🧬 Known OSS vulnerabilities — OSV-Scannerⓘ4 found · 1 serious
Your dependencies cross-checked against the OSV vulnerability database.
SeriousPYSEC-2023-238 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parque
A package you depend on has a known security hole (CVE-2023-47248). Fix: Update that package to its patched version.
Worth fixingPYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
A package you depend on has a known security hole (CVE-2026-33310). Fix: Update that package to its patched version.
FYIPYSEC-2024-161 Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it
reads Arro
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.