Conversation
Spectra Assure Community Scan: ❌ FAILScanned: ❌ Rejected packages📦
|
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2024-8020 | 🟠 7.50 | PyTorch Lightning is vulnerable to a denial of service via unexpected POST requests to the /api/v1/state endpoint. |
⚡ exploit |
Policy violations: ❌ 2 failed ·
| Policy | Description | Count |
|---|---|---|
| SQ30110 | ❌ Detected presence of malicious files through file reputation or third-party scanners. | 1 |
| SQ30109 | ❌ Detected presence of malicious files through analyst-vetted file reputation. | 1 |
| SQ31102 | † overridden from FAIL by rl-protect |
1 |
📦 pkg:pypi/pillow@8.0.0 — REJECT (2 of 3)
📅 Released 5 years ago
Caution
Assessment
❌ Vulnerabilities: 1 patch mandated vulnerabilities
Vulnerabilities: 🔴 5 critical · 🟠 24 high · 🟡 16 medium
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2022-37434 | 🔴 9.80 | zlib has a heap-based buffer over-read or buffer overflow in inflate via a large gzip header extra field. | ⚡ exploit |
| CVE-2023-50447 | 🔴 9.30 | Pillow allows arbitrary code execution via the environment parameter in PIL.ImageMath.eval. | ⚡ exploit |
| CVE-2023-4863 | 🟠 8.80 | Google Chrome's libwebp is vulnerable to a heap buffer overflow, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page. | ⚡ exploit 📋 mandate ☠️ malware |
| CVE-2022-3970 | 🟠 8.80 | LibTIFF's TIFFReadRGBATileExt function is vulnerable to integer overflow, allowing remote exploitation. | ⚡ exploit |
| CVE-2021-23437 | 🟠 8.70 | Pillow is vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. | ⚡ exploit |
and 40 more vulnerabilities — see full report →
Policy violations: ❌ 4 failed
| Policy | Description | Count |
|---|---|---|
| SQ31104 | ❌ Detected presence of critical severity vulnerabilities. | 2 |
| SQ31102 | ❌ Detected presence of severe vulnerabilities with active exploitation. | 2 |
| SQ31103 | ❌ Detected presence of malware-exploited vulnerabilities. | 1 |
| SQ31101 | ❌ Detected presence of patch mandated vulnerabilities. | 1 |
📦 pkg:pypi/cryptography@3.0 — REJECT (3 of 3)
📅 Released 5 years ago
Warning
Assessment
Vulnerabilities: 🔴 2 critical · 🟠 12 high · 🟡 15 medium
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2024-5535 | 🔴 9.10 | OpenSSL's SSL_select_next_proto function may cause a crash or memory contents to be sent to the peer when called with an empty supported client protocols buffer. | ⚡ exploit |
| CVE-2022-0778 | 🟠 7.50 | OpenSSL's BN_mod_sqrt function contains a bug that can cause an infinite loop when parsing certificates with invalid explicit curve parameters, leading to a denial of service attack. | ⚡ exploit |
| CVE-2023-23931 | 🟡 6.90 | Cryptography's Cipher.update_into function allows mutation of immutable objects, violating Python rules. | ⚡ exploit |
| CVE-2021-3449 | 🟡 5.90 | OpenSSL TLS server may crash due to a NULL pointer dereference when handling a maliciously crafted renegotiation ClientHello message. | ⚡ exploit |
| CVE-2021-3711 | 🔴 9.80 | OpenSSL's EVP_PKEY_decrypt function is vulnerable to a buffer overflow when decrypting SM2 encrypted data, potentially allowing an attacker to alter application behavior or cause a crash. |
and 24 more vulnerabilities — see full report →
Policy violations: ❌ 1 failed ·
| Policy | Description | Count |
|---|---|---|
| SQ31104 | ❌ Detected presence of critical severity vulnerabilities. | 1 |
| SQ31102 | † overridden from FAIL by rl-protect |
1 |
Spectra Assure Community Scan: ❌ FAILScanned: ❌ Rejected packages📦
|
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2021-4229 | 🟠 8.80 | ua-parser-js contains a backdoor in its crypto mining component, allowing for potential malicious activity. |
📦 pkg:npm/express@4.18.2 — REJECT (4 of 8)
📅 Released 3 years ago
⚖️ Permissive (MIT)
Caution
Assessment
❌ Vulnerabilities: 1 severe vulnerabilities exploited
Vulnerabilities: 🟠 3 high · 🟡 4 medium · 🔵 3 low
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2024-45590 | 🟠 8.70 | body-parser is vulnerable to denial of service when url encoding is enabled, allowing a malicious actor to flood the server with a large number of requests. | ⚡ exploit |
| CVE-2025-15284 | 🟡 6.30 | qs is vulnerable to a denial-of-service attack via memory exhaustion due to improper input validation in its bracket notation. | ⚡ exploit |
| CVE-2026-2391 | 🟡 6.30 | qs is vulnerable to Denial of Service (DoS) via memory exhaustion due to a bypass of the array limit enforcement when the comma option is enabled. |
⚡ exploit |
| CVE-2024-45296 | 🟠 7.70 | path-to-regexp is vulnerable to a Regular Expression Denial of Service (ReDoS) due to inefficient regular expression patterns. | |
| CVE-2024-52798 | 🟠 7.70 | path-to-regexp is vulnerable to a regular expression denial of service (ReDoS) due to incomplete fix for CVE-2024-45296. |
and 5 more vulnerabilities — see full report →
📦 pkg:npm/lodash@4.17.20 — REJECT (5 of 8)
📅 Released 5 years ago
⚖️ Permissive (MIT)
Caution
Assessment
❌ Vulnerabilities: 1 severe vulnerabilities exploited
Vulnerabilities: 🟠 1 high · 🟡 2 medium
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2021-23337 | 🟠 7.20 | Lodash is vulnerable to Command Injection via the template function. | ⚡ exploit |
| CVE-2020-28500 | 🟡 5.30 | Lodash is vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. | ⚡ exploit |
| CVE-2025-13465 | 🟡 6.90 | Lodash is vulnerable to prototype pollution in the _.unset and _.omit functions. |
Important
3 more rejected packages
📦 pkg:npm/moment@2.29.1 — ❌ Vulnerabilities: 2 severe vulnerabilities exploited
📦 pkg:npm/vue@0.8.6 — ❌ Repository: Caution: Package removed!
