Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.9.1Generated 2026-04-15 07:58:45 UTC
Critical
23 found
High
91 found
Scan Date
Apr 15, 2026

Scanner: Docker Scout

Critical vulnerabilities: 5

High vulnerabilities: 21

Medium vulnerabilities: 36

Critical

CVEPackageInstalledFixedDescription
CVE-2026-33186grpc1.77.01.79.3CVE-2026-33186: Improper Authorization
CVE-2026-6100python3.113.11.2-6%2Bdeb12u6not fixedCVE-2026-6100
CVE-2026-35030litellm1.82.61.83.0CVE-2026-35030: Improper Authentication
CVE-2024-52338pyarrow14.0.217.0.0CVE-2024-52338
CVE-2025-68121stdlib1.25.51.25.7CVE-2025-68121

High

CVEPackageInstalledFixedDescription
CVE-2026-24051sdk1.38.01.40.0CVE-2026-24051: Untrusted Search Path
CVE-2026-4519python3.12.133.13.13CVE-2026-4519
CVE-2025-55131nodejs22.21.0-1nodesource1not fixedCVE-2025-55131
CVE-2026-24049wheel0.45.10.46.2CVE-2026-24049: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-39883sdk1.38.01.43.0CVE-2026-39883: Untrusted Search Path
CVE-2024-23342ecdsa0.19.1not fixedCVE-2024-23342: Observable Discrepancy
CVE-2025-59465nodejs22.21.0-1nodesource1not fixedCVE-2025-59465
CVE-2025-59466nodejs22.21.0-1nodesource1not fixedCVE-2025-59466
CVE-2025-61726stdlib1.25.51.25.6CVE-2025-61726
CVE-2026-21637nodejs22.21.0-1nodesource1not fixedCVE-2026-21637
CVE-2026-21710nodejs22.21.0-1nodesource1not fixedCVE-2026-21710
CVE-2026-25679stdlib1.25.51.25.8CVE-2026-25679
CVE-2026-27135nghttp21.52.0-1%2Bdeb12u2not fixedCVE-2026-27135
CVE-2026-32280stdlib1.25.51.25.9CVE-2026-32280
CVE-2026-32281stdlib1.25.51.25.9CVE-2026-32281
CVE-2026-32283stdlib1.25.51.25.9CVE-2026-32283
CVE-2026-33231nltk3.9.3not fixedCVE-2026-33231: Missing Authentication for Critical Function
CVE-2026-26007cryptography44.0.346.0.5CVE-2026-26007: Insufficient Verification of Data Authenticity
GHSA-69x8-hrgq-fjj8litellm1.82.61.83.0GHSA-69x8-hrgq-fjj8: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-35029litellm1.82.61.83.0CVE-2026-35029: Incorrect Authorization
CVE-2026-40192pillow12.1.112.2.0CVE-2026-40192: Allocation of Resources Without Limits or Throttling

Medium

CVEPackageInstalledFixedDescription
CVE-2025-45582tar1.34%2Bdfsg-1.2%2Bdeb12u1not fixedCVE-2025-45582
CVE-2026-25934v55.16.45.16.5CVE-2026-25934: Improper Validation of Integrity Check Value
CVE-2026-25645requests2.32.52.33.0CVE-2026-25645: Insecure Temporary File
CVE-2026-33699pypdf6.9.16.9.2CVE-2026-33699: Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-34165v55.16.45.17.1CVE-2026-34165: Integer Underflow (Wrap or Wraparound)
CVE-2026-5704tar1.34%2Bdfsg-1.2%2Bdeb12u1not fixedCVE-2026-5704
GHSA-rf74-v2fm-23pwnltk3.9.3not fixedGHSA-rf74-v2fm-23pw: Uncontrolled Recursion
CVE-2025-69872diskcache5.6.3not fixedCVE-2025-69872: Deserialization of Untrusted Data
CVE-2022-42969py1.11.0not fixedCVE-2022-42969
CVE-2025-61730stdlib1.25.51.25.6CVE-2025-61730
CVE-2026-21714nodejs22.21.0-1nodesource1not fixedCVE-2026-21714
CVE-2026-33936ecdsa0.19.10.19.2CVE-2026-33936: Improper Handling of Length Parameter Inconsistency
CVE-2026-32288stdlib1.25.51.25.9CVE-2026-32288
CVE-2026-1502python3.12.13not fixedCVE-2026-1502
CVE-2026-21713nodejs22.21.0-1nodesource1not fixedCVE-2026-21713
CVE-2026-21717nodejs22.21.0-1nodesource1not fixedCVE-2026-21717
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.7.8GHSA-xmrv-pmrh-hhx2: Improper Input Validation
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.7.8GHSA-xmrv-pmrh-hhx2: Improper Input Validation
CVE-2026-3446python3.12.133.13.13CVE-2026-3446
CVE-2026-3644python3.113.11.2-6%2Bdeb12u6not fixedCVE-2026-3644
CVE-2026-3644python3.113.11.2-6%2Bdeb12u6not fixedCVE-2026-3644
CVE-2026-4224python3.113.11.2-6%2Bdeb12u6not fixedCVE-2026-4224
CVE-2026-4224python3.113.11.2-6%2Bdeb12u6not fixedCVE-2026-4224
CVE-2026-27142stdlib1.25.51.25.8CVE-2026-27142
CVE-2026-32289stdlib1.25.51.25.9CVE-2026-32289
CVE-2026-33230nltk3.9.33.9.4CVE-2026-33230: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-12781python3.12.133.13.10CVE-2025-12781
CVE-2026-34525aiohttp3.13.33.13.4CVE-2026-34525: Improper Input Validation
CVE-2026-32282stdlib1.25.51.25.9CVE-2026-32282
CVE-2025-61728stdlib1.25.51.25.6CVE-2025-61728
CVE-2026-34515aiohttp3.13.33.13.4CVE-2026-34515: Absolute Path Traversal
CVE-2026-34516aiohttp3.13.33.13.4CVE-2026-34516: Allocation of Resources Without Limits or Throttling
CVE-2025-71176pytest9.0.29.0.3CVE-2025-71176: Creation of Temporary File in Directory with Insecure Permissions
GHSA-pqhf-p39g-3x64uv0.8.90.9.6GHSA-pqhf-p39g-3x64: Improper Input Validation
CVE-2026-22815aiohttp3.13.33.13.4CVE-2026-22815: Uncontrolled Resource Consumption
CVE-2026-40260pypdf6.9.16.10.0CVE-2026-40260: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.