gitsafehub
github.com/m-hilgendorf/lief ↗

m-hilgendorf/lief

scanned 2026-08-11 · git e1b5424
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies24Known OSS vulnerabilities74Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 24 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2026-25541 Bytes is a utility library for working with bytes. From version 1.2.1 ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-25541). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41676 rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41676). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41678 rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41678). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41681 rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41681). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41898 rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41898). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42327 rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-42327). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44662 rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-44662). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45784 rust-openssl: rust-openssl: Heap Corruption from Incorrect Buffer Sizing
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-45784). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4fcv-w3qc-ppgg rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (GHSA-4fcv-w3qc-ppgg). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-4432 ring: Some AES functions may panic when overflow checking is enabled in ring
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2025-4432). Fix: Update that package to its patched version.
  • Worth fixing GHSA-82j2-j2ch-gfr8 rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (GHSA-82j2-j2ch-gfr8). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25727 time: time affected by a stack exhaustion denial of service attack
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-25727). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLs
    doc/requirements.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creation
    doc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41066 lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read
    scripts/metrics/requirements.txt
    A package you depend on has a known security hole (CVE-2026-41066). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-71176 pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling
    tests/requirements.txt
    A package you depend on has a known security hole (CVE-2025-71176). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLs
    tests/requirements.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creation
    tests/requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Minor CVE-2025-15504 LIEF is vulnerable to segmentation fault
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2025-15504). Fix: Update that package to its patched version.
  • Minor CVE-2026-41677 rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41677). Fix: Update that package to its patched version.
  • Minor GHSA-965h-392x-2mh5 webpki: Name constraints for URI names were incorrectly accepted
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (GHSA-965h-392x-2mh5). Fix: Update that package to its patched version.
  • Minor GHSA-xgp8-3hg3-c2mh webpki: Name constraints were accepted for certificates asserting a wildcard name
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (GHSA-xgp8-3hg3-c2mh). Fix: Update that package to its patched version.
  • Minor GHSA-rr8g-9fpq-6wmg Tokio broadcast channel calls clone in parallel, but does not require `Sync`
    api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (GHSA-rr8g-9fpq-6wmg). Fix: Update that package to its patched version.
  • Minor CVE-2026-4539 pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer
    doc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4539). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 74 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing PYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system te
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-43012 Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40897). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-49 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to versio
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2025-47273). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1918 setuptools vulnerable to Command Injection via package URL
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2024-6345). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3447 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude,
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2026-59890). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-43017 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40898). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-148 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: thi
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2020-26137). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-192 urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of t
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2023-43804). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-212 urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had i
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2023-45803). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-141 urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fal
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44431). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1994 urllib3 streaming API improperly handles highly compressed data
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66471). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1995 urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2024-37891). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1996 Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2026-21441). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1998 urllib3 allows an unbounded number of links in the decompression chain
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66418). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1999 urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/.github/requirements.txt
    A package you depend on has a known security hole (CVE-2025-50181). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-49 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to versio
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/python/build-requirements.txt
    A package you depend on has a known security hole (CVE-2025-47273). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3447 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude,
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/python/build-requirements.txt
    A package you depend on has a known security hole (CVE-2026-59890). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2047 Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/python/build-requirements.txt
    A package you depend on has a known security hole (CVE-2026-24049). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2026-0007 Integer overflow in `BytesMut::reserve`
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-25541). Fix: Update that package to its patched version.
  • Worth fixing RUSTSEC-2025-0022 Use-After-Free in `Md::fetch` and `Cipher::fetch`
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-8c75-8mhr-p7r9 rust-openssl has incorrect bounds assertion in aes key wrap
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41678). Fix: Update that package to its patched version.
  • Worth fixing GHSA-ghm9-cr32-g9qj rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41681). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hppc-g8h3-xhp3 rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
    /workdirs/scan-9735ef05-f634-4502-b911-2cf527aa9bce/api/rust/cargo/Cargo.lock
    A package you depend on has a known security hole (CVE-2026-41898). Fix: Update that package to its patched version.
… 49 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.