Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2199636
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9290
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68367
Echo
7422
GHC
3
GIT
108119
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144419
npm
228744
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25166
Red Hat
23331
Rocky Linux
4297
Root
19541
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9512
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-r4vp-3vw6-r2x5
PyPI/compliance-trestle
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
3 days ago
Fix available
Severity - 8.4 (High)
GHSA-mr95-65j8-9mxp
PyPI/compliance-trestle
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
3 days ago
Fix available
Severity - 7.8 (High)
PYSEC-2026-3817
PyPI/compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
10 Sep
Fix available
Severity - 7.8 (High)
GHSA-jw39-3688-r4rx
PyPI/compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
28 Aug
Fix available
Severity - 7.8 (High)
PYSEC-2026-3659
PyPI/compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
19 Aug
Fix available
Severity - 8.6 (High)
GHSA-h47f-gmjp-m7rr
PyPI/compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
12 Aug
Fix available
Severity - 8.6 (High)
PYSEC-2026-2425
PyPI/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
13 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-2427
PyPI/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
13 Jul
Fix available
Severity - 6.7 (Medium)
PYSEC-2026-2423
PyPI/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
13 Jul
Fix available
Severity - 8.4 (High)
PYSEC-2026-2426
PyPI/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
13 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-2424
PyPI/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
13 Jul
Fix available
Severity - 7.1 (High)
GHSA-gg2g-p7xc-qqmm
PyPI/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
28 May
Fix available
Severity - 7.8 (High)
GHSA-w76h-q7c6-jpjp
PyPI/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
28 May
Fix available
Severity - 6.7 (Medium)
GHSA-4q5v-7g7x-j79w
PyPI/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
28 May
Fix available
Severity - 8.4 (High)
GHSA-mj4x-vf5c-5xg8
PyPI/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
28 May
Fix available
Severity - 5.5 (Medium)
GHSA-g3vg-vx23-3858
PyPI/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
27 May
Fix available
Severity - 7.1 (High)
PyPI - OSV