AI stack advisories — vulnerabilities OSV published for the packages you run
Every security advisory OSV published in the last 60 days for 25 packages used in AI stacks (torch, transformers, vLLM, langchain, gradio, aiohttp and more): identifiers, affected and fixed versions, read from the API and not written by a model.
What this page is
Once a day we ask the OSV database — the vulnerability database maintained by Google, which aggregates GitHub Security Advisories, PyPA advisories, the NVD and others — what it has published in the last 60 days for 25 packages that show up in AI stacks. This page is the answer, unedited: identifiers, summaries, affected version ranges and fixed versions exactly as the API returns them. No language model writes anything here, and no human reviews it before publication.
Two things this page deliberately does not do. It does not rate anything: when OSV carries no severity field for an entry — which happens often, the PYSEC records in particular — the line below says so instead of guessing. And it does not tell you whether a flaw is exploitable in your deployment: that depends on how you call the library, and nobody but you can answer it.
The most recent advisory in this batch was published on 2026-09-17. GHSA-8pw2-6jv3-mj5j is the newest entry; the full list follows.
Advisories published in the last 60 days
| Published | Package | Identifier | Affected versions | Fixed in | Link |
|---|---|---|---|---|---|
| 2026-09-17 | vllm (PyPI) | GHSA-8pw2-6jv3-mj5j — CVE-2026-69147 | all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source) | 0.28.0 | GHSA-8pw2-6jv3-mj5j |
| 2026-09-16 | vllm (PyPI) | GHSA-hcwq-8wjf-3gcr — CVE-2026-57173 | all versions < 0.24.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+86 more listed by the source) | 0.24.0 | GHSA-hcwq-8wjf-3gcr |
| 2026-09-12 | vllm (PyPI) | PYSEC-2026-3985 — CVE-2026-90553 | all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source) | 0.28.0 | PYSEC-2026-3985 |
| 2026-09-08 | vllm (PyPI) | GHSA-7m6h-x95x-82q5 — CVE-2026-73558 | all versions < 0.27.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+90 more listed by the source) | 0.27.0 | GHSA-7m6h-x95x-82q5 |
| 2026-09-08 | vllm (PyPI) | GHSA-4hhp-h66f-j5j7 — CVE-2026-73560 | all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) | 0.26.0 | GHSA-4hhp-h66f-j5j7 |
| 2026-09-04 | vllm (PyPI) | GHSA-pr7f-p5mw-fc87 — CVE-2026-73557 | >= 0.21.0 < 0.26.0 ; enumerated versions: 0.21.0, 0.22.0, 0.22.1, … (+4 more listed by the source) | 0.26.0 | GHSA-pr7f-p5mw-fc87 |
| 2026-09-04 | vllm (PyPI) | GHSA-hwrm-c4cx-rf4j — CVE-2026-73555 | all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) | 0.26.0 | GHSA-hwrm-c4cx-rf4j |
| 2026-09-04 | vllm (PyPI) | GHSA-8737-qx52-hjff — CVE-2026-71486 | all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) | 0.26.0 | GHSA-8737-qx52-hjff |
| 2026-09-04 | vllm (PyPI) | GHSA-48jh-3gj7-fg8v — CVE-2026-73556 | all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source) | 0.26.0 | GHSA-48jh-3gj7-fg8v |
| 2026-08-13 | vllm (PyPI) | GHSA-87x5-vmc3-756j — CVE-2026-73559 | >= 0.19.0 < 0.26.0 ; enumerated versions: 0.19.0, 0.19.1, 0.20.0, … (+9 more listed by the source) | 0.26.0 | GHSA-87x5-vmc3-756j |
| 2026-08-10 | accelerate (PyPI) | GHSA-4j2p-28q2-5m79 — CVE-2026-69112 | all versions <= 1.14.0 ; enumerated versions: 0.0.1, 0.1.0, 0.10.0, … (+79 more listed by the source) | not provided by the source | GHSA-4j2p-28q2-5m79 |
| 2026-08-03 | aiohttp (PyPI) | GHSA-mq44-7p77-q5h7 — CVE-2026-59881 | all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source) | 3.14.2 | GHSA-mq44-7p77-q5h7 |
| 2026-08-03 | aiohttp (PyPI) | GHSA-mfx4-hv73-q22v — CVE-2026-69243 | all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source) | 3.14.2 | GHSA-mfx4-hv73-q22v |
