VYPR

apk package

wolfi/open-webui

pkg:apk/wolfi/open-webui

Vulnerabilities (131)

  • CVE-2026-71870MedAug 7, 2026
    affected < 0.11.0-r8fixed 0.11.0-r8

    pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction.

  • CVE-2026-71852MedAug 7, 2026
    affected < 0.11.0-r8fixed 0.11.0-r8

    pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries

  • CVE-2026-71554MedAug 6, 2026
    affected < 0.11.0-r2fixed 0.11.0-r2

    h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the r

  • CVE-2026-67422HigAug 6, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in expon

  • CVE-2026-61632MedAug 6, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by by joining the src onto

  • CVE-2026-69247HigAug 3, 2026
    affected < 0.11.0-r8fixed 0.11.0-r8

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguish

  • CVE-2026-69244HigAug 3, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental resp

  • CVE-2026-69243MedAug 3, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggli

  • CVE-2026-12061higJul 31, 2026
    affected < 0.11.0-r7fixed 0.11.0-r7

    ### Summary `ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an optional greedy run o

  • CVE-2026-59881MedJul 30, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpect

  • CVE-2026-46338MedJul 16, 2026
    affected < 0.9.6-r1fixed 0.9.6-r1

    PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing mark

  • CVE-2026-49477HigJul 14, 2026
    affected < 0.10.1-r3fixed 0.10.1-r3

    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in so

  • CVE-2026-49476HigJul 14, 2026
    affected < 0.10.1-r3fixed 0.10.1-r3

    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to so

  • CVE-2026-59203MedJul 14, 2026
    affected < 0.10.2-r1fixed 0.10.2-r1

    Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeat

  • CVE-2026-59936HigJul 8, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection such as when extracting page text. This iss

  • CVE-2026-59935HigJul 8, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting pag

  • CVE-2026-59938MedJul 8, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.

  • CVE-2026-59937HigJul 8, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0.

  • CVE-2026-54531MedJun 22, 2026
    affected < 0.9.6-r5fixed 0.9.6-r5

    pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0.

  • CVE-2026-54530MedJun 22, 2026
    affected < 0.9.6-r5fixed 0.9.6-r5

    pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode. This vulnerability is fixed in 6.13.0.

Page 1 of 7