Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.9.12Generated 2026-09-21 00:21:08 UTC
Critical
1 found
High
45 found
Scan Date
Sep 21, 2026

Scanner: Docker Scout

Critical vulnerabilities: 13

High vulnerabilities: 44

Medium vulnerabilities: 45

Critical

CVEPackageInstalledFixedDescription
CVE-2026-33186grpc1.77.01.79.3CVE-2026-33186: Improper Authorization
CVE-2026-39830crypto0.45.00.52.0CVE-2026-39830: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2026-39831crypto0.45.00.52.0CVE-2026-39831: Missing Authorization
CVE-2026-39832crypto0.45.00.52.0CVE-2026-39832: Improper Preservation of Permissions
CVE-2026-39833crypto0.45.00.52.0CVE-2026-39833: Missing Authorization
CVE-2026-39834crypto0.45.00.52.0CVE-2026-39834: Integer Overflow or Wraparound
CVE-2026-42508crypto0.45.00.52.0CVE-2026-42508: Improper Certificate Validation
CVE-2026-63374anyio4.11.04.14.2CVE-2026-63374: Improper Certificate Validation
CVE-2026-45833chromadb0.5.20not fixedCVE-2026-45833: Improper Control of Generation of Code ('Code Injection')
CVE-2026-39821net0.47.00.55.0CVE-2026-39821
CVE-2026-39821net0.47.00.55.0CVE-2026-39821
CVE-2025-68121stdlib1.25.51.25.7CVE-2025-68121
CVE-2026-46595crypto0.45.00.52.0CVE-2026-46595: Incorrect Implementation of Authentication Algorithm

High

CVEPackageInstalledFixedDescription
CVE-2026-84445grpc1.77.01.82.2CVE-2026-84445: Improper Validation of Array Index
CVE-2026-24051sdk1.38.01.40.0CVE-2026-24051: Untrusted Search Path
CVE-2026-45022v55.16.45.19.0CVE-2026-45022: Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-71556v55.16.45.19.2CVE-2026-71556: Improper Link Resolution Before File Access ('Link Following')
CVE-2026-87818gitpython3.1.593.1.60CVE-2026-87818
CVE-2026-39883sdk1.38.01.43.0CVE-2026-39883: Untrusted Search Path
CVE-2025-61726stdlib1.25.51.25.6CVE-2025-61726
CVE-2026-25679stdlib1.25.51.25.8CVE-2026-25679
CVE-2026-29181otel1.38.01.41.0CVE-2026-29181: Uncontrolled Resource Consumption
CVE-2026-32280stdlib1.25.51.25.9CVE-2026-32280
CVE-2026-32281stdlib1.25.51.25.9CVE-2026-32281
CVE-2026-32283stdlib1.25.51.25.9CVE-2026-32283
CVE-2026-33811stdlib1.25.51.25.10CVE-2026-33811
CVE-2026-33814net0.47.01.25.10CVE-2026-33814
CVE-2026-33814net0.47.01.25.10CVE-2026-33814
CVE-2026-33818stdlib1.25.51.25.13CVE-2026-33818
CVE-2026-39820stdlib1.25.51.25.10CVE-2026-39820
CVE-2026-39829crypto0.45.00.52.0CVE-2026-39829: Improper Validation of Specified Quantity in Input
CVE-2026-39836stdlib1.25.51.25.10CVE-2026-39836
CVE-2026-41602thrift0.22.00.23.0CVE-2026-41602: Integer Overflow or Wraparound
CVE-2026-42499stdlib1.25.51.25.10CVE-2026-42499
CVE-2026-42504stdlib1.25.51.25.11CVE-2026-42504
CVE-2026-46597crypto0.45.00.52.0CVE-2026-46597: Incorrect Type Conversion or Cast
CVE-2026-46600net0.47.00.56.0CVE-2026-46600
CVE-2026-56853stdlib1.25.51.25.13CVE-2026-56853
CVE-2026-56854crypto0.45.00.55.0CVE-2026-56854
CVE-2026-56855crypto0.45.00.56.0CVE-2026-56855
CVE-2026-56859stdlib1.25.51.25.13CVE-2026-56859
CVE-2026-56862stdlib1.25.51.25.13CVE-2026-56862
CVE-2026-57585msgpack1.1.21.2.1CVE-2026-57585
CVE-2026-78662crypto0.45.00.56.0CVE-2026-78662
CVE-2026-87819gitpython3.1.593.1.60CVE-2026-87819
GHSA-6v7p-g79w-8964msgpack1.1.21.2.1GHSA-6v7p-g79w-8964: Use After Free
CVE-2025-47273setuptools70.3.078.1.1CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-39822stdlib1.25.51.25.12CVE-2026-39822
CVE-2026-44973v55.6.25.9.0CVE-2026-44973: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-81726nltk3.10.3not fixedCVE-2026-81726: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-85091zlib1.3.2-r51.3.3-r0CVE-2026-85091
CVE-2026-43871thrift0.22.00.24.0CVE-2026-43871: Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-84304grpc1.77.01.83.1CVE-2026-84304: Uncontrolled Resource Consumption
CVE-2026-87817gitpython3.1.593.1.60CVE-2026-87817
CVE-2026-45830chromadb0.5.20not fixedCVE-2026-45830: Incorrect Privilege Assignment
CVE-2026-45831chromadb0.5.20not fixedCVE-2026-45831: Incorrect Authorization
GHSA-hrxh-6v49-42gfgrpc1.77.01.82.1GHSA-hrxh-6v49-42gf: Uncaught Exception