| 2026-08-03 | aiohttp (PyPI) | GHSA-cq5v-8q36-5273 — CVE-2026-69244 | all versions < 3.14.3 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+306 more listed by the source) | 3.14.3 | GHSA-cq5v-8q36-5273 |
| 2026-08-02 | transformers (PyPI) | GHSA-xrqw-3rrv-vx5w — CVE-2026-9856 | all versions < 5.10.0 ; enumerated versions: 0.1, 2.0.0, 2.1.0, … (+223 more listed by the source) | 5.10.0 | GHSA-xrqw-3rrv-vx5w |
| 2026-07-23 | vllm (PyPI) | PYSEC-2026-3542 — CVE-2026-54234 | >= 0.17.1 < 0.24.0 ; enumerated versions: 0.17.1, 0.18.0, 0.18.1, … (+9 more listed by the source) | 0.24.0 | PYSEC-2026-3542 |
| 2026-07-23 | pillow (PyPI) | PYSEC-2026-3496 — CVE-2026-59204 | >= 8.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+24 more listed by the source) | 12.3.0 | PYSEC-2026-3496 |
| 2026-07-23 | pillow (PyPI) | PYSEC-2026-3495 — CVE-2026-59200 | >= 5.1.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+45 more listed by the source) | 12.3.0 | PYSEC-2026-3495 |
| 2026-07-23 | pillow (PyPI) | PYSEC-2026-3494 — CVE-2026-59198 | >= 5.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+44 more listed by the source) | 12.3.0 | PYSEC-2026-3494 |
| 2026-07-23 | pillow (PyPI) | PYSEC-2026-3493 — CVE-2026-54058 | all versions < 12.3.0 ; enumerated versions: 1.0, 1.1, 1.2, … (+103 more listed by the source) | 12.3.0 | PYSEC-2026-3493 |
One line per advisory, with the source summary
- vllm (PyPI), published 2026-09-17 —
GHSA-8pw2-6jv3-mj5j— severity: MODERATE (database_specific.severityof OSV entry GHSA-8pw2-6jv3-mj5j)- Summary, quoted from the source: “vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation”
- Aliases listed by OSV: CVE-2026-69147
- Affected versions: all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source)
- Fixed in: 0.28.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - Source entry: https://osv.dev/vulnerability/GHSA-8pw2-6jv3-mj5j
- vllm (PyPI), published 2026-09-16 —
GHSA-hcwq-8wjf-3gcr— severity: MODERATE (database_specific.severityof OSV entry GHSA-hcwq-8wjf-3gcr)- Summary, quoted from the source: “vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions”
- Aliases listed by OSV: CVE-2026-57173
- Affected versions: all versions < 0.24.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+86 more listed by the source)
- Fixed in: 0.24.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - Source entry: https://osv.dev/vulnerability/GHSA-hcwq-8wjf-3gcr
- vllm (PyPI), published 2026-09-12 —
PYSEC-2026-3985— severity: not provided by the source — this OSV entry has nodatabase_specific.severity; itsseverityfield carries only a CVSS vector, quoted in full below- Summary, quoted from the source (summary read from the identifier
CVE-2026-90553, which OSV publishes for the same advisory): “vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor” - Aliases listed by OSV: CVE-2026-90553, GHSA-3c86-2m5g-59q7
- Affected versions: all versions < 0.28.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+92 more listed by the source)
- Fixed in: 0.28.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - Source entry: https://osv.dev/vulnerability/PYSEC-2026-3985
- Summary, quoted from the source (summary read from the identifier
- vllm (PyPI), published 2026-09-08 —
GHSA-7m6h-x95x-82q5,PYSEC-2026-3935— severity: MODERATE (database_specific.severityof OSV entry GHSA-7m6h-x95x-82q5)- Summary, quoted from the source: “vLLM: Cross-User Data Leak Vulnerability”
- Aliases listed by OSV: CVE-2026-73558, PYSEC-2026-3935, GHSA-7m6h-x95x-82q5
- Affected versions: all versions < 0.27.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+90 more listed by the source)
- Fixed in: 0.27.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N - Source entry: https://osv.dev/vulnerability/GHSA-7m6h-x95x-82q5
- vllm (PyPI), published 2026-09-08 —
