…trivyCVE-2026-49477
- Tornado is a Python web framework and asynchronous networking library. ...Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTT…trivyCVE-2026-49855
- Tornado is a Python web framework and asynchronous networking library. ...Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed sc…trivyCVE-2026-49853
- tornado-python: Tornado: Denial of Service via large multipart bodiesTornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this cre…trivyCVE-2026-31958
- tornado: Tornado Quadratic DoS via Crafted Multipart ParametersTornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to parse specific HTTP header va…trivyCVE-2025-67726
- tornado: Tornado Quadratic DoS via Repeated Header CoalescingTornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using stri…trivyCVE-2025-67725
- tornado: Tornado: Cookie attribute injection due to improper handling of cookie argumentsIn Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.trivyCVE-2026-35536
- transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit t…trivyCVE-2024-11393
- transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this v…trivyCVE-2024-11392
- transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vu…trivyCVE-2024-11394
- ultrajson: UltraJSON: Denial of Service via large indent parameter in JSON serializationUltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the …trivyCVE-2026-32875
- urllib3: urllib3 Streaming API improperly handles highly compressed dataurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…trivyCVE-2025-66471
- urllib3: urllib3 Streaming API improperly handles highly compressed dataurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…trivyCVE-2025-66471
- urllib3: urllib3 Streaming API improperly handles highly compressed dataurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…trivyCVE-2025-66471
- urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…trivyCVE-2026-21441
- urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…trivyCVE-2026-21441
- urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…trivyCVE-2026-21441
- urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.trivyCVE-2026-44431
- urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.trivyCVE-2026-44431
- urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headersurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.trivyCVE-2026-44431
- urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…trivyCVE-2025-66418
- urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…trivyCVE-2025-66418
- urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…trivyCVE-2025-66418
- wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpackingwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the fil…trivyCVE-2026-24049
This report is public.