Back to AI Stack Advisories
stack advisoriesstack-advisoriessecuritysupply-chain

AI stack advisories — vulnerabilities OSV published for the packages you run

Every security advisory OSV published in the last 60 days for 25 packages used in AI stacks (torch, transformers, vLLM, langchain, gradio, aiohttp and more): identifiers, affected and fixed versions, read from the API and not written by a model.

FTL LabSeptember 20, 202616 min read3 038 words

What this page is

Once a day we ask the OSV database — the vulnerability database maintained by Google, which aggregates GitHub Security Advisories, PyPA advisories, the NVD and others — what it has published in the last 60 days for 25 packages that show up in AI stacks. This page is the answer, unedited: identifiers, summaries, affected version ranges and fixed versions exactly as the API returns them. No language model writes anything here, and no human reviews it before publication.

Two things this page deliberately does not do. It does not rate anything: when OSV carries no severity field for an entry — which happens often, the PYSEC records in particular — the line below says so instead of guessing. And it does not tell you whether a flaw is exploitable in your deployment: that depends on how you call the library, and nobody but you can answer it.

The most recent advisory in this batch was published on 2026-09-17. GHSA-8pw2-6jv3-mj5j is the newest entry; the full list follows.

Advisories published in the last 60 days

Published Package Identifier Affected versions Fixed in Link
2026-09-17 vllm (PyPI) GHSA-8pw2-6jv3-mj5j — CVE-2026-69147 all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source) 0.28.0 GHSA-8pw2-6jv3-mj5j
2026-09-16 vllm (PyPI) GHSA-hcwq-8wjf-3gcr — CVE-2026-57173 all versions < 0.24.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+86 more listed by the source) 0.24.0 GHSA-hcwq-8wjf-3gcr
2026-09-12 vllm (PyPI) PYSEC-2026-3985 — CVE-2026-90553 all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source) 0.28.0 PYSEC-2026-3985
2026-09-08 vllm (PyPI) GHSA-7m6h-x95x-82q5 — CVE-2026-73558 all versions < 0.27.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+90 more listed by the source) 0.27.0 GHSA-7m6h-x95x-82q5
2026-09-08 vllm (PyPI) GHSA-4hhp-h66f-j5j7 — CVE-2026-73560 all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) 0.26.0 GHSA-4hhp-h66f-j5j7
2026-09-04 vllm (PyPI) GHSA-pr7f-p5mw-fc87 — CVE-2026-73557 >= 0.21.0 < 0.26.0 ; enumerated versions: 0.21.0, 0.22.0, 0.22.1, … (+4 more listed by the source) 0.26.0 GHSA-pr7f-p5mw-fc87
2026-09-04 vllm (PyPI) GHSA-hwrm-c4cx-rf4j — CVE-2026-73555 all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) 0.26.0 GHSA-hwrm-c4cx-rf4j
2026-09-04 vllm (PyPI) GHSA-8737-qx52-hjff — CVE-2026-71486 all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) 0.26.0 GHSA-8737-qx52-hjff
2026-09-04 vllm (PyPI) GHSA-48jh-3gj7-fg8v — CVE-2026-73556 all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) 0.26.0 GHSA-48jh-3gj7-fg8v
2026-08-13 vllm (PyPI) GHSA-87x5-vmc3-756j — CVE-2026-73559 >= 0.19.0 < 0.26.0 ; enumerated versions: 0.19.0, 0.19.1, 0.20.0, … (+9 more listed by the source) 0.26.0 GHSA-87x5-vmc3-756j
2026-08-10 accelerate (PyPI) GHSA-4j2p-28q2-5m79 — CVE-2026-69112 all versions <= 1.14.0 ; enumerated versions: 0.0.1, 0.1.0, 0.10.0, … (+79 more listed by the source) not provided by the source GHSA-4j2p-28q2-5m79
2026-08-03 aiohttp (PyPI) GHSA-mq44-7p77-q5h7 — CVE-2026-59881 all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source) 3.14.2 GHSA-mq44-7p77-q5h7
2026-08-03 aiohttp (PyPI) GHSA-mfx4-hv73-q22v — CVE-2026-69243 all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source) 3.14.2 GHSA-mfx4-hv73-q22v
2026-08-03 aiohttp (PyPI) GHSA-cq5v-8q36-5273 — CVE-2026-69244 all versions < 3.14.3 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+306 more listed by the source) 3.14.3 GHSA-cq5v-8q36-5273
2026-08-02 transformers (PyPI) GHSA-xrqw-3rrv-vx5w — CVE-2026-9856 all versions < 5.10.0 ; enumerated versions: 0.1, 2.0.0, 2.1.0, … (+223 more listed by the source) 5.10.0 GHSA-xrqw-3rrv-vx5w
2026-07-23 vllm (PyPI) PYSEC-2026-3542 — CVE-2026-54234 >= 0.17.1 < 0.24.0 ; enumerated versions: 0.17.1, 0.18.0, 0.18.1, … (+9 more listed by the source) 0.24.0 PYSEC-2026-3542
2026-07-23 pillow (PyPI) PYSEC-2026-3496 — CVE-2026-59204 >= 8.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+24 more listed by the source) 12.3.0 PYSEC-2026-3496
2026-07-23 pillow (PyPI) PYSEC-2026-3495 — CVE-2026-59200 >= 5.1.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+45 more listed by the source) 12.3.0 PYSEC-2026-3495
2026-07-23 pillow (PyPI) PYSEC-2026-3494 — CVE-2026-59198 >= 5.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+44 more listed by the source) 12.3.0 PYSEC-2026-3494
2026-07-23 pillow (PyPI) PYSEC-2026-3493 — CVE-2026-54058 all versions < 12.3.0 ; enumerated versions: 1.0, 1.1, 1.2, … (+103 more listed by the source) 12.3.0 PYSEC-2026-3493

