Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.11.0Generated 2026-06-30 10:56:09 UTC
Critical
9 found
High
32 found
Scan Date
Jun 30, 2026

Scanner: Docker Scout

Critical vulnerabilities: 10

High vulnerabilities: 25

Medium vulnerabilities: 32

Critical

CVEPackageInstalledFixedDescription
CVE-2026-33186grpc1.77.01.79.3CVE-2026-33186: Improper Authorization
CVE-2026-39830crypto0.45.00.52.0CVE-2026-39830
CVE-2026-39831crypto0.45.00.52.0CVE-2026-39831
CVE-2026-39832crypto0.45.00.52.0CVE-2026-39832
CVE-2026-39833crypto0.45.00.52.0CVE-2026-39833
CVE-2026-39834crypto0.45.00.52.0CVE-2026-39834
CVE-2026-42508crypto0.45.00.52.0CVE-2026-42508
CVE-2026-39821net0.47.00.55.0CVE-2026-39821
CVE-2025-68121stdlib1.25.51.25.7CVE-2025-68121
CVE-2026-46595crypto0.45.00.52.0CVE-2026-46595

High

CVEPackageInstalledFixedDescription
CVE-2026-24051sdk1.38.01.40.0CVE-2026-24051: Untrusted Search Path
CVE-2026-45022v55.16.45.19.0CVE-2026-45022: Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-24049wheel0.45.10.46.2CVE-2026-24049: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-39883sdk1.38.01.43.0CVE-2026-39883: Untrusted Search Path
CVE-2025-61726stdlib1.25.51.25.6CVE-2025-61726
CVE-2026-25679stdlib1.25.51.25.8CVE-2026-25679
CVE-2026-29181otel1.38.01.41.0CVE-2026-29181: Uncontrolled Resource Consumption
CVE-2026-32280stdlib1.25.51.25.9CVE-2026-32280
CVE-2026-32281stdlib1.25.51.25.9CVE-2026-32281
CVE-2026-32283stdlib1.25.51.25.9CVE-2026-32283
CVE-2026-33811stdlib1.25.51.25.10CVE-2026-33811
CVE-2026-33814net0.47.01.25.10CVE-2026-33814
CVE-2026-33814net0.47.01.25.10CVE-2026-33814
CVE-2026-39820stdlib1.25.51.25.10CVE-2026-39820
CVE-2026-39829crypto0.45.00.52.0CVE-2026-39829
CVE-2026-39836stdlib1.25.51.25.10CVE-2026-39836
CVE-2026-41602thrift0.22.00.23.0CVE-2026-41602: Integer Overflow or Wraparound
CVE-2026-42499stdlib1.25.51.25.10CVE-2026-42499
CVE-2026-42504stdlib1.25.51.25.11CVE-2026-42504
CVE-2026-46597crypto0.45.00.52.0CVE-2026-46597
CVE-2026-48802python-engineio4.13.14.13.2CVE-2026-48802: Allocation of Resources Without Limits or Throttling
CVE-2026-48804python-socketio5.16.15.16.2CVE-2026-48804: Allocation of Resources Without Limits or Throttling
CVE-2026-48809python-engineio4.13.14.13.2CVE-2026-48809: Allocation of Resources Without Limits or Throttling
CVE-2026-54293nltk3.9.4not fixedCVE-2026-54293: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-44973v55.6.25.9.0CVE-2026-44973: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Medium

CVEPackageInstalledFixedDescription
CVE-2026-25934v55.16.45.16.5CVE-2026-25934: Improper Validation of Integrity Check Value
CVE-2026-41506v55.16.45.18.0CVE-2026-41506: Insufficiently Protected Credentials
CVE-2026-34165v55.16.45.17.1CVE-2026-34165: Integer Underflow (Wrap or Wraparound)
CVE-2025-61730stdlib1.25.51.25.6CVE-2025-61730
CVE-2026-39825stdlib1.25.51.25.10CVE-2026-39825
CVE-2026-39835crypto0.45.00.52.0CVE-2026-39835
CVE-2026-42507stdlib1.25.51.25.11CVE-2026-42507
CVE-2026-46598crypto0.45.00.52.0CVE-2026-46598
CVE-2026-45571v55.16.45.19.1CVE-2026-45571: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-32288stdlib1.25.51.25.9CVE-2026-32288
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.7.8GHSA-xmrv-pmrh-hhx2: Improper Input Validation
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.7.8GHSA-xmrv-pmrh-hhx2: Improper Input Validation
CVE-2026-25681net0.47.00.55.0CVE-2026-25681
CVE-2026-27136net0.47.00.55.0CVE-2026-27136
CVE-2026-27142stdlib1.25.51.25.8CVE-2026-27142
CVE-2026-32289stdlib1.25.51.25.9CVE-2026-32289
CVE-2026-39823stdlib1.25.51.25.10CVE-2026-39823
CVE-2026-39826stdlib1.25.51.25.10CVE-2026-39826
CVE-2026-42502net0.47.00.55.0CVE-2026-42502
CVE-2026-42506net0.47.00.55.0CVE-2026-42506
CVE-2026-39828crypto0.45.00.52.0CVE-2026-39828
CVE-2026-32282stdlib1.25.51.25.9CVE-2026-32282
CVE-2025-61728stdlib1.25.51.25.6CVE-2025-61728
CVE-2026-25680net0.47.00.55.0CVE-2026-25680
CVE-2026-27145stdlib1.25.51.25.11CVE-2026-27145
CVE-2026-39827crypto0.45.00.52.0CVE-2026-39827
CVE-2026-44740v55.6.25.9.0CVE-2026-44740: Uncontrolled Recursion
GHSA-w5pp-99ch-qj29v55.16.45.19.1GHSA-w5pp-99ch-qj29: Uncontrolled Resource Consumption
CVE-2026-46678pydantic-ai-slim1.94.01.99.0CVE-2026-46678: Server-Side Request Forgery (SSRF)
CVE-2026-48782pydantic-ai-slim1.94.01.102.0CVE-2026-48782: Server-Side Request Forgery (SSRF)
CVE-2026-45409idna3.113.15CVE-2026-45409: Inefficient Regular Expression Complexity
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.