Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-41419 python-gevent: privilege escalation via a crafted script to the WSGIServer componentCVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposureCVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary codeCVE-2019-10906 python-jinja2: str.format_map allows sandbox escapeCVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filterCVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filterCVE-2024-34064 jinja2: accepts keys containing non-attribute charactersCVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format methodCVE-2021-20270 python-pygments: Infinite loop in SML lexer may lead to DoSCVE-2021-27291 python-pygments: ReDoS in multiple lexersCVE-2022-40896 pygments: ReDoS in pygmentsCVE-2023-37920 python-certifi: Removal of e-Tugra root certificateCVE-2022-23491 python-certifi: untrusted root certificatesCVE-2022-40899 python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web serverCVE-2024-3651 python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputsCVE-2018-18074 python-requests: Redirect from HTTPS to HTTP does not remove Authorization headerCVE-2023-32681 python-requests: Unintended leak of Proxy-Authorization headerCVE-2024-35195 requests: subsequent requests to the same host ignore cert verificationCVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLsCVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creationCVE-2019-11324 python-urllib3: Certification mishandle when error should be thrownCVE-2023-43804 python-urllib3: Cookie request header isn't stripped during cross-origin redirectsCVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed dataYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-177 An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.PYSEC-2018-32 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentialPYSEC-2021-421 Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.PYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2021-140 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only PYSEC-2021-141 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity anPYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.PYSEC-2022-42986 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates fromPYSEC-2023-135 Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed purPYSEC-2024-230 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.PYSEC-2022-42991 An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.PYSEC-2024-60 A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings,PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions priorPYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to disPYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rePYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLsPYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=FalsePYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system tePYSEC-2019-132 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.PYSEC-2019-133 The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.