VulnScope — package-centric CVE lookup- LOW3.7CVE-2026-49854Tornado has out-of-bounds memory access via C extension
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- MEDIUM5.8Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
- MEDIUM6.5python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
- MEDIUM5.9Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
- HIGH8.1Litestar has HTML Injection Through its CSRF Token
- MEDIUM6.5vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
- MEDIUM5.4Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
- MEDIUM4.3Bugsink: DOS using large numbers of event tags
- MEDIUM4.3Bugsink: Project scoping missing in sourcemap and debug-file lookup
- LOW3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
- LOW3.1Bugsink: Issue event views can show an event from another project if its UUID is known
- HIGH8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
- MEDIUM6.5Authorization Bypass in SearchModelVersions in mlflow/mlflow
- MEDIUM6.5Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
- HIGH7.3Apache Airflow: Arbitrary import in custom deadline-reference deserialization
- HIGH8.8Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
- HIGH7.5Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation
- MEDIUM4.3Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
- MEDIUM6.5Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler
- MEDIUM5.3Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
- MEDIUM5.3Strawberry GraphQL has a Circular Fragment Reference DOS
- MEDIUM6.1WebOb: Location header normalization during redirect leads to open redirect - again
- HIGH8.6Docling Core: Unsafe remote filename resolution
- HIGH8.1Docling Core: Insufficient validation of image reference URIs