VYPR

apk package

wolfi/open-webui

pkg:apk/wolfi/open-webui

Vulnerabilities (131)

  • CVE-2025-6985HigOct 6, 2025
    affected < 0.6.33-r0fixed 0.6.33-r0

    The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse

  • CVE-2025-61765MedOct 6, 2025
    affected < 0.6.33-r1fixed 0.6.33-r1

    python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server dep

  • CVE-2025-59420HigSep 22, 2025
    affected < 0.6.30-r1fixed 0.6.30-r1

    Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed toke

  • CVE-2025-6984HigSep 4, 2025
    affected < 0.6.27-r0fixed 0.6.27-r0

    The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external ent

  • CVE-2025-55197HigAug 13, 2025
    affected < 0.6.22-r1fixed 0.6.22-r1

    pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content

  • CVE-2025-54121MedJul 21, 2025
    affected < 0.6.18-r1fixed 0.6.18-r1

    Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will bl

  • CVE-2025-48379HigJul 1, 2025
    affected < 0.6.36-r0fixed 0.6.36-r0

    Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only aff

  • CVE-2025-50182MedJun 19, 2025
    affected < 0.6.36-r0fixed 0.6.36-r0

    urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpReque

  • CVE-2025-3000MedMar 31, 2025
    affected < 0.9.6-r5fixed 0.9.6-r5

    A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

  • CVE-2024-28219MedApr 3, 2024
    affected < 0.6.36-r0fixed 0.6.36-r0

    In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

  • CVE-2024-23342HigJan 23, 2024
    affected < 0.11.0-r0fixed 0.11.0-r0

    The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior

Page 7 of 7