GHSA-4hhp-h66f-j5j7,PYSEC-2026-3934— severity: MODERATE (database_specific.severityof OSV entry GHSA-4hhp-h66f-j5j7)- Summary, quoted from the source: “vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor
_fetch_imageand audio loader bypass MediaConnector protections” - Aliases listed by OSV: CVE-2026-73560, PYSEC-2026-3934, GHSA-4hhp-h66f-j5j7
- Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
- Fixed in: 0.26.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - Source entry: https://osv.dev/vulnerability/GHSA-4hhp-h66f-j5j7
- Summary, quoted from the source: “vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor
- vllm (PyPI), published 2026-09-04 —
GHSA-pr7f-p5mw-fc87,PYSEC-2026-3938— severity: MODERATE (database_specific.severityof OSV entry GHSA-pr7f-p5mw-fc87)- Summary, quoted from the source: “vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts”
- Aliases listed by OSV: CVE-2026-73557, PYSEC-2026-3938, GHSA-pr7f-p5mw-fc87
- Affected versions: >= 0.21.0 < 0.26.0 ; enumerated versions: 0.21.0, 0.22.0, 0.22.1, … (+4 more listed by the source)
- Fixed in: 0.26.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/GHSA-pr7f-p5mw-fc87
- vllm (PyPI), published 2026-09-04 —
GHSA-hwrm-c4cx-rf4j,PYSEC-2026-3937— severity: MODERATE (database_specific.severityof OSV entry GHSA-hwrm-c4cx-rf4j)- Summary, quoted from the source: “vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages”
- Aliases listed by OSV: CVE-2026-73555, PYSEC-2026-3937, GHSA-hwrm-c4cx-rf4j
- Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
- Fixed in: 0.26.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - Source entry: https://osv.dev/vulnerability/GHSA-hwrm-c4cx-rf4j
- vllm (PyPI), published 2026-09-04 —
GHSA-8737-qx52-hjff,PYSEC-2026-3936— severity: MODERATE (database_specific.severityof OSV entry GHSA-8737-qx52-hjff)- Summary, quoted from the source: “vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds”
- Aliases listed by OSV: CVE-2026-71486, PYSEC-2026-3936, GHSA-8737-qx52-hjff
- Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
- Fixed in: 0.26.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L - Source entry: https://osv.dev/vulnerability/GHSA-8737-qx52-hjff
- vllm (PyPI), published 2026-09-04 —
GHSA-48jh-3gj7-fg8v,PYSEC-2026-3933— severity: MODERATE (database_specific.severityof OSV entry GHSA-48jh-3gj7-fg8v)- Summary, quoted from the source: “vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m”
- Aliases listed by OSV: CVE-2026-73556, PYSEC-2026-3933, GHSA-48jh-3gj7-fg8v
- Affected versions: all versions < 0.26.0 ; enumerated versions: 0.0.1, 0.1.0, 0.1.1, … (+89 more listed by the source)
- Fixed in: 0.26.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L - Source entry: https://osv.dev/vulnerability/GHSA-48jh-3gj7-fg8v
- vllm (PyPI), published 2026-08-13 —
GHSA-87x5-vmc3-756j,PYSEC-2026-3704— severity: MODERATE (database_specific.severityof OSV entry GHSA-87x5-vmc3-756j)- Summary, quoted from the source: “vLLM: Completion prompt lists fan out into unbounded engine requests”
- Aliases listed by OSV: CVE-2026-73559, PYSEC-2026-3704, GHSA-87x5-vmc3-756j
- Affected versions: >= 0.19.0 < 0.26.0 ; enumerated versions: 0.19.0, 0.19.1, 0.20.0, … (+9 more listed by the source)
- Fixed in: 0.26.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - Source entry: https://osv.dev/vulnerability/GHSA-87x5-vmc3-756j
- accelerate (PyPI), published 2026-08-10 —
GHSA-4j2p-28q2-5m79,PYSEC-2026-3804— severity: MODERATE (database_specific.severityof OSV entry GHSA-4j2p-28q2-5m79)- Summary, quoted from the source: “Accelerate path traversal and denial of service via sharded checkpoint weight_map entries”
- Aliases listed by OSV: CVE-2026-69112, PYSEC-2026-3804, GHSA-4j2p-28q2-5m79
- Affected versions: all versions <= 1.14.0 ; enumerated versions: 0.0.1, 0.1.0, 0.10.0, … (+79 more listed by the source)
- Fixed in: not provided by the source
