Scanner: Docker Scout
Critical vulnerabilities: 0
High vulnerabilities: 17
Medium vulnerabilities: 8
Critical
No critical vulnerabilities found.
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| GHSA-3rp5-jjmw-4wv2 | gitpython | 3.1.50 | 3.1.53 | GHSA-3rp5-jjmw-4wv2: Improper Neutralization of Special Elements in Output Used by a Downstream Comp... |
| CVE-2026-12243 | nltk | 3.9.4 | not fixed | CVE-2026-12243 |
| CVE-2026-54293 | nltk | 3.9.4 | 3.10.0 | CVE-2026-54293: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-59884 | pyasn1 | 0.6.3 | 0.6.4 | CVE-2026-59884 |
| CVE-2026-59885 | pyasn1 | 0.6.3 | 0.6.4 | CVE-2026-59885: Uncontrolled Resource Consumption |
| CVE-2026-59886 | pyasn1 | 0.6.3 | 0.6.4 | CVE-2026-59886: Uncontrolled Resource Consumption |
| CVE-2026-59939 | httplib2 | 0.31.0 | 0.32.0 | CVE-2026-59939: Uncontrolled Resource Consumption |
| GHSA-6p8h-3wgx-97gf | gitpython | 3.1.50 | 3.1.54 | GHSA-6p8h-3wgx-97gf: Incomplete List of Disallowed Inputs |
| GHSA-94p4-4cq8-9g67 | gitpython | 3.1.50 | 3.1.55 | GHSA-94p4-4cq8-9g67: Exposure of Sensitive Information to an Unauthorized Actor |
| GHSA-rwj8-pgh3-r573 | gitpython | 3.1.50 | 3.1.52 | GHSA-rwj8-pgh3-r573: Exposure of Sensitive Information to an Unauthorized Actor |
| RUSTSEC-2026-0194 | quick-xml | 0.40.1 | 0.41.0 | RUSTSEC-2026-0194 |
| RUSTSEC-2026-0195 | quick-xml | 0.40.1 | 0.41.0 | RUSTSEC-2026-0195 |
| GHSA-fjr4-x663-mwxc | gitpython | 3.1.50 | 3.1.54 | GHSA-fjr4-x663-mwxc: Improper Neutralization of Argument Delimiters in a Command ('Argument Injectio... |
| GHSA-956x-8gvw-wg5v | gitpython | 3.1.50 | 3.1.51 | GHSA-956x-8gvw-wg5v: Improper Neutralization of Special Elements used in a Command ('Command Injecti... |
| GHSA-v396-v7q4-x2qj | gitpython | 3.1.50 | 3.1.51 | GHSA-v396-v7q4-x2qj: Improper Neutralization of Special Elements used in an OS Command ('OS Command ... |
| GHSA-2f96-g7mh-g2hx | gitpython | 3.1.50 | 3.1.51 | GHSA-2f96-g7mh-g2hx: Incomplete List of Disallowed Inputs |
| GHSA-r9mr-m37c-5fr3 | gitpython | 3.1.50 | 3.1.54 | GHSA-r9mr-m37c-5fr3: Improper Neutralization of Special Elements used in an OS Command ('OS Command ... |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2025-69872 | diskcache | 5.6.3 | not fixed | CVE-2025-69872: Deserialization of Untrusted Data |
| CVE-2026-41425 | authlib | 1.6.9 | 1.6.11 | CVE-2026-41425: Cross-Site Request Forgery (CSRF) |
| CVE-2026-41479 | authlib | 1.6.9 | 1.6.10 | CVE-2026-41479: URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| CVE-2026-44681 | authlib | 1.6.9 | 1.6.12 | CVE-2026-44681: URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2026-59890 | setuptools | 82.0.1 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2025-71176 | pytest | 9.0.2 | 9.0.3 | CVE-2025-71176: Creation of Temporary File in Directory with Insecure Permissions |
| CVE-2026-45409 | idna | 3.11 | 3.15 | CVE-2026-45409: Inefficient Regular Expression Complexity |