One line per advisory, with the source summary

  • vllm (PyPI), published 2026-09-17 — GHSA-8pw2-6jv3-mj5j — severity: MODERATE (database_specific.severity of OSV entry GHSA-8pw2-6jv3-mj5j)
    • Summary, quoted from the source: “vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation”
    • Aliases listed by OSV: CVE-2026-69147
    • Affected versions: all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source)
    • Fixed in: 0.28.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    • Source entry: https://osv.dev/vulnerability/GHSA-8pw2-6jv3-mj5j
  • vllm (PyPI), published 2026-09-16 — GHSA-hcwq-8wjf-3gcr — severity: MODERATE (database_specific.severity of OSV entry GHSA-hcwq-8wjf-3gcr)
    • Summary, quoted from the source: “vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions”
    • Aliases listed by OSV: CVE-2026-57173
    • Affected versions: all versions < 0.24.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+86 more listed by the source)
    • Fixed in: 0.24.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    • Source entry: https://osv.dev/vulnerability/GHSA-hcwq-8wjf-3gcr
  • vllm (PyPI), published 2026-09-12 — PYSEC-2026-3985 — severity: not provided by the source — this OSV entry has no database_specific.severity; its severity field carries only a CVSS vector, quoted in full below
    • Summary, quoted from the source (summary read from the identifier CVE-2026-90553, which OSV publishes for the same advisory): “vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor”
    • Aliases listed by OSV: CVE-2026-90553, GHSA-3c86-2m5g-59q7
    • Affected versions: all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source)
    • Fixed in: 0.28.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • Source entry: https://osv.dev/vulnerability/PYSEC-2026-3985
  • vllm (PyPI), published 2026-09-08 — GHSA-7m6h-x95x-82q5, PYSEC-2026-3935 — severity: MODERATE (database_specific.severity of OSV entry GHSA-7m6h-x95x-82q5)
    • Summary, quoted from the source: “vLLM: Cross-User Data Leak Vulnerability”
    • Aliases listed by OSV: CVE-2026-73558, PYSEC-2026-3935, GHSA-7m6h-x95x-82q5
    • Affected versions: all versions < 0.27.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+90 more listed by the source)
    • Fixed in: 0.27.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
    • Source entry: https://osv.dev/vulnerability/GHSA-7m6h-x95x-82q5
  • vllm (PyPI), published 2026-09-08 — GHSA-4hhp-h66f-j5j7, PYSEC-2026-3934 — severity: MODERATE (database_specific.severity of OSV entry GHSA-4hhp-h66f-j5j7)
    • Summary, quoted from the source: “vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor _fetch_image and audio loader bypass MediaConnector protections”
    • Aliases listed by OSV: CVE-2026-73560, PYSEC-2026-3934, GHSA-4hhp-h66f-j5j7
    • Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
    • Fixed in: 0.26.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    • Source entry: https://osv.dev/vulnerability/GHSA-4hhp-h66f-j5j7
  • vllm (PyPI), published 2026-09-04 — GHSA-pr7f-p5mw-fc87, PYSEC-2026-3938 — severity: MODERATE (database_specific.severity of OSV entry GHSA-pr7f-p5mw-fc87)
    • Summary, quoted from the source: “vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts”
    • Aliases listed by OSV: CVE-2026-73557, PYSEC-2026-3938, GHSA-pr7f-p5mw-fc87
    • Affected versions: >= 0.21.0 < 0.26.0 ; enumerated versions: 0.21.0, 0.22.0, 0.22.1, … (+4 more listed by the source)
    • Fixed in: 0.26.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/GHSA-pr7f-p5mw-fc87
  • vllm (PyPI), published 2026-09-04 — GHSA-hwrm-c4cx-rf4j, PYSEC-2026-3937 — severity: MODERATE (database_specific.severity of OSV entry GHSA-hwrm-c4cx-rf4j)
    • Summary, quoted from the source: “vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages”
    • Aliases listed by OSV: CVE-2026-73555, PYSEC-2026-3937, GHSA-hwrm-c4cx-rf4j
    • Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