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H - CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/GHSA-4j2p-28q2-5m79
- aiohttp (PyPI), published 2026-08-03 —
GHSA-mq44-7p77-q5h7,PYSEC-2026-3547— severity: MODERATE (database_specific.severityof OSV entry GHSA-mq44-7p77-q5h7)- Summary, quoted from the source: “AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate”
- Aliases listed by OSV: CVE-2026-59881, PYSEC-2026-3547, GHSA-mq44-7p77-q5h7
- Affected versions: all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source)
- Fixed in: 3.14.2
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/GHSA-mq44-7p77-q5h7
- aiohttp (PyPI), published 2026-08-03 —
GHSA-mfx4-hv73-q22v,PYSEC-2026-3546— severity: MODERATE (database_specific.severityof OSV entry GHSA-mfx4-hv73-q22v)- Summary, quoted from the source: “AIOHTTP: HTTP request smuggling via WebSocket upgrade”
- Aliases listed by OSV: CVE-2026-69243, PYSEC-2026-3546, GHSA-mfx4-hv73-q22v
- Affected versions: all versions < 3.14.2 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+305 more listed by the source)
- Fixed in: 3.14.2
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/GHSA-mfx4-hv73-q22v
- aiohttp (PyPI), published 2026-08-03 —
GHSA-cq5v-8q36-5273,PYSEC-2026-3545— severity: HIGH (database_specific.severityof OSV entry GHSA-cq5v-8q36-5273)- Summary, quoted from the source: “AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)”
- Aliases listed by OSV: CVE-2026-69244, PYSEC-2026-3545, GHSA-cq5v-8q36-5273
- Affected versions: all versions < 3.14.3 ; enumerated versions: 0.1, 0.10.0, 0.10.1, … (+306 more listed by the source)
- Fixed in: 3.14.3
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/GHSA-cq5v-8q36-5273
- transformers (PyPI), published 2026-08-02 —
GHSA-xrqw-3rrv-vx5w,PYSEC-2026-3929— severity: HIGH (database_specific.severityof OSV entry GHSA-xrqw-3rrv-vx5w)- Summary, quoted from the source: “Transformers save_pretrained path traversal allows arbitrary file writes through chat template names”
- Aliases listed by OSV: CVE-2026-9856, PYSEC-2026-3929, GHSA-xrqw-3rrv-vx5w
- Affected versions: all versions < 5.10.0 ; enumerated versions: 0.1, 2.0.0, 2.1.0, … (+223 more listed by the source)
- Fixed in: 5.10.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L - Source entry: https://osv.dev/vulnerability/GHSA-xrqw-3rrv-vx5w
- vllm (PyPI), published 2026-07-23 —
PYSEC-2026-3542— severity: not provided by the source — this OSV entry has nodatabase_specific.severity; itsseverityfield carries only a CVSS vector, quoted in full below- Summary, quoted from the source: “vLLM has Remote DoS via Invalid Recovered Token Reinjection”
- Aliases listed by OSV: CVE-2026-54234, GHSA-8wr5-jm2h-8r4f
- Affected versions: >= 0.17.1 < 0.24.0 ; enumerated versions: 0.17.1, 0.18.0, 0.18.1, … (+9 more listed by the source)
- Fixed in: 0.24.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Source entry: https://osv.dev/vulnerability/PYSEC-2026-3542
- pillow (PyPI), published 2026-07-23 —
PYSEC-2026-3496— severity: not provided by the source — this OSV entry has nodatabase_specific.severity; itsseverityfield carries only a CVSS vector, quoted in full below- Summary, quoted from the source: “Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service”
- Aliases listed by OSV: BIT-pillow-2026-59204, CVE-2026-59204, GHSA-vjc4-5qp5-m44j
- Affected versions: >= 8.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+24 more listed by the source)
- Fixed in: 12.3.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/PYSEC-2026-3496
- pillow (PyPI), published 2026-07-23 —
PYSEC-2026-3495— severity: not provided by the source — this OSV entry has nodatabase_specific.severity; itsseverityfield carries only a CVSS vector, quoted in full below- Summary, quoted from the source: “Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()”