Medium

CVEPackageInstalledFixedDescription
CVE-2026-25934v55.16.45.16.5CVE-2026-25934: Improper Validation of Integrity Check Value
CVE-2026-41506v55.16.45.18.0CVE-2026-41506: Insufficiently Protected Credentials
CVE-2026-84310pypdf6.15.06.16.1CVE-2026-84310: Asymmetric Resource Consumption (Amplification)
CVE-2026-84311pypdf6.15.06.16.1CVE-2026-84311: Excessive Iteration
CVE-2026-34165v55.16.45.17.1CVE-2026-34165: Integer Underflow (Wrap or Wraparound)
CVE-2026-16599wget1.25.0-r161.25.0-r17CVE-2026-16599
CVE-2025-69872diskcache5.6.3not fixedCVE-2025-69872: Deserialization of Untrusted Data
CVE-2025-61730stdlib1.25.51.25.6CVE-2025-61730
CVE-2026-39825stdlib1.25.51.25.10CVE-2026-39825
CVE-2026-39835crypto0.45.00.52.0CVE-2026-39835: Improper Certificate Validation
CVE-2026-42505stdlib1.25.51.25.12CVE-2026-42505
CVE-2026-42507stdlib1.25.51.25.11CVE-2026-42507
CVE-2026-46598crypto0.45.00.52.0CVE-2026-46598: Improper Validation of Array Index
CVE-2026-85999soupsieve2.8.42.9.0CVE-2026-85999: Inefficient Regular Expression Complexity
CVE-2026-86000soupsieve2.8.42.9.0CVE-2026-86000: Inefficient Regular Expression Complexity
GHSA-2mjx-qc3c-rqvcrustls0.23.430.23.45GHSA-2mjx-qc3c-rqvc
CVE-2026-45571v55.16.45.19.1CVE-2026-45571: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-32288stdlib1.25.51.25.9CVE-2026-32288
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
CVE-2026-56860stdlib1.25.51.25.13CVE-2026-56860
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.97.3GHSA-xmrv-pmrh-hhx2: Improper Input Validation
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.97.3GHSA-xmrv-pmrh-hhx2: Improper Input Validation
CVE-2026-25681net0.47.00.55.0CVE-2026-25681
CVE-2026-27136net0.47.00.55.0CVE-2026-27136
CVE-2026-27142stdlib1.25.51.25.8CVE-2026-27142
CVE-2026-32289stdlib1.25.51.25.9CVE-2026-32289
CVE-2026-39823stdlib1.25.51.25.10CVE-2026-39823
CVE-2026-39826stdlib1.25.51.25.10CVE-2026-39826
CVE-2026-42502net0.47.00.55.0CVE-2026-42502
CVE-2026-42506net0.47.00.55.0CVE-2026-42506
CVE-2026-56858stdlib1.25.51.25.13CVE-2026-56858
CVE-2026-59890setuptools70.3.083.0.0CVE-2026-59890: Improper Handling of Unicode Encoding
CVE-2026-59890setuptools70.3.083.0.0CVE-2026-59890: Improper Handling of Unicode Encoding
CVE-2026-39828crypto0.45.00.52.0CVE-2026-39828: Improper Preservation of Permissions
CVE-2026-71557v55.16.45.19.2CVE-2026-71557: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-84303grpc1.77.01.83.1CVE-2026-84303: Improper Handling of Case Sensitivity
CVE-2026-32282stdlib1.25.51.25.9CVE-2026-32282
CVE-2025-61728stdlib1.25.51.25.6CVE-2025-61728
CVE-2026-25680net0.47.00.55.0CVE-2026-25680: Uncontrolled Resource Consumption
CVE-2026-27145stdlib1.25.51.25.11CVE-2026-27145
CVE-2026-39827crypto0.45.00.52.0CVE-2026-39827: Improper Enforcement of Message Integrity During Transmission in a Communication Cha...
CVE-2026-44740v55.6.25.9.0CVE-2026-44740: Uncontrolled Recursion
GHSA-w5pp-99ch-qj29v55.16.45.19.1GHSA-w5pp-99ch-qj29: Uncontrolled Resource Consumption
CVE-2026-64847anyio4.11.04.14.2CVE-2026-64847: Allocation of Resources Without Limits or Throttling
CVE-2026-84309pypdf6.15.06.16.0CVE-2026-84309: Loop with Unreachable Exit Condition ('Infinite Loop')
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.