gitsafehub
github.com/lresende/kubeflow ↗

lresende/kubeflow

scanned 2026-08-12 · git 80cb162
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies431Known OSS vulnerabilities448Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 431 found · 5 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2019-6446 numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious CVE-2018-7575 Integer Overflow or Wraparound in Google TensorFlow
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2018-7575). Fix: Update that package to its patched version.
  • Serious CVE-2021-41208 Incomplete validation in boosted trees code
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-41208). Fix: Update that package to its patched version.
  • Serious CVE-2023-25668 CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25668). Fix: Update that package to its patched version.
  • Serious GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (GHSA-h6gw-r52c-724r). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequences
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2025-69534). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-14322 Pallets Werkzeug vulnerable to Path Traversal
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2019-14322). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerability
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2019-14806). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fields
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25577). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34069 python-werkzeug: user may execute code on a developer's machine
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34069). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-49766 werkzeug: python-werkzeug: Werkzeug safe_join not safe on Windows
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2024-49766). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66221 Werkzeug: Werkzeug: Denial of service via Windows device names in path segments
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66221). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensions
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2026-21860). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27199 Werkzeug safe_join() allows Windows special device names
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27199). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-6817 bleach.clean behavior parsing style attributes could result in a regul ...
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-6817). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-6802 In Mozilla Bleach before 3.11, a mutation XSS affects users calling bl ...
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-6802). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-6816 In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCD ...
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-6816). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-23980 python-bleach: Mutation cross-site scripting in bleach.clean
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-23980). Fix: Update that package to its patched version.
  • Worth fixing GHSA-gj48-438w-jh9v Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (GHSA-gj48-438w-jh9v). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-33953 gRPC: hpack table accounting errors can lead to denial of service
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-33953). Fix: Update that package to its patched version.
  • Worth fixing CVE-2016-9909 The serializer in html5lib before 0.99999999 might allow remote attack ...
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2016-9909). Fix: Update that package to its patched version.
  • Worth fixing CVE-2016-9910 The serializer in html5lib before 0.99999999 might allow remote attack ...
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2016-9910). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-41495 numpy: NULL pointer dereference in numpy.sort in in the PyArray_DescrNew() due to missing return-value validation
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-41495). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-33430 numpy: buffer overflow in the PyArray_NewFromDescr_int() in ctors.c
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-33430). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-34141 numpy: incomplete string comparison in the numpy.core component
    components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-34141). Fix: Update that package to its patched version.
… 406 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 448 found · 9 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2019-108 ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-205 Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2018-7575). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-125 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However,
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15202). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-128 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap ove
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15205). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-129 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corrupt
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-15206). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-400 TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of serv
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-41208). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-548 TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25668). Fix: Update that package to its patched version.
  • Serious GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-r6jx-9g48-2r5r Arbitrary code execution due to YAML deserialization
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-37678). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-89 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Ma
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2025-69534). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-140 Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2019-14806). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are ap
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-46136). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a sm
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-25577). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1065 Pallets Werkzeug vulnerable to Path Traversal
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2019-14322). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2043 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34069). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2044 Werkzeug safe_join() allows Windows special device names with compound extensions
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2026-21860). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2045 Werkzeug safe_join not safe on Windows
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2024-49766). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2046 Werkzeug safe_join() allows Windows special device names
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66221). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2320 Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previou
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27199). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-27 In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-6802). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-28 In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-6816). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-340 In Mozilla Bleach before 3.1.4, `bleach.clean` behavior parsing style attributes could result in a regular expression denial of service (ReDoS).
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2020-6817). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-865 In Mozilla Bleach before 3.3.0, a mutation XSS affects users calling bleach.clean with math or svg; p or br; and style, title, noscript, script, textarea, noframes, iframe, or xmp tags with strip_comm
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2021-23980). Fix: Update that package to its patched version.
  • Worth fixing GHSA-gj48-438w-jh9v Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1424 Excessive Iteration in gRPC
    /workdirs/scan-8d496586-643f-462d-82c4-319d455bc793/components/k8s-model-server/inception-client/requirements.txt
    A package you depend on has a known security hole (CVE-2023-33953). Fix: Update that package to its patched version.
… 423 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.