- Aliases listed by OSV: BIT-pillow-2026-59200, CVE-2026-59200, GHSA-jjj6-mw9f-p565
- Affected versions: >= 5.1.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+45 more listed by the source)
- Fixed in: 12.3.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Source entry: https://osv.dev/vulnerability/PYSEC-2026-3495
- pillow (PyPI), published 2026-07-23 —
PYSEC-2026-3494— severity: not provided by the source — this OSV entry has nodatabase_specific.severity; itsseverityfield carries only a CVSS vector, quoted in full below- Summary, quoted from the source: “Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images”
- Aliases listed by OSV: BIT-pillow-2026-59198, CVE-2026-59198, GHSA-fj7v-r99m-22gq
- Affected versions: >= 5.2.0 < 12.3.0 ; enumerated versions: 10.0.0, 10.0.1, 10.1.0, … (+44 more listed by the source)
- Fixed in: 12.3.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L - Source entry: https://osv.dev/vulnerability/PYSEC-2026-3494
- pillow (PyPI), published 2026-07-23 —
PYSEC-2026-3493— severity: not provided by the source — this OSV entry has nodatabase_specific.severity; itsseverityfield carries only a CVSS vector, quoted in full below- Summary, quoted from the source: “Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)”
- Aliases listed by OSV: BIT-pillow-2026-54058, CVE-2026-54058, GHSA-62p4-gmf7-7g93
- Affected versions: all versions < 12.3.0 ; enumerated versions: 1.0, 1.1, 1.2, … (+103 more listed by the source)
- Fixed in: 12.3.0
- CVSS vector, copied character for character from the source (no score is computed by us):
CVSS_V4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N - Source entry: https://osv.dev/vulnerability/PYSEC-2026-3493
How this page is built
- Data read live from the OSV (api.osv.dev/v1/query) on 2026-09-20 (server clock); the exact read window is kept in the dated state file. Nothing on this page predates that read, and nothing on it was written earlier.
- Window: advisories whose
publishedfield falls on or after 2026-07-22 (the last 60 days). Entries outside that window are skipped, however severe they look. - Exact package names and ecosystems queried (25 queries, one POST request each):
torch(PyPI),transformers(PyPI),vllm(PyPI),langchain(PyPI),langchain-core(PyPI),openai(PyPI),llama-index(PyPI),sentence-transformers(PyPI),accelerate(PyPI),diffusers(PyPI),gradio(PyPI),fastapi(PyPI),pydantic(PyPI),numpy(PyPI),pillow(PyPI),aiohttp(PyPI),requests(PyPI),safetensors(PyPI),onnxruntime(PyPI),xgboost(PyPI),scikit-learn(PyPI),tensorflow(PyPI),openai(npm),langchain(npm),@langchain/core(npm). - 25 of 25 queries returned a valid answer. None failed.
- Identifiers, summaries, affected ranges and fixed versions are copied verbatim from the API response. Where OSV lists the same vulnerability under more than one identifier (a GitHub advisory and a PyPA entry sharing one CVE), the entries are grouped and every identifier of the group is shown.
- Severity appears only when the source provides it: either
database_specific.severity(the entry's own word, for example MODERATE) or a CVSS vector from theseverityfield, quoted character for character and attributed to the entry that carries it. No score is computed, converted or averaged on this page. - No assessment of our own: no exploitability claim, no priority ranking, no affected-product reasoning. This is a reading of a database, not an audit.
- No human reviewed this page before publication. It is written by
pipelines/stack_advisories.pyand published unread. If the API is unavailable, the run fails and the page is left as it was — an empty page is never substituted for a failed collection. - Source of record: https://api.osv.dev/v1/query (POST, JSON body) · entry detail: https://osv.dev/vulnerability/
Was this article helpful?
Let us know to improve our AI generation.