VulnScope — package-centric CVE lookup- HIGH8.3CVE-2026-50574yt-dlp: Arbitrary code execution via manifest downloads with aria2c
- HIGH8.6Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
- HIGH7.5Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)
- HIGH8.3yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
- MEDIUM6.1yt-dlp: File Downloader cookie leak with curl
- MEDIUM6.1Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
- MEDIUM6.5Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
- HIGH7.5vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
- HIGH8.8Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
- HIGH7.5Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
- HIGH7.5Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
- LOW3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
- HIGH7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
- LOW3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
- LOW3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
- LOW3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
- HIGH7.7Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- HIGH7.5tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- HIGH7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- MEDIUM5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
- LOW3.7Tornado has out-of-bounds memory access via C extension
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- MEDIUM5.8Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
- MEDIUM6.5python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
- MEDIUM5.9Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header