packages
npm / PyPI / Rust / Java / Ruby / PHP + OSVKeeps: package, version, advisory
- 2026-07-07npm release: next 16.3.0-canary.80
The React Framework
package:npm:next - 2026-07-07npm release: nx 23.1.0-rc.0
The core Nx plugin contains the core functionality of Nx like the project graph, nx commands and task orchestration.
NXpackage:npm:nx - 2026-07-07PyPI release: langflow 1.10.2
A Python package with a built-in web application
LANGFLOWpackage:pypi:langflow - 2026-07-07PyPI release: langflow 1.10.2rc4
A Python package with a built-in web application
LANGFLOWpackage:pypi:langflow - 2026-07-07OSV advisory: langflow PYSEC-2026-1525
Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()
LANGFLOWosv:pypi:langflow - 2026-07-07OSV advisory: langflow PYSEC-2026-1524
Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx Langflow Missing Authentication on Critical API Endpoints
LANGFLOWosv:pypi:langflow - 2026-07-07OSV advisory: langflow PYSEC-2026-1522
Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery
LANGFLOWosv:pypi:langflow Aliases: CVE-2025-6051, GHSA-rcv9-qm8p-9p6j Hugging Face Transformers library has Regular Expression Denial of Service
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-6921, GHSA-4w7r-h757-3r74 Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-6638, GHSA-59p9-h35m-wg4g Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-5197, GHSA-9356-575x-2w9m Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-3933, GHSA-37mw-44qp-f5jm Transformers is vulnerable to ReDoS attack through its DonutProcessor class
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-3263, GHSA-q2wp-rjmx-x6x9 Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-3777, GHSA-phhr-52qp-3mj4 Transformers's Improper Input Validation vulnerability can be exploited through username injection
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-3264, GHSA-jjph-296x-mrcr Transformers vulnerable to ReDoS attack through its get_imports() function
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-3262, GHSA-489j-g2vx-39wf Transformers vulnerable to ReDoS attack through its SETTING_RE variable
HUGGINGFACEosv:pypi:transformersAliases: CVE-2025-1194, GHSA-fpwr-67px-3qhx Transformers Regular Expression Denial of Service (ReDoS) vulnerability
HUGGINGFACEosv:pypi:transformers- 2026-07-07OSV advisory: litellm PYSEC-2026-1546
Aliases: CVE-2025-0628, GHSA-fjcf-3j3r-78rp LiteLLM Has an Improper Authorization Vulnerability
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1543
Aliases: CVE-2025-0330, GHSA-879v-fggm-vxw2 LiteLLM Has a Leakage of Langfuse API Keys
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1548
Aliases: CVE-2024-9606, GHSA-g5pg-73fc-hjwq LiteLLM Reveals Portion of API Key via a Logging File
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1545
Aliases: CVE-2024-8984, GHSA-fh2c-86xm-pm2x LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1541
Aliases: CVE-2024-6825, GHSA-53gh-p8jc-7rg8 LiteLLM Vulnerable to Remote Code Execution (RCE)
LITELLMosv:pypi:litellm Aliases: CVE-2024-12720, GHSA-6rvg-6v2m-4j46 Transformers Regular Expression Denial of Service (ReDoS) vulnerability
HUGGINGFACEosv:pypi:transformers- 2026-07-07OSV advisory: litellm PYSEC-2026-1549
Aliases: CVE-2024-10188, GHSA-gw2q-qw9j-rgv7 LiteLLM Vulnerable to Denial of Service (DoS)
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: langflow PYSEC-2026-1523
Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution
LANGFLOWosv:pypi:langflow - 2026-07-07OSV advisory: langflow PYSEC-2026-1521
Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow
LANGFLOWosv:pypi:langflow - 2026-07-07OSV advisory: litellm PYSEC-2026-1547
Aliases: CVE-2024-6587, GHSA-g26j-5385-hhw3 LiteLLM Server-Side Request Forgery (SSRF) vulnerability
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1551
Aliases: CVE-2024-5710, GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1550
Aliases: CVE-2024-5225, GHSA-h6m6-jj8v-94jj SQL injection in litellm
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1544
Aliases: CVE-2024-4890, GHSA-8j42-pcfm-3467 SQL injection in litellm
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1540
Aliases: CVE-2024-4888, GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm
LITELLMosv:pypi:litellm - 2026-07-07OSV advisory: litellm PYSEC-2026-1542
Aliases: CVE-2024-4264, GHSA-7ggm-4rjg-594w litellm passes untrusted data to `eval` function without sanitization
LITELLMosv:pypi:litellm Aliases: CVE-2024-3568, GHSA-37q5-v5qm-c9v8 Transformers Deserialization of Untrusted Data vulnerability
HUGGINGFACEosv:pypi:transformersRaw FFI bindings to platform libraries like libc.
packages:crates-io:libcderive(Error)
packages:crates-io:thiserrorImplementation detail of the `thiserror` crate
packages:crates-io:thiserror-implA macro to generate structures which behave like bitflags.
packages:crates-io:bitflagsRandom number generators and other randomness functionality.
packages:crates-io:randCore random number generation traits and tools for implementation.
packages:crates-io:rand_coreParser for Rust source code
packages:crates-io:synRust for Windows
packages:crates-io:windows-sysA small cross-platform library for retrieving random data from system source
packages:crates-io:getrandomA Rust port of Google's SwissTable hash map
packages:crates-io:hashbrown- 2026-07-07PyPI release: langflow 1.11.0.dev34
A Python package with a built-in web application
LANGFLOWpackage:pypi:langflow - 2026-07-07npm release: next 16.3.0-canary.79
The React Framework
package:npm:next