VYPR

apk package

wolfi/open-webui

pkg:apk/wolfi/open-webui

Vulnerabilities (145)

  • CVE-2026-81727HigAug 27, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a sha

  • CVE-2026-81724MedAug 27, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets

  • CVE-2026-81723LowAug 27, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of serv

  • CVE-2026-81722HigAug 27, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it f

  • CVE-2026-79675CriAug 25, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to

  • CVE-2026-78680HigAug 25, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working direc

  • CVE-2026-66393HigAug 22, 2026
    affected < 0.8.12-r2fixed 0.8.12-r2

    NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unh

  • CVE-2026-71514LowAug 22, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the path

  • CVE-2026-71513HigAug 22, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attacker

  • CVE-2026-72818HigAug 20, 2026
    affected < 0.11.3-r1fixed 0.11.3-r1

    The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label sepa

  • CVE-2026-71870LowAug 7, 2026
    affected < 0.11.0-r8fixed 0.11.0-r8

    pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction.

  • CVE-2026-71852LowAug 7, 2026
    affected < 0.11.0-r8fixed 0.11.0-r8

    pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries

  • CVE-2026-71554MedAug 6, 2026
    affected < 0.11.0-r2fixed 0.11.0-r2

    h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the r

  • CVE-2026-67422HigAug 6, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in expon

  • CVE-2026-61632MedAug 6, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by by joining the src onto

  • CVE-2026-69247HigAug 3, 2026
    affected < 0.11.0-r8fixed 0.11.0-r8

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguish

  • CVE-2026-69244HigAug 3, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental resp

  • CVE-2026-69243MedAug 3, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggli

  • CVE-2026-12061higJul 31, 2026
    affected < 0.11.0-r7fixed 0.11.0-r7

    ### Summary `ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an optional greedy run o

  • CVE-2026-59881MedJul 30, 2026
    affected < 0.11.0-r6fixed 0.11.0-r6

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpect

Page 1 of 8