Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.10.0Generated 2026-05-21 11:01:53 UTC
Critical
2 found
High
101 found
Scan Date
May 21, 2026

Scanner: Docker Scout

Critical vulnerabilities: 2

High vulnerabilities: 32

Critical

CVEPackageInstalledFixedDescription
CVE-2026-33186grpc1.77.01.79.3CVE-2026-33186: Improper Authorization
CVE-2025-68121stdlib1.25.51.25.7CVE-2025-68121

High

CVEPackageInstalledFixedDescription
CVE-2025-45768pyjwt2.12.1not fixedCVE-2025-45768
CVE-2026-24051sdk1.38.01.40.0CVE-2026-24051: Untrusted Search Path
CVE-2026-45022v55.16.45.19.0CVE-2026-45022: Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-24049wheel0.45.10.46.2CVE-2026-24049: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-45134langsmith0.7.310.8.0CVE-2026-45134: Deserialization of Untrusted Data
CVE-2026-39883sdk1.38.01.43.0CVE-2026-39883: Untrusted Search Path
CVE-2024-34997joblib1.5.2not fixedCVE-2024-34997
CVE-2025-61726stdlib1.25.51.25.6CVE-2025-61726
CVE-2025-69534markdown3.10.2not fixedCVE-2025-69534
CVE-2026-0846nltk3.9.4not fixedCVE-2026-0846
CVE-2026-25679stdlib1.25.51.25.8CVE-2026-25679
CVE-2026-29181otel1.38.01.41.0CVE-2026-29181: Uncontrolled Resource Consumption
CVE-2026-32280stdlib1.25.51.25.9CVE-2026-32280
CVE-2026-32281stdlib1.25.51.25.9CVE-2026-32281
CVE-2026-32283stdlib1.25.51.25.9CVE-2026-32283
CVE-2026-33811stdlib1.25.51.25.10CVE-2026-33811
CVE-2026-33814net0.47.00.53.0CVE-2026-33814
CVE-2026-33814net0.47.00.53.0CVE-2026-33814
CVE-2026-39820stdlib1.25.51.25.10CVE-2026-39820
CVE-2026-39836stdlib1.25.51.25.10CVE-2026-39836
CVE-2026-41602thrift0.22.00.23.0CVE-2026-41602: Integer Overflow or Wraparound
CVE-2026-42499stdlib1.25.51.25.10CVE-2026-42499
CVE-2025-14920transformers5.3.0not fixedCVE-2025-14920
CVE-2025-14921transformers5.3.0not fixedCVE-2025-14921
CVE-2025-14924transformers5.3.0not fixedCVE-2025-14924
CVE-2025-14926transformers5.3.0not fixedCVE-2025-14926
CVE-2025-14927transformers5.3.0not fixedCVE-2025-14927
CVE-2025-14928transformers5.3.0not fixedCVE-2025-14928
CVE-2025-14929transformers5.3.0not fixedCVE-2025-14929
CVE-2025-14930transformers5.3.0not fixedCVE-2025-14930
CVE-2026-44973v55.6.25.9.0CVE-2026-44973: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-44660ujson5.12.05.12.1CVE-2026-44660: Missing Release of Memory after Effective Lifetime
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.