Skip to content

Update dependency transformers to v4.53.0

18fed7d
Select commit
Loading
Failed to load commit list.
Open

Update dependency transformers to v4.53.0 #2

Update dependency transformers to v4.53.0
18fed7d
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 25, 2026 in 54m 41s

Security Report

You have successfully remediated 46 vulnerabilities, but introduced 24 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-0994

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/protobuf-3.20.0.dist-info

Dependency Hierarchy:

-> ❌ protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library)

High 8.6 Direct protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl None

Unreachable

CVE-2025-4565

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/protobuf-3.20.0.dist-info

Dependency Hierarchy:

-> ❌ protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library)

High 7.5 Direct protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl 4.25.8 None

Unreachable

CVE-2022-1941

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/protobuf-3.20.0.dist-info

Dependency Hierarchy:

-> ❌ protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library)

High 7.5 Direct protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl protobuf - 3.20.2,protobuf - 3.18.3,protobuf - 3.19.5,protobuf - 3.21.6,protobuf - 3.21.6,protobuf - 3.18.3,protobuf - 3.20.2,protobuf - 3.19.5 None

Unreachable

CVE-2023-6572

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/gradio-3.41.2.dist-info

Dependency Hierarchy:

-> ❌ gradio-3.41.2-py3-none-any.whl (Vulnerable Library)

High 8.1 Direct gradio-3.41.2-py3-none-any.whl gradio-3.41.2-py3-none-any.whl None
CVE-2021-20276

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info

Dependency Hierarchy:

-> clean_fid-0.1.35-py3-none-any.whl (Root Library)

   -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl clean_fid-0.1.35-py3-none-any.whl Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix None
CVE-2021-20276

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info

Dependency Hierarchy:

-> gradio-3.41.2-py3-none-any.whl (Root Library)

   -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl gradio-3.41.2-py3-none-any.whl Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix None
CVE-2021-20276

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info

Dependency Hierarchy:

-> facexlib-0.3.0-py3-none-any.whl (Root Library)

   -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl facexlib-0.3.0-py3-none-any.whl Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix None
CVE-2021-20276

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info

Dependency Hierarchy:

-> scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library)

   -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> accelerate-1.10.1-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl accelerate-1.10.1-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> transformers-4.53.0-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl transformers-4.53.0-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> clean_fid-0.1.35-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl clean_fid-0.1.35-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> torchsde-0.2.6-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl torchsde-0.2.6-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> gradio-3.41.2-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl gradio-3.41.2-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> facexlib-0.3.0-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl facexlib-0.3.0-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41496

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> pytorch_lightning-2.6.0-py3-none-any.whl (Root Library)

   -> torchmetrics-1.8.2-py3-none-any.whl

     -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.5 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl pytorch_lightning-2.6.0-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> accelerate-1.10.1-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl accelerate-1.10.1-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> transformers-4.53.0-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl transformers-4.53.0-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> clean_fid-0.1.35-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl clean_fid-0.1.35-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> torchsde-0.2.6-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl torchsde-0.2.6-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> gradio-3.41.2-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl gradio-3.41.2-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> facexlib-0.3.0-py3-none-any.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl facexlib-0.3.0-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library)

   -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Transitive https://github.com/numpy/numpy.git - no_fix None
CVE-2021-41495

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info

Dependency Hierarchy:

-> pytorch_lightning-2.6.0-py3-none-any.whl (Root Library)

   -> torchmetrics-1.8.2-py3-none-any.whl

     -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl pytorch_lightning-2.6.0-py3-none-any.whl Transitive https://github.com/numpy/numpy.git - no_fix None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-21441 urllib3-2.0.7-py3-none-any.whl
CVE-2025-47273 setuptools-68.0.0-py3-none-any.whl
CVE-2025-69226 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2022-22815 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-3264 transformers-4.30.2-py3-none-any.whl
CVE-2024-47081 requests-2.31.0-py3-none-any.whl
CVE-2025-54121 starlette-0.27.0-py3-none-any.whl
CVE-2025-3263 transformers-4.30.2-py3-none-any.whl
CVE-2026-0994 protobuf-3.20.0-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl
CVE-2025-69225 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2024-11392 transformers-4.30.2-py3-none-any.whl
CVE-2021-41496 numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
CVE-2024-48063 torch-1.13.1-cp37-cp37m-manylinux1_x86_64.whl
CVE-2026-1260 sentencepiece-0.2.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2022-45199 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-4565 protobuf-3.20.0-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl
CVE-2023-4863 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-50182 urllib3-2.0.7-py3-none-any.whl
CVE-2025-1194 transformers-4.30.2-py3-none-any.whl
CVE-2021-20276 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2024-24762 fastapi-0.103.2-py3-none-any.whl
CVE-2022-22817 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2026-24049 wheel-0.42.0-py3-none-any.whl
CVE-2025-62727 starlette-0.27.0-py3-none-any.whl
CVE-2025-66471 urllib3-2.0.7-py3-none-any.whl
CVE-2025-6921 transformers-4.30.2-py3-none-any.whl
CVE-2021-41495 numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
CVE-2024-5569 zipp-3.15.0-py3-none-any.whl
CVE-2024-8019 pytorch_lightning-1.9.5-py3-none-any.whl
CVE-2025-69223 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2023-50447 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2023-25399 scipy-1.7.3-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
CVE-2023-29824 scipy-1.7.3-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
CVE-2022-1941 protobuf-3.20.0-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl
CVE-2024-12720 transformers-4.30.2-py3-none-any.whl
CVE-2024-11394 transformers-4.30.2-py3-none-any.whl
CVE-2022-45198 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2024-28219 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-3730 torch-1.13.1-cp37-cp37m-manylinux1_x86_64.whl
CVE-2022-22816 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2022-24303 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
WS-2022-0097 Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-53643 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-69229 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-50181 urllib3-2.0.7-py3-none-any.whl
CVE-2024-11393 transformers-4.30.2-py3-none-any.whl

Base branch total remaining vulnerabilities: 46
Base branch commit: 2d3a584d65ec03c086b8d9cead8e576023e13380


Total libraries scanned: 127

Scan token: 9333499c2fde49ae9507d77b50708b10