π [IBM OSPO Security Notification] β IBM/torchlogic
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @KyleErwin @estebandito22
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Deadline |
Fix PR |
| π΄ critical |
CVE-2023-50447 |
Pillow |
< 10.2.0 |
10.2.0 |
2026-09-25 |
β |
| π΄ critical |
CVE-2025-32434 |
torch |
< 2.6.0 |
2.6.0 |
2026-09-25 |
β |
| π high |
CVE-2023-52323 |
pycryptodome |
< 3.19.1 |
3.19.1 |
2026-10-18 |
β |
| π high |
CVE-2024-28219 |
pillow |
< 10.3.0 |
10.3.0 |
2026-10-18 |
β |
| π high |
CVE-2024-31583 |
torch |
< 2.2.0 |
2.2.0 |
2026-10-18 |
β |
| π high |
CVE-2024-31580 |
torch |
< 2.2.0 |
2.2.0 |
2026-10-18 |
β |
| π high |
CVE-2024-6345 |
setuptools |
< 70.0.0 |
70.0.0 |
2026-10-18 |
β |
| π high |
CVE-2025-47273 |
setuptools |
< 78.1.1 |
78.1.1 |
2026-10-18 |
β |
| π high |
CVE-2025-66418 |
urllib3 |
>= 1.24, < 2.6.0 |
2.6.0 |
2026-10-18 |
β |
| π high |
CVE-2025-66471 |
urllib3 |
>= 1.0, < 2.6.0 |
2.6.0 |
2026-10-18 |
β |
| π high |
CVE-2026-21441 |
urllib3 |
>= 1.22, < 2.6.3 |
2.6.3 |
2026-10-18 |
β |
| π high |
CVE-2026-25990 |
pillow |
>= 10.3.0, < 12.1.1 |
12.1.1 |
2026-10-18 |
β |
| π high |
CVE-2026-40192 |
pillow |
>= 10.3.0, < 12.2.0 |
12.2.0 |
2026-10-18 |
β |
| π high |
CVE-2026-41205 |
Mako |
<= 1.3.10 |
1.3.11 |
2026-10-18 |
β |
| π high |
CVE-2026-42311 |
pillow |
>= 10.3.0, < 12.2.0 |
12.2.0 |
2026-10-18 |
β |
| π high |
CVE-2026-44307 |
Mako |
<= 1.3.11 |
1.3.12 |
2026-10-18 |
β |
| π high |
CVE-2026-44431 |
urllib3 |
>= 1.23, < 2.7.0 |
2.7.0 |
2026-10-18 |
β |
| π high |
CVE-2026-54060 |
pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-54058 |
pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-54059 |
pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-55380 |
pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-55379 |
pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-59197 |
Pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-59199 |
Pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-59205 |
pillow |
< 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-59200 |
Pillow |
>= 5.1.0, < 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π high |
CVE-2026-59204 |
pillow |
>= 8.2.0, < 12.3.0 |
12.3.0 |
2026-10-13 |
β |
| π‘ medium |
CVE-2024-22195 |
jinja2 |
< 3.1.3 |
3.1.3 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-3651 |
idna |
< 3.7 |
3.7 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-34064 |
Jinja2 |
< 3.1.4 |
3.1.4 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-35195 |
requests |
< 2.32.0 |
2.32.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-37891 |
urllib3 |
>= 2.0.0, < 2.2.2 |
2.2.2 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-5206 |
scikit-learn |
< 1.5.0 |
1.5.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-5569 |
zipp |
< 3.19.1 |
3.19.1 |
2026-12-17 |
β |
| π‘ medium |
GHSA-8qw9-gf7w-42x5 |
streamlit |
>= 0.63.0, < 1.30.0 |
1.30.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-42474 |
streamlit |
< 1.37.0 |
1.37.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-56326 |
jinja2 |
<= 3.1.4 |
3.1.5 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-56201 |
jinja2 |
>= 3.0.0, <= 3.1.4 |
3.1.5 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-27516 |
Jinja2 |
<= 3.1.5 |
3.1.6 |
2026-12-17 |
β |
| π‘ medium |
CVE-2024-47081 |
requests |
< 2.32.4 |
2.32.4 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-3730 |
torch |
<= 2.7.1 |
2.8.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-50181 |
urllib3 |
< 2.5.0 |
2.5.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-50182 |
urllib3 |
>= 2.2.0, < 2.5.0 |
2.5.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-66034 |
fonttools |
>= 4.33.0, < 4.60.2 |
4.60.2 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-68146 |
filelock |
< 3.20.1 |
3.20.1 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-22701 |
filelock |
< 3.20.3 |
3.20.3 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-33682 |
Streamlit |
< 1.54.0 |
1.54.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-25645 |
requests |
< 2.33.0 |
2.33.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-71176 |
pytest |
< 9.0.3 |
9.0.3 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-42308 |
pillow |
< 12.2.0 |
12.2.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-42310 |
pillow |
>= 4.2.0, < 12.2.0 |
12.2.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-45409 |
idna |
< 3.15 |
3.15 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-2998 |
torch |
<= 2.6.0 |
β |
2026-12-12 |
β |
| π‘ medium |
CVE-2025-2999 |
torch |
< 2.9.1 |
2.9.1 |
2026-12-12 |
β |
| π‘ medium |
CVE-2026-55798 |
Pillow |
< 12.3.0 |
12.3.0 |
2026-12-12 |
β |
| π‘ medium |
CVE-2026-59198 |
Pillow |
>= 5.2.0, < 12.3.0 |
12.3.0 |
2026-12-12 |
β |
| π‘ medium |
CVE-2026-59890 |
setuptools |
< 83.0.0 |
83.0.0 |
2026-12-12 |
β |
| π΅ low |
CVE-2024-34062 |
tqdm |
>= 4.4.0, < 4.66.3 |
4.66.3 |
β |
β |
| π΅ low |
CVE-2024-39689 |
certifi |
>= 2021.5.30, < 2024.7.4 |
2024.7.4 |
β |
β |
| π΅ low |
CVE-2025-2953 |
torch |
< 2.7.1-rc1 |
2.7.1-rc1 |
β |
β |
| π΅ low |
CVE-2025-2148 |
torch |
<= 2.6.0 |
β |
β |
β |
| π΅ low |
CVE-2025-2149 |
torch |
<= 2.6.0 |
β |
β |
β |
| π΅ low |
CVE-2025-3001 |
torch |
< 2.10.0 |
2.10.0 |
β |
β |
| π΅ low |
CVE-2026-10804 |
streamlit |
< 1.53.1 |
1.53.1 |
β |
β |
| π΅ low |
CVE-2025-3000 |
torch |
<= 2.12.1 |
2.13.0 |
β |
β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π [IBM OSPO Security Notification] β IBM/torchlogic
Attention: @KyleErwin @estebandito22
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.