gitsafehub
github.com/wietze/bsides-ldn-2019 ↗

wietze/bsides-ldn-2019

scanned 2026-08-13 · git ea26c49
3 of 6 checks flagged a security issue
🟡 Worth a look
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets6Vulnerable dependencies24Known OSS vulnerabilities27Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 6 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    README.original.md:79
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    README.md:87
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    conf/config.ini:4
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    conf/config.ini:5
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/test_adversary_api.py:24
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    tests/test_adversary_api.py:25
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 24 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2023-37920 python-certifi: Removal of e-Tugra root certificate
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-37920). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-23491 python-certifi: untrusted root certificates
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-23491). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-3651 python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-3651). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputs
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-5629 python-pymongo: Out-of-bounds read in bson module
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-5629). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-32681 python-requests: Unintended leak of Proxy-Authorization header
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-32681). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-35195 requests: subsequent requests to the same host ignore cert verification
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-35195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-47081 requests: Requests vulnerable to .netrc credentials leak via malicious URLs
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creation
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-31116 python-ujson: improper decoding of escaped surrogate characters may lead to string corruption, key confusion or value overwriting
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-31116). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44660 python-ujson: UltraJSON: Memory leak leading to Denial of Service
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44660). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-45958 UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-45958). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-31117 python-ujson: Potential double free of buffer during string decoding
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-31117). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54911 UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-54911). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-43804 python-urllib3: Cookie request header isn't stripped during cross-origin redirects
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-43804). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66418 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-66418). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed data
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-66471). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-21441 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-21441). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44431). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
    requirements.txt
    A package you depend on has a known security hole (CVE-2019-11236). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-26137). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-45803 urllib3: Request body not stripped after redirect from 303 status changes request method to GET
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-45803). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-37891 urllib3: proxy-authorization request header is not stripped during cross-origin redirects
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-37891). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-50181 urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-50181). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 27 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing PYSEC-2022-42986 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2022-23491). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-135 Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed pur
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2023-37920). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-230 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2024-39689). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-60 A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings,
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2024-3651). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1826 PyMongo Out-of-bounds Read in the bson module
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2024-5629). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1845 pytest has vulnerable tmpdir handling
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2025-71176). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `re
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2023-32681). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLs
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=False
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2024-35195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system te
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1056 Potential double free of buffer during string decoding
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2022-31117). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1057 Incorrect handling of invalid surrogate pair characters
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2022-31116). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2293 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exceptio
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44660). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2294 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2026-54911). Fix: Update that package to its patched version.
  • Worth fixing GHSA-fh56-85cw-5pq6 UltraJSON vulnerable to Out-of-bounds Write
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2021-45958). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-132 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2019-11236). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-148 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: thi
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2020-26137). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-192 urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of t
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2023-43804). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-212 urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had i
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2023-45803). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-141 urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fal
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44431). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1994 urllib3 streaming API improperly handles highly compressed data
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66471). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1995 urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2024-37891). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1996 Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2026-21441). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1998 urllib3 allows an unbounded number of links in the decompression chain
    /workdirs/scan-67c512ae-95dc-4068-a992-759f1b2048d4/requirements.txt
    A package you depend on has a known security hole (CVE-2025-66418). Fix: Update that package to its patched version.
… 2 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.