    • Fixed in: 0.26.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    • Source entry: https://osv.dev/vulnerability/GHSA-hwrm-c4cx-rf4j
  • vllm (PyPI), published 2026-09-04 — GHSA-8737-qx52-hjff, PYSEC-2026-3936 — severity: MODERATE (database_specific.severity of OSV entry GHSA-8737-qx52-hjff)
    • Summary, quoted from the source: “vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds”
    • Aliases listed by OSV: CVE-2026-71486, PYSEC-2026-3936, GHSA-8737-qx52-hjff
    • Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
    • Fixed in: 0.26.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
    • Source entry: https://osv.dev/vulnerability/GHSA-8737-qx52-hjff
  • vllm (PyPI), published 2026-09-04 — GHSA-48jh-3gj7-fg8v, PYSEC-2026-3933 — severity: MODERATE (database_specific.severity of OSV entry GHSA-48jh-3gj7-fg8v)
    • Summary, quoted from the source: “vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m”
    • Aliases listed by OSV: CVE-2026-73556, PYSEC-2026-3933, GHSA-48jh-3gj7-fg8v
    • Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
    • Fixed in: 0.26.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    • Source entry: https://osv.dev/vulnerability/GHSA-48jh-3gj7-fg8v
  • vllm (PyPI), published 2026-08-13 — GHSA-87x5-vmc3-756j, PYSEC-2026-3704 — severity: MODERATE (database_specific.severity of OSV entry GHSA-87x5-vmc3-756j)
    • Summary, quoted from the source: “vLLM: Completion prompt lists fan out into unbounded engine requests”
    • Aliases listed by OSV: CVE-2026-73559, PYSEC-2026-3704, GHSA-87x5-vmc3-756j
    • Affected versions: >= 0.19.0 < 0.26.0 ; enumerated versions: 0.19.0, 0.19.1, 0.20.0, … (+9 more listed by the source)
    • Fixed in: 0.26.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    • Source entry: https://osv.dev/vulnerability/GHSA-87x5-vmc3-756j
  • accelerate (PyPI), published 2026-08-10 — GHSA-4j2p-28q2-5m79, PYSEC-2026-3804 — severity: MODERATE (database_specific.severity of OSV entry GHSA-4j2p-28q2-5m79)
    • Summary, quoted from the source: “Accelerate path traversal and denial of service via sharded checkpoint weight_map entries”
    • Aliases listed by OSV: CVE-2026-69112, PYSEC-2026-3804, GHSA-4j2p-28q2-5m79
    • Affected versions: all versions <= 1.14.0 ; enumerated versions: 0.0.1, 0.1.0, 0.10.0, … (+79 more listed by the source)
    • Fixed in: not provided by the source
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/GHSA-4j2p-28q2-5m79
  • aiohttp (PyPI), published 2026-08-03 — GHSA-mq44-7p77-q5h7, PYSEC-2026-3547 — severity: MODERATE (database_specific.severity of OSV entry GHSA-mq44-7p77-q5h7)
    • Summary, quoted from the source: “AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate”
    • Aliases listed by OSV: CVE-2026-59881, PYSEC-2026-3547, GHSA-mq44-7p77-q5h7
    • Affected versions: all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source)
    • Fixed in: 3.14.2
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/GHSA-mq44-7p77-q5h7
  • aiohttp (PyPI), published 2026-08-03 — GHSA-mfx4-hv73-q22v, PYSEC-2026-3546 — severity: MODERATE (database_specific.severity of OSV entry GHSA-mfx4-hv73-q22v)
    • Summary, quoted from the source: “AIOHTTP: HTTP request smuggling via WebSocket upgrade”
    • Aliases listed by OSV: CVE-2026-69243, PYSEC-2026-3546, GHSA-mfx4-hv73-q22v
    • Affected versions: all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source)
    • Fixed in: 3.14.2
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/GHSA-mfx4-hv73-q22v
  • aiohttp (PyPI), published 2026-08-03 — GHSA-cq5v-8q36-5273, PYSEC-2026-3545 — severity: HIGH (database_specific.severity of OSV entry GHSA-cq5v-8q36-5273)
    • Summary, quoted from the source: “AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)”
    • Aliases listed by OSV: CVE-2026-69244, PYSEC-2026-3545, GHSA-cq5v-8q36-5273
    • Affected versions: all versions < 3.14.3 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+306 more listed by the source)
    • Fixed in: 3.14.3
