Skip to main content

api Security Scan

View Release Notes
Securityv3.9.8Generated 2026-07-27 08:02:54 UTC
Critical
Clean
High
52 found
Scan Date
Jul 27, 2026

Scanner: Docker Scout

Critical vulnerabilities: 0

High vulnerabilities: 17

Medium vulnerabilities: 8

Critical

No critical vulnerabilities found.

High

CVEPackageInstalledFixedDescription
GHSA-3rp5-jjmw-4wv2gitpython3.1.503.1.53GHSA-3rp5-jjmw-4wv2: Improper Neutralization of Special Elements in Output Used by a Downstream Comp...
CVE-2026-12243nltk3.9.4not fixedCVE-2026-12243
CVE-2026-54293nltk3.9.43.10.0CVE-2026-54293: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59884pyasn10.6.30.6.4CVE-2026-59884
CVE-2026-59885pyasn10.6.30.6.4CVE-2026-59885: Uncontrolled Resource Consumption
CVE-2026-59886pyasn10.6.30.6.4CVE-2026-59886: Uncontrolled Resource Consumption
CVE-2026-59939httplib20.31.00.32.0CVE-2026-59939: Uncontrolled Resource Consumption
GHSA-6p8h-3wgx-97gfgitpython3.1.503.1.54GHSA-6p8h-3wgx-97gf: Incomplete List of Disallowed Inputs
GHSA-94p4-4cq8-9g67gitpython3.1.503.1.55GHSA-94p4-4cq8-9g67: Exposure of Sensitive Information to an Unauthorized Actor
GHSA-rwj8-pgh3-r573gitpython3.1.503.1.52GHSA-rwj8-pgh3-r573: Exposure of Sensitive Information to an Unauthorized Actor
RUSTSEC-2026-0194quick-xml0.40.10.41.0RUSTSEC-2026-0194
RUSTSEC-2026-0195quick-xml0.40.10.41.0RUSTSEC-2026-0195
GHSA-fjr4-x663-mwxcgitpython3.1.503.1.54GHSA-fjr4-x663-mwxc: Improper Neutralization of Argument Delimiters in a Command ('Argument Injectio...
GHSA-956x-8gvw-wg5vgitpython3.1.503.1.51GHSA-956x-8gvw-wg5v: Improper Neutralization of Special Elements used in a Command ('Command Injecti...
GHSA-v396-v7q4-x2qjgitpython3.1.503.1.51GHSA-v396-v7q4-x2qj: Improper Neutralization of Special Elements used in an OS Command ('OS Command ...
GHSA-2f96-g7mh-g2hxgitpython3.1.503.1.51GHSA-2f96-g7mh-g2hx: Incomplete List of Disallowed Inputs
GHSA-r9mr-m37c-5fr3gitpython3.1.503.1.54GHSA-r9mr-m37c-5fr3: Improper Neutralization of Special Elements used in an OS Command ('OS Command ...

Medium

CVEPackageInstalledFixedDescription
CVE-2025-69872diskcache5.6.3not fixedCVE-2025-69872: Deserialization of Untrusted Data
CVE-2026-41425authlib1.6.91.6.11CVE-2026-41425: Cross-Site Request Forgery (CSRF)
CVE-2026-41479authlib1.6.91.6.10CVE-2026-41479: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
CVE-2026-44681authlib1.6.91.6.12CVE-2026-44681: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-59890setuptools82.0.183.0.0CVE-2026-59890: Improper Handling of Unicode Encoding
CVE-2025-71176pytest9.0.29.0.3CVE-2025-71176: Creation of Temporary File in Directory with Insecure Permissions
CVE-2026-45409idna3.113.15CVE-2026-45409: Inefficient Regular Expression Complexity
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.