VYPR

apk package

chainguard/label-studio

pkg:apk/chainguard/label-studio

Vulnerabilities (67)

  • CVE-2026-66393HigAug 22, 2026
    affected < 1.23.0-r1fixed 1.23.0-r1

    NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unh

  • CVE-2026-71491HigAug 17, 2026
    affected < 1.23.0-r12fixed 1.23.0-r12

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format

  • CVE-2026-59894MedAug 17, 2026
    affected < 1.23.0-r12fixed 1.23.0-r12

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQ

  • CVE-2026-59893HigAug 17, 2026
    affected < 1.23.0-r12fixed 1.23.0-r12

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through

  • CVE-2026-54284HigAug 17, 2026
    affected < 1.23.0-r12fixed 1.23.0-r12

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.

  • CVE-2026-55415HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or custo

  • CVE-2026-55403LowJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowin

  • CVE-2026-55391HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in src/datamodel_code_generator/ht

  • CVE-2026-55389HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_gene

  • CVE-2026-54691HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loo

  • CVE-2026-54690HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.9.1 until 0.61.0, datamodel-code-generator silently dereferences attacker-controlled JSON Schem

  • CVE-2026-54654HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2, src/datamodel_code_generato

  • CVE-2026-54653HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory valu

  • CVE-2026-54621HigJul 28, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja

  • CVE-2026-59886HigJul 14, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent,

  • CVE-2026-59885HigJul 14, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per

  • CVE-2026-59200HigJul 14, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaus

  • CVE-2026-59197HigJul 14, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size vali

  • CVE-2026-54058CriJul 14, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.t

  • CVE-2026-59205HigJul 14, 2026
    affected < 1.23.0-r11fixed 1.23.0-r11

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed

Page 1 of 4