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/GHSA-cq5v-8q36-5273
  • transformers (PyPI), published 2026-08-02 — GHSA-xrqw-3rrv-vx5w, PYSEC-2026-3929 — severity: HIGH (database_specific.severity of OSV entry GHSA-xrqw-3rrv-vx5w)
    • Summary, quoted from the source: “Transformers save_pretrained path traversal allows arbitrary file writes through chat template names”
    • Aliases listed by OSV: CVE-2026-9856, PYSEC-2026-3929, GHSA-xrqw-3rrv-vx5w
    • Affected versions: all versions < 5.10.0 ; enumerated versions: 0.1, 2.0.0, 2.1.0, … (+223 more listed by the source)
    • Fixed in: 5.10.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
    • Source entry: https://osv.dev/vulnerability/GHSA-xrqw-3rrv-vx5w
  • vllm (PyPI), published 2026-07-23 — PYSEC-2026-3542 — severity: not provided by the source — this OSV entry has no database_specific.severity; its severity field carries only a CVSS vector, quoted in full below
    • Summary, quoted from the source: “vLLM has Remote DoS via Invalid Recovered Token Reinjection”
    • Aliases listed by OSV: CVE-2026-54234, GHSA-8wr5-jm2h-8r4f
    • Affected versions: >= 0.17.1 < 0.24.0 ; enumerated versions: 0.17.1, 0.18.0, 0.18.1, … (+9 more listed by the source)
    • Fixed in: 0.24.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • Source entry: https://osv.dev/vulnerability/PYSEC-2026-3542
  • pillow (PyPI), published 2026-07-23 — PYSEC-2026-3496 — severity: not provided by the source — this OSV entry has no database_specific.severity; its severity field carries only a CVSS vector, quoted in full below
    • Summary, quoted from the source: “Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service”
    • Aliases listed by OSV: BIT-pillow-2026-59204, CVE-2026-59204, GHSA-vjc4-5qp5-m44j
    • Affected versions: >= 8.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+24 more listed by the source)
    • Fixed in: 12.3.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/PYSEC-2026-3496
  • pillow (PyPI), published 2026-07-23 — PYSEC-2026-3495 — severity: not provided by the source — this OSV entry has no database_specific.severity; its severity field carries only a CVSS vector, quoted in full below
    • Summary, quoted from the source: “Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()”
    • Aliases listed by OSV: BIT-pillow-2026-59200, CVE-2026-59200, GHSA-jjj6-mw9f-p565
    • Affected versions: >= 5.1.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+45 more listed by the source)
    • Fixed in: 12.3.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • Source entry: https://osv.dev/vulnerability/PYSEC-2026-3495
  • pillow (PyPI), published 2026-07-23 — PYSEC-2026-3494 — severity: not provided by the source — this OSV entry has no database_specific.severity; its severity field carries only a CVSS vector, quoted in full below
    • Summary, quoted from the source: “Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images”
    • Aliases listed by OSV: BIT-pillow-2026-59198, CVE-2026-59198, GHSA-fj7v-r99m-22gq
    • Affected versions: >= 5.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+44 more listed by the source)
    • Fixed in: 12.3.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
    • Source entry: https://osv.dev/vulnerability/PYSEC-2026-3494
  • pillow (PyPI), published 2026-07-23 — PYSEC-2026-3493 — severity: not provided by the source — this OSV entry has no database_specific.severity; its severity field carries only a CVSS vector, quoted in full below
    • Summary, quoted from the source: “Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)”
    • Aliases listed by OSV: BIT-pillow-2026-54058, CVE-2026-54058, GHSA-62p4-gmf7-7g93
    • Affected versions: all versions < 12.3.0 ; enumerated versions: 1.0, 1.1, 1.2, … (+103 more listed by the source)
    • Fixed in: 12.3.0
    • CVSS vector, copied character for character from the source (no score is computed by us): CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
    • Source entry: https://osv.dev/vulnerability/PYSEC-2026-3493

