Open Source Vulnerabilities
vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm
vLLM: Cross-User Data Leak Vulnerability
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler-cloud
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
mkdocs-material
Material for MkDocs: DOM XSS in search suggestions via query parameter
mkdocs-material
Material for MkDocs: DOM XSS in search suggestions via query parameter
unstructured
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured
unstructured: Server-Side Request Forgery in the URL-based partitioning
scrapy
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
scrapy
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
omnigent
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
omnigent
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
mistune
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
mistune
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
tornado
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
tornado
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
banks
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
banks
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
pypdf
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
nltk
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
nltk
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
pypdf
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf
pypdf: Possible infinite loop for TreeObject.insert_child
sqlparse
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
nltk
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
nltk
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
djangorestframework
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
restrictedpython
RestrictedPython guard hooks can be shadowed via positional-only arguments
restrictedpython
RestrictedPython guard hooks can be shadowed via positional-only arguments
plone-app-event
plone.app.event vulnerable to denial of service via iCalendar import
plone-app-event
plone.app.event vulnerable to denial of service via iCalendar import
weblate
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
weblate
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
protego
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
protego
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
plone-app-portlets
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone-app-portlets
plone.app.portlets vulnerable to denial of service via RSS feed portlet
piccolo-admin
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
wsgidav
WsgiDAV MySQL provider has a blind SQL injection
compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
aiosmtplib
aiosmtplib: STARTTLS response injection
webob
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
webob
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
asyncssh
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
senaite-core
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite-core
senaite.core Vulnerable to Eval Injection and Missing Authorization
kas
kas Persistently Disables SSH Host Key Checking
starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
jupyterhub
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
jupyterhub
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
icalendar
icalendar has Algorithmic Complexity in Equality
chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