📦 pkg:npm/body-parser@1.20.1 — ❌ Vulnerabilities: 1 severe vulnerabilities exploited
🔗 express@4.18.2 → body-parser@1.20.1
⚠️ Scan Warnings
Packages with issues that did not meet the rejection threshold.
📦 pkg:npm/path-to-regexp@0.1.7 — WARN (1 of 6)
🔗 express@4.18.2 → path-to-regexp@0.1.7
📅 Released 10 years ago
⚖️ Permissive (MIT)
Warning
Assessment
Vulnerabilities: 🟠 3 high
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2024-45296 | 🟠 7.70 | path-to-regexp is vulnerable to a Regular Expression Denial of Service (ReDoS) due to inefficient regular expression patterns. | |
| CVE-2024-52798 | 🟠 7.70 | path-to-regexp is vulnerable to a regular expression denial of service (ReDoS) due to incomplete fix for CVE-2024-45296. | |
| CVE-2026-4867 | 🟠 7.50 | path-to-regexp is vulnerable to Regular Expression Denial of Service via multiple route parameters, allowing for catastrophic backtracking. |
📦 pkg:npm/cookie@0.5.0 — WARN (2 of 6)
🔗 express@4.18.2 → cookie@0.5.0
📅 Released 4 years ago
⚖️ Permissive (MIT)
Warning
Assessment
Vulnerabilities: 🟡 1 medium
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2024-47764 | 🟡 6.90 | Cookie, an HTTP cookie parser and serializer for HTTP servers, is vulnerable to unexpected cookie values due to inadequate validation of name, path, and domain fields. |
📦 pkg:npm/qs@6.11.0 — WARN (3 of 6)
🔗 express@4.18.2 → qs@6.11.0
📅 Released 3 years ago
⚖️ Permissive (BSD-3-Clause)
Warning
Assessment
Vulnerabilities: 🟡 2 medium
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2025-15284 | 🟡 6.30 | qs is vulnerable to a denial-of-service attack via memory exhaustion due to improper input validation in its bracket notation. | ⚡ exploit |
| CVE-2026-2391 | 🟡 6.30 | qs is vulnerable to Denial of Service (DoS) via memory exhaustion due to a bypass of the array limit enforcement when the comma option is enabled. |
⚡ exploit |
📦 pkg:npm/node-fetch@2.6.1 — WARN (4 of 6)
📅 Released 5 years ago
⚖️ Permissive (MIT)
Warning
Assessment
Vulnerabilities: 🟡 1 medium
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2022-0235 | 🟡 6.10 | node-fetch exposes sensitive information to an unauthorized actor when forwarding secure headers during redirects. | ⚡ exploit |
📦 pkg:npm/send@0.18.0 — WARN (5 of 6)
🔗 express@4.18.2 → send@0.18.0
📅 Released 4 years ago
⚖️ Permissive (MIT)
Warning
Assessment
Vulnerabilities: 🔵 1 low
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2024-43799 | 🔵 2.30 | Send library is vulnerable to code execution due to passing untrusted user input to SendStream.redirect. |
Important
1 more warning
📦 pkg:npm/serve-static@1.15.0 —
🔗 express@4.18.2 → serve-static@1.15.0
Spectra Assure Community Scan: ❌ FAILScanned:
|
| Assessment | Result |
|---|---|
| Malware | ✅ No evidence of malware inclusion |
| Tampering | |
| Vulnerabilities | ✅ No known vulnerabilities detected |
| Secrets | ✅ No sensitive information found |
| Hardening | ✅ No application hardening issues |
| Licenses | ✅ No license compliance issues |
No description provided.