How this page is built

  • Data read live from the OSV (api.osv.dev/v1/query) on 2026-09-20 (server clock); the exact read window is kept in the dated state file. Nothing on this page predates that read, and nothing on it was written earlier.
  • Window: advisories whose published field falls on or after 2026-07-22 (the last 60 days). Entries outside that window are skipped, however severe they look.
  • Exact package names and ecosystems queried (25 queries, one POST request each): torch (PyPI), transformers (PyPI), vllm (PyPI), langchain (PyPI), langchain-core (PyPI), openai (PyPI), llama-index (PyPI), sentence-transformers (PyPI), accelerate (PyPI), diffusers (PyPI), gradio (PyPI), fastapi (PyPI), pydantic (PyPI), numpy (PyPI), pillow (PyPI), aiohttp (PyPI), requests (PyPI), safetensors (PyPI), onnxruntime (PyPI), xgboost (PyPI), scikit-learn (PyPI), tensorflow (PyPI), openai (npm), langchain (npm), @langchain/core (npm).
  • 25 of 25 queries returned a valid answer. None failed.
  • Identifiers, summaries, affected ranges and fixed versions are copied verbatim from the API response. Where OSV lists the same vulnerability under more than one identifier (a GitHub advisory and a PyPA entry sharing one CVE), the entries are grouped and every identifier of the group is shown.
  • Severity appears only when the source provides it: either database_specific.severity (the entry's own word, for example MODERATE) or a CVSS vector from the severity field, quoted character for character and attributed to the entry that carries it. No score is computed, converted or averaged on this page.
  • No assessment of our own: no exploitability claim, no priority ranking, no affected-product reasoning. This is a reading of a database, not an audit.
  • No human reviewed this page before publication. It is written by pipelines/stack_advisories.py and published unread. If the API is unavailable, the run fails and the page is left as it was — an empty page is never substituted for a failed collection.
  • Source of record: https://api.osv.dev/v1/query (POST, JSON body) · entry detail: https://osv.dev/vulnerability/
stack-advisoriessecuritysupply-chainosvftl-lab
Share this article:

Was this article helpful?

Let us know to improve our AI generation.