Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
820017
AlmaLinux
5541
Alpaquita
12763
Alpine
4374
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
616
Bitnami
8525
Chainguard
10011
CleanStart
1988
CRAN
14
crates.io
2639
Debian
62546
Echo
7861
GHC
3
GIT
98259
GitHub Actions
54
Go
8603
Hackage
32
Hex
228
Julia
1655
Linux
26631
Mageia
6105
Maven
6833
MinimOS
107576
npm
226183
NuGet
1844
opam
24
openEuler
7502
openSUSE
13884
OSS-Fuzz
3978
Packagist
6822
Pub
11
PyPI
24363
Red Hat
22066
Rocky Linux
3896
Root
18886
RubyGems
4591
SUSE
22316
SwiftURL
59
TuxCare
8271
Ubuntu
59901
VSCode
20
Wolfi
7124
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-h47f-gmjp-m7rr
PyPI/compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
2 days ago
Fix available
Severity - 8.6 (High)
PYSEC-2026-2425
PyPI/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
13 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-2427
PyPI/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
13 Jul
Fix available
Severity - 6.7 (Medium)
PYSEC-2026-2423
PyPI/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
13 Jul
Fix available
Severity - 8.4 (High)
PYSEC-2026-2426
PyPI/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
13 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-2424
PyPI/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
13 Jul
Fix available
Severity - 7.1 (High)
GHSA-gg2g-p7xc-qqmm
PyPI/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
28 May
Fix available
Severity - 7.8 (High)
GHSA-w76h-q7c6-jpjp
PyPI/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
28 May
Fix available
Severity - 6.7 (Medium)
GHSA-4q5v-7g7x-j79w
PyPI/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
28 May
Fix available
Severity - 8.4 (High)
GHSA-mj4x-vf5c-5xg8
PyPI/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
28 May
Fix available
Severity - 5.5 (Medium)
GHSA-g3vg-vx23-3858
PyPI/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
27 May
Fix available
Severity - 7.1 (High)
PyPI - OSV