Skip to main content

api Security Scan

View Release Notes
Securityv3.9.4Generated 2026-05-21 07:08:27 UTC
Critical
2 found
High
44 found
Scan Date
May 20, 2026

Scanner: Docker Scout

Critical vulnerabilities: 0

High vulnerabilities: 13

Medium vulnerabilities: 10

Critical

No critical vulnerabilities found.

High

CVEPackageInstalledFixedDescription
CVE-2025-45768pyjwt2.12.0not fixedCVE-2025-45768
CVE-2024-23342ecdsa0.19.2not fixedCVE-2024-23342: Observable Discrepancy
CVE-2024-34997joblib1.5.2not fixedCVE-2024-34997
CVE-2025-69534markdown3.10.2not fixedCVE-2025-69534
CVE-2026-0846nltk3.9.4not fixedCVE-2026-0846
CVE-2025-14920transformers5.3.0not fixedCVE-2025-14920
CVE-2025-14921transformers5.3.0not fixedCVE-2025-14921
CVE-2025-14924transformers5.3.0not fixedCVE-2025-14924
CVE-2025-14926transformers5.3.0not fixedCVE-2025-14926
CVE-2025-14927transformers5.3.0not fixedCVE-2025-14927
CVE-2025-14928transformers5.3.0not fixedCVE-2025-14928
CVE-2025-14929transformers5.3.0not fixedCVE-2025-14929
CVE-2025-14930transformers5.3.0not fixedCVE-2025-14930

Medium

CVEPackageInstalledFixedDescription
CVE-2026-3219pip26.0.1not fixedCVE-2026-3219: Unrestricted Upload of File with Dangerous Type
CVE-2025-69872diskcache5.6.3not fixedCVE-2025-69872: Deserialization of Untrusted Data
CVE-2022-42969py1.11.0not fixedCVE-2022-42969
CVE-2024-1681flask-cors6.0.2not fixedCVE-2024-1681
CVE-2026-6357pip26.0.126.1CVE-2026-6357: Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-41425authlib1.6.91.6.11CVE-2026-41425: Cross-Site Request Forgery (CSRF)
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
CVE-2026-44681authlib1.6.91.6.12CVE-2026-44681: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-71176pytest9.0.29.0.3CVE-2025-71176: Creation of Temporary File in Directory with Insecure Permissions
CVE-2026-45409idna3.113.15CVE-2026-45409: Inefficient Regular Expression Complexity
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.