Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-q43m-vhcp-mhvm
  • PyPI/docling
  • PyPI/docling-slim
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode 2 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-ph3r-5jfg-f84f
  • PyPI/vllm
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core 2 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-935w-9g4m-p28p
  • PyPI/vllm
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle 2 hours ago
  • Fix available
  • Severity - 3.1 (Low)
GHSA-g6x2-hccm-hh4m
  • PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names 2 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-v4x9-3549-crwv
  • PyPI/pymongo
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding 2 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-vp6j-j7w5-5xjj
  • PyPI/pymongo
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters 2 hours ago
  • Fix available
  • Severity - 8.3 (High)
GHSA-qx36-8mw2-4r3x
  • PyPI/pymongo
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption 2 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-x33g-cr3x-6449
  • PyPI/pyjwt
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion 2 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-x6mc-67gf-chw4
  • PyPI/vllm
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach 2 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-58v5-2m8f-94pr
  • PyPI/vllm
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion 2 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-ph72-cqr5-qpp7
  • PyPI/vllm
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features 2 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-85xf-c7hm-whqw
  • PyPI/vllm
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites) 2 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2phq-3phc-84px
  • PyPI/vllm
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank` 2 hours ago
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-2823-qmq8-rwvj
  • PyPI/vllm
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service 2 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2cv4-cqwr-gwf7
  • PyPI/uv
  • crates.io/uv
uv: Path traversal on Windows through wheel extraction 2 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-5639-2j2p-m4mx
  • PyPI/mako
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup 2 hours ago
  • Fix available
  • Severity - 6.5 (Medium)