← Scan another repo

github.com/datawhalechina/happy-llm

@ f115ef3788bf

Submitted 8/4/2026, 10:28:02 AM · Status: ok

Risk grade
F
100 / 100
Findings
569
4 critical131 high408 medium22 low4 info0 on CISA KEV0ATT&CK
Showing 569 of 569 findings

Findings

  • NLTK has a Zip Slip Vulnerability
    grypeCVE-2025-14009EPSS 0.8%
  • PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
    grypeCVE-2025-32434EPSS 1.9%
  • nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip pack…
    trivyCVE-2025-14009
  • PyTorch is a Python package that provides tensor computation with stro ...
    PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.…
    trivyCVE-2025-32434
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
    grypeCVE-2026-25087EPSS 0.8%
  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    grypeCVE-2026-21441EPSS 2.7%
  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    grypeCVE-2026-21441EPSS 2.7%
  • Deserialization of Untrusted Data in Hugging Face Transformers
    grypeCVE-2024-11394EPSS 2.4%
  • Deserialization of Untrusted Data in Hugging Face Transformers
    grypeCVE-2024-11393EPSS 2.9%
  • Deserialization of Untrusted Data in Hugging Face Transformers
    grypeCVE-2024-11392EPSS 7.1%
  • FITS GZIP decompression bomb in Pillow
    grypeCVE-2026-40192EPSS 0.7%
  • GitPython has Command Injection via Git options bypass
    grypeCVE-2026-42215EPSS 0.8%
  • GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
    grypeCVE-2026-44243EPSS 0.4%
  • GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
    grype
  • GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    grype
  • GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
    grype
  • GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
    grype
  • GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
    grype
  • GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
    grype
  • GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
    grype
  • GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
    grype
  • GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
    grypeCVE-2026-44244EPSS 0.2%
  • GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
    grype
  • GitPython: Unsafe option check validates multi_options before shlex.split transformation
    grypeCVE-2026-42284EPSS 0.6%
  • HuggingFace transformers vulnerable to remote code execution
    grypeCVE-2026-4372EPSS 0.5%
  • HuggingFace transformers vulnerable to remote code execution
    grypeCVE-2026-4372EPSS 0.5%
  • huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
    grypeCVE-2026-5241EPSS 0.5%
  • huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
    grypeCVE-2026-5241EPSS 0.5%
  • Incorrect handling of invalid surrogate pair characters
    grypeCVE-2022-31116EPSS 2.3%
  • Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
    grypeCVE-2026-54293EPSS 0.6%
  • NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
    grypeCVE-2026-33236EPSS 0.6%
  • NLTK has a Path Traversal issue
    grypeCVE-2026-0847EPSS 0.9%
  • NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
    grypeCVE-2026-0846EPSS 0.4%
  • ntlk unsafe deserialization vulnerability
    grypeCVE-2024-39705EPSS 1.4%
  • Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
    grypeCVE-2026-55379EPSS 0.4%
  • Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
    grypeCVE-2026-55380EPSS 0.4%
  • Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
    grypeCVE-2026-54059EPSS 0.4%
  • Pillow affected by out-of-bounds write when loading PSD images
    grypeCVE-2026-25990EPSS 0.4%
  • Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
    grypeCVE-2026-42311EPSS 0.1%
  • Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
    grypeCVE-2026-59204EPSS 0.4%
  • Pillow vulnerability can cause write buffer overflow on BCn encoding
    grypeCVE-2025-48379EPSS 0.3%
  • Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
    grypeCVE-2026-54060EPSS 0.4%
  • Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
    grypeCVE-2026-59205EPSS 0.4%
  • Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
    grypeCVE-2026-59200EPSS 0.4%
  • Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
    grypeCVE-2026-59199EPSS 0.4%
  • Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
    grypeCVE-2026-59197EPSS 0.4%
  • Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
    grypeCVE-2026-54058EPSS 0.4%
  • protobuf affected by a JSON recursion depth bypass
    grypeCVE-2026-0994EPSS 0.7%
  • Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
    grypeCVE-2026-49476EPSS 0.4%
  • Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
    grypeCVE-2026-49477EPSS 0.4%
  • tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
    grypeCVE-2026-49855EPSS 0.6%
  • Tornado has cookie attribute injection via .RequestHandler.set_cookie
    grypeCVE-2026-35536EPSS 0.2%
  • Tornado is vulnerable to DoS due to too many multipart parts
    grypeCVE-2026-31958EPSS 0.4%
  • Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
    grypeCVE-2026-49853EPSS 0.4%
  • Tornado: Quadratic DoS via Crafted Multipart Parameters
    grypeCVE-2025-67726EPSS 0.5%
  • Tornado: Quadratic DoS via Repeated Header Coalescing
    grypeCVE-2025-67725EPSS 0.5%
  • UltraJSON has a Memory Leak in ujson.dump() on Write Failure
    grypeCVE-2026-44660EPSS 0.4%
  • UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
    grypeCVE-2026-32875EPSS 0.5%
  • Unauthenticated remote shutdown in nltk.app.wordnet_app
    grypeCVE-2026-33231EPSS 0.9%
  • urllib3 allows an unbounded number of links in the decompression chain
    grypeCVE-2025-66418EPSS 0.7%
  • urllib3 allows an unbounded number of links in the decompression chain
    grypeCVE-2025-66418EPSS 0.7%
  • urllib3 streaming API improperly handles highly compressed data
    grypeCVE-2025-66471EPSS 0.7%
  • urllib3 streaming API improperly handles highly compressed data
    grypeCVE-2025-66471EPSS 0.7%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
    grypeCVE-2026-24049EPSS 0.3%
  • apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files
    Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as B…
    trivyCVE-2026-25087
  • GitPython is a python library used to interact with Git repositories. ...
    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines …
    trivyCVE-2026-44244
  • GitPython is a python library used to interact with Git repositories. ...
    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (st…
    trivyCVE-2026-42284
  • GitPython is a python library used to interact with Git repositories. ...
    GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass tha…
    trivyCVE-2026-42215
  • GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
    ## Summary `Diffable.diff()` forwards `**kwargs` straight into `diff`/`diff_tree` with **no** `check_unsafe_options` guard. `Diffable` is mixed into `Commit`, `Tree`, `IndexFile`, and `Submodule`, giving a broad surface. `git diff --output=<path>` writes real patch content to an …
    trivy
  • GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
    ## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython (PyPI: GitPython) **Affected:** all versions carrying the 3.1.47 blocklist fix, throug…
    trivy
  • GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
    ## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused…
    trivy
  • GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
    ### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `…
    trivy
  • GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
    ## Summary The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `Repo.clone_from()` from running caller-supplied URLs through `os.path.expandvars()`, but it guarded only that one caller. `Remote.crea…
    trivy
  • GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
    ### Summary In GitPython `<= 3.1.52`, the config writer neutralizes only CR, LF, and NUL in configuration **names**, but writes section names into the `[...]` header with no other escaping. A section/subsection name that contains `] [ "` closes the intended header and opens a se…
    trivy
  • GitPython: GitPython: Arbitrary file write via crafted reference paths
    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository…
    trivyCVE-2026-44243
  • GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
    ## Summary GitPython's `unsafe_git_clone_options` denylist omits `--template`. `git clone --template=<dir>` copies `<dir>/hooks/` into the new repository and runs them (`post-checkout` fires during clone), so a caller who can influence clone options can achieve arbitrary command …
    trivy
  • GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
    Summary The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to writ…
    trivy
  • GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
    ## Summary GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling a…
    trivy
  • HuggingFace transformers vulnerable to remote code execution
    A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…
    trivyCVE-2026-4372
  • HuggingFace transformers vulnerable to remote code execution
    A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…
    trivyCVE-2026-4372
  • NLTK through 3.8.1 allows remote code execution if untrusted packages ...
    NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
    trivyCVE-2024-39705
  • nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files
    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processi…
    trivyCVE-2026-33236
  • nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
    A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensit…
    trivyCVE-2026-0846
  • nltk: NLTK: Arbitrary file read via path traversal vulnerability
    A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file pa…
    trivyCVE-2026-0847
  • nltk: NLTK: Denial of Service via unauthenticated remote shutdown
