Your dependencies cross-checked against the OSV vulnerability database.
-
Worth fixing PYSEC-2024-36 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the out
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2024-0690). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1121 ansible-core Incorrect Authorization vulnerability
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2024-9902). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1122 Ansible template injection vulnerability
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2023-5764). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1123 Ansible-Core vulnerable to content protections bypass
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2024-11079). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1124 Ansible vulnerable to Insertion of Sensitive Information into Log File
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2024-8775). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1125 Ansible may expose private key
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2023-4237). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3458 ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2026-11332). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1123 Ansible-Core vulnerable to content protections bypass
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2024-11079). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1124 Ansible vulnerable to Insertion of Sensitive Information into Log File
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2024-8775). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3458 ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2026-11332). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3458 ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2026-11332). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3552 cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2026-69247). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3553 python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2026-69249). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3554 python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2026-69248). Fix: Update that package to its patched version.
-
Worth fixing GHSA-537c-gmf6-5ccf Vulnerable OpenSSL included in cryptography wheels
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1845 pytest has vulnerable tmpdir handling
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2025-71176). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1845 pytest has vulnerable tmpdir handling
/workdirs/scan-bceec4c7-c539-4056-aa80-9fdbee245b9a/uv.lock
A package you depend on has a known security hole (CVE-2025-71176). Fix: Update that package to its patched version.