gitsafehub
github.com/matrixise/talk-pythonie-meetup-kafka ↗

matrixise/talk-pythonie-meetup-kafka

scanned 2026-08-16 · git eb0380b
3 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets1Vulnerable dependencies127Known OSS vulnerabilities143Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 1 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    docker-compose.yml:24
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 127 found · 6 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious CVE-2021-41945 Encode OSS httpx < 0.23.0 is affected by improper input validation in ...
    poetry.lock
    A package you depend on has a known security hole (CVE-2021-41945). Fix: Update that package to its patched version.
  • Serious CVE-2021-25289 python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
    poetry.lock
    A package you depend on has a known security hole (CVE-2021-25289). Fix: Update that package to its patched version.
  • Serious CVE-2021-34552 python-pillow: Buffer overflow in image convert function
    poetry.lock
    A package you depend on has a known security hole (CVE-2021-34552). Fix: Update that package to its patched version.
  • Serious CVE-2022-22817 python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
    poetry.lock
    A package you depend on has a known security hole (CVE-2022-22817). Fix: Update that package to its patched version.
  • Serious CVE-2023-50447 pillow: Arbitrary Code Execution via the environment parameter
    poetry.lock
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-23334 aiohttp: follow_symlinks directory traversal vulnerability
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-23334). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-30251 aiohttp: DoS when trying to parse malformed POST requests
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-30251). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69223 aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-69223). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-69244 aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-69244). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-37276 python-aiohttp: HTTP request smuggling via llhttp HTTP request parser
    poetry.lock
    A package you depend on has a known security hole (CVE-2023-37276). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-47627 python-aiohttp: numerous issues in HTTP parser with header parsing
    poetry.lock
    A package you depend on has a known security hole (CVE-2023-47627). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-49081 aiohttp: HTTP request modification
    poetry.lock
    A package you depend on has a known security hole (CVE-2023-49081). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-49082 aiohttp: CRLF injection if user controls the HTTP method using aiohttp client
    poetry.lock
    A package you depend on has a known security hole (CVE-2023-49082). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-23829 python-aiohttp: http request smuggling
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-23829). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-27306 aiohttp: XSS on index pages for static file handling
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-27306). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-52304 aiohttp: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions
    poetry.lock
    A package you depend on has a known security hole (CVE-2024-52304). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69227 aiohttp: aiohttp: Denial of Service via specially crafted POST request
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-69227). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69228 aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-69228). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69229 aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling
    poetry.lock
    A package you depend on has a known security hole (CVE-2025-69229). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22815 aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-22815). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34515 aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-34515). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34516 aiohttp: AIOHTTP: Denial of Service via excessive multipart headers
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-34516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34525 aiohttp: aiohttp: Security bypass via multiple Host headers
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-34525). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34993 aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()
    poetry.lock
    A package you depend on has a known security hole (CVE-2026-34993). Fix: Update that package to its patched version.
… 102 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 143 found · 12 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in resp
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2026-34520). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-348 h11 accepts some malformed Chunked-Encoding bodies
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-183 Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2021-41945). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-137 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2021-25287). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-138 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2021-25288). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-331 Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2021-34552). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-35 An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOT
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2021-25289). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-10 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2022-22817). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-168 Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2022-24303). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-187 virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2024-53899). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-120 aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2023-37276). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-246 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2023-47627). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-247 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protoco
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2023-47641). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-250 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2023-49081). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-251 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even crea
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2023-49082). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-24 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static fi
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2024-23334). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-26 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must tri
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2024-23829). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1098 aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2024-30251). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1100 AIOHTTP vulnerable to denial of service through large payloads
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2025-69228). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1101 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2025-69223). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1102 aiohttp Cross-site Scripting vulnerability on index pages for static file handling
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2024-27306). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1103 aiohttp allows request smuggling due to incorrect parsing of chunk extensions
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2024-52304). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1106 AIOHTTP vulnerable to DoS through chunked messages
    /workdirs/scan-dbfdc0e9-92ed-4a84-8c21-ed853204e1ae/poetry.lock
    A package you depend on has a known security hole (CVE-2025-69229). Fix: Update that package to its patched version.
… 118 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.