    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet B…
    trivyCVE-2026-33231
  • nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`
    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and…
    trivyCVE-2026-54293
  • Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed…
    trivyCVE-2026-59205
  • Pillow: Pillow: Denial of Service via crafted JPEG2000 image
    Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient …
    trivyCVE-2026-59204
  • Pillow: Pillow: Denial of service via crafted PDF stream
    Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus…
    trivyCVE-2026-59200
  • Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing
    Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadi…
    trivyCVE-2026-40192
  • Pillow: Pillow: Denial of Service via out-of-bounds write in image processing
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v…
    trivyCVE-2026-59199
  • Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image
    Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t…
    trivyCVE-2026-54058
  • Pillow: Pillow: Native heap out-of-bounds write
    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali…
    trivyCVE-2026-59197
  • pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
    Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
    trivyCVE-2026-25990
  • Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing
    Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.
    trivyCVE-2026-42311
  • python-pillow: Pillow: Denial of Service via crafted BDF font file
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented de…
    trivyCVE-2026-55379
  • python-pillow: Pillow: Denial of Service via crafted GD 2.x image file
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap alloca…
    trivyCVE-2026-55380
  • python-pillow: Pillow: Denial of Service via crafted PCF font data
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause exce…
    trivyCVE-2026-54059
  • python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files
    Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during …
    trivyCVE-2026-54060
  • python-pillow: pillow: Pillow DDS Heap Buffer Overflow
    Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only aff…
    trivyCVE-2025-48379
  • python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…
    trivyCVE-2026-49476
  • python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so…
    trivyCVE-2026-49476
  • python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…
    trivyCVE-2026-5241
  • python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…
    trivyCVE-2026-5241
  • python-ujson: improper decoding of escaped surrogate characters may lead to string corruption, key confusion or value overwriting
    UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly.…
    trivyCVE-2022-31116
  • python-ujson: UltraJSON: Memory leak leading to Denial of Service
    UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each fa…
    trivyCVE-2026-44660
  • python: protobuf: Protobuf: Denial of Service due to recursion depth bypass
    A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling l…
    trivyCVE-2026-0994
  • soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…
    trivyCVE-2026-49477
  • soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so…
    trivyCVE-2026-49477
  • Tornado is a Python web framework and asynchronous networking library. ...
    Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTT…
    trivyCVE-2026-49855
  • Tornado is a Python web framework and asynchronous networking library. ...
    Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed sc…
    trivyCVE-2026-49853
  • tornado-python: Tornado: Denial of Service via large multipart bodies
    Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this cre…
    trivyCVE-2026-31958
  • tornado: Tornado Quadratic DoS via Crafted Multipart Parameters
    Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to parse specific HTTP header va…
    trivyCVE-2025-67726
  • tornado: Tornado Quadratic DoS via Repeated Header Coalescing
    Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using stri…
    trivyCVE-2025-67725
  • tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
    In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
    trivyCVE-2026-35536
  • transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit t…
    trivyCVE-2024-11393
  • transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this v…
    trivyCVE-2024-11392
  • transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vu…
    trivyCVE-2024-11394
  • ultrajson: UltraJSON: Denial of Service via large indent parameter in JSON serialization
    UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the …
    trivyCVE-2026-32875
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418
  • wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking
    wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the fil…
    trivyCVE-2026-24049

This report is public.