Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.9.2Generated 2026-04-28 05:24:20 UTC
Critical
Clean
High
12 found
Scan Date
Apr 28, 2026

Scanner: Docker Scout

Critical vulnerabilities: 2

High vulnerabilities: 10

Medium vulnerabilities: 20

Critical

CVEPackageInstalledFixedDescription
CVE-2026-33186grpc1.77.01.79.3CVE-2026-33186: Improper Authorization
CVE-2025-68121stdlib1.25.51.25.7CVE-2025-68121

High

CVEPackageInstalledFixedDescription
CVE-2026-24051sdk1.38.01.40.0CVE-2026-24051: Untrusted Search Path
CVE-2026-24049wheel0.45.10.46.2CVE-2026-24049: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-39883sdk1.38.01.43.0CVE-2026-39883: Untrusted Search Path
CVE-2024-23342ecdsa0.19.1not fixedCVE-2024-23342: Observable Discrepancy
CVE-2025-61726stdlib1.25.51.25.6CVE-2025-61726
CVE-2026-25679stdlib1.25.51.25.8CVE-2026-25679
CVE-2026-32280stdlib1.25.51.25.9CVE-2026-32280
CVE-2026-32281stdlib1.25.51.25.9CVE-2026-32281
CVE-2026-32283stdlib1.25.51.25.9CVE-2026-32283
CVE-2026-33231nltk3.9.3not fixedCVE-2026-33231: Missing Authentication for Critical Function

Medium

CVEPackageInstalledFixedDescription
CVE-2026-25934v55.16.45.16.5CVE-2026-25934: Improper Validation of Integrity Check Value
CVE-2026-3219pip26.0.1not fixedCVE-2026-3219: Unrestricted Upload of File with Dangerous Type
GHSA-3xc5-wrhm-f963v55.16.45.18.0GHSA-3xc5-wrhm-f963: Insufficiently Protected Credentials
CVE-2026-34165v55.16.45.17.1CVE-2026-34165: Integer Underflow (Wrap or Wraparound)
GHSA-rf74-v2fm-23pwnltk3.9.3not fixedGHSA-rf74-v2fm-23pw: Uncontrolled Recursion
CVE-2025-69872diskcache5.6.3not fixedCVE-2025-69872: Deserialization of Untrusted Data
CVE-2022-42969py1.11.0not fixedCVE-2022-42969
CVE-2025-61730stdlib1.25.51.25.6CVE-2025-61730
CVE-2026-33936ecdsa0.19.10.19.2CVE-2026-33936: Improper Handling of Length Parameter Inconsistency
GHSA-jj8c-mmj3-mmgvauthlib1.6.91.6.11GHSA-jj8c-mmj3-mmgv: Cross-Site Request Forgery (CSRF)
CVE-2026-32288stdlib1.25.51.25.9CVE-2026-32288
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.7.8GHSA-xmrv-pmrh-hhx2: Improper Input Validation
GHSA-xmrv-pmrh-hhx2eventstream1.7.31.7.8GHSA-xmrv-pmrh-hhx2: Improper Input Validation
CVE-2026-27142stdlib1.25.51.25.8CVE-2026-27142
CVE-2026-32289stdlib1.25.51.25.9CVE-2026-32289
CVE-2026-33230nltk3.9.33.9.4CVE-2026-33230: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-32282stdlib1.25.51.25.9CVE-2026-32282
CVE-2025-61728stdlib1.25.51.25.6CVE-2025-61728
CVE-2025-71176pytest9.0.29.0.3CVE-2025-71176: Creation of Temporary File in Directory with Insecure Permissions
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.