Update dependency transformers to v4.53.0 #2
Security Report
You have successfully remediated 46 vulnerabilities, but introduced 24 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2026-0994Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/protobuf-3.20.0.dist-info Dependency Hierarchy: -> ❌ protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library) |
8.6 | Direct protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl | None | |||
CVE-2025-4565Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/protobuf-3.20.0.dist-info Dependency Hierarchy: -> ❌ protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library) |
7.5 | Direct protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl | 4.25.8 | None | ||
CVE-2022-1941Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/protobuf-3.20.0.dist-info Dependency Hierarchy: -> ❌ protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl (Vulnerable Library) |
7.5 | Direct protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl | protobuf - 3.20.2,protobuf - 3.18.3,protobuf - 3.19.5,protobuf - 3.21.6,protobuf - 3.21.6,protobuf - 3.18.3,protobuf - 3.20.2,protobuf - 3.19.5 | None | ||
CVE-2023-6572Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/gradio-3.41.2.dist-info Dependency Hierarchy: -> ❌ gradio-3.41.2-py3-none-any.whl (Vulnerable Library) |
8.1 | Direct gradio-3.41.2-py3-none-any.whl |
gradio-3.41.2-py3-none-any.whl | None | |||
CVE-2021-20276Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info Dependency Hierarchy: -> clean_fid-0.1.35-py3-none-any.whl (Root Library) -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl |
clean_fid-0.1.35-py3-none-any.whl | Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix |
None | ||
CVE-2021-20276Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info Dependency Hierarchy: -> gradio-3.41.2-py3-none-any.whl (Root Library) -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl |
gradio-3.41.2-py3-none-any.whl | Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix |
None | ||
CVE-2021-20276Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info Dependency Hierarchy: -> facexlib-0.3.0-py3-none-any.whl (Root Library) -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl |
facexlib-0.3.0-py3-none-any.whl | Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix |
None | ||
CVE-2021-20276Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/pillow-10.4.0.dist-info Dependency Hierarchy: -> scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library) -> ❌ pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Transitive pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl |
scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Transitive Pillow - no_fix,ch.qos.logback:logback-core - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> accelerate-1.10.1-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
accelerate-1.10.1-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> transformers-4.53.0-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
transformers-4.53.0-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> clean_fid-0.1.35-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
clean_fid-0.1.35-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> torchsde-0.2.6-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
torchsde-0.2.6-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> gradio-3.41.2-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
gradio-3.41.2-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> facexlib-0.3.0-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
facexlib-0.3.0-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41496Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> pytorch_lightning-2.6.0-py3-none-any.whl (Root Library) -> torchmetrics-1.8.2-py3-none-any.whl -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
pytorch_lightning-2.6.0-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> accelerate-1.10.1-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
accelerate-1.10.1-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> transformers-4.53.0-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
transformers-4.53.0-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> clean_fid-0.1.35-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
clean_fid-0.1.35-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> torchsde-0.2.6-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
torchsde-0.2.6-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> gradio-3.41.2-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
gradio-3.41.2-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> facexlib-0.3.0-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
facexlib-0.3.0-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
scikit_image-0.24.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None | ||
CVE-2021-41495Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260225224643_KLMUJE/python_OYKUEO/202602252246431/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> pytorch_lightning-2.6.0-py3-none-any.whl (Root Library) -> torchmetrics-1.8.2-py3-none-any.whl -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | Transitive numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
pytorch_lightning-2.6.0-py3-none-any.whl | Transitive https://github.com/numpy/numpy.git - no_fix |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-21441 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2025-47273 | setuptools-68.0.0-py3-none-any.whl |
| CVE-2025-69226 | aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2022-22815 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-3264 | transformers-4.30.2-py3-none-any.whl |
| CVE-2024-47081 | requests-2.31.0-py3-none-any.whl |
| CVE-2025-54121 | starlette-0.27.0-py3-none-any.whl |
| CVE-2025-3263 | transformers-4.30.2-py3-none-any.whl |
| CVE-2026-0994 | protobuf-3.20.0-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
| CVE-2025-69225 | aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-11392 | transformers-4.30.2-py3-none-any.whl |
| CVE-2021-41496 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2024-48063 | torch-1.13.1-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-1260 | sentencepiece-0.2.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2022-45199 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-4565 | protobuf-3.20.0-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
| CVE-2023-4863 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-50182 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2025-1194 | transformers-4.30.2-py3-none-any.whl |
| CVE-2021-20276 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-24762 | fastapi-0.103.2-py3-none-any.whl |
| CVE-2022-22817 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2026-24049 | wheel-0.42.0-py3-none-any.whl |
| CVE-2025-62727 | starlette-0.27.0-py3-none-any.whl |
| CVE-2025-66471 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2025-6921 | transformers-4.30.2-py3-none-any.whl |
| CVE-2021-41495 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2024-5569 | zipp-3.15.0-py3-none-any.whl |
| CVE-2024-8019 | pytorch_lightning-1.9.5-py3-none-any.whl |
| CVE-2025-69223 | aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2023-50447 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2023-25399 | scipy-1.7.3-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2023-29824 | scipy-1.7.3-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2022-1941 | protobuf-3.20.0-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.whl |
| CVE-2024-12720 | transformers-4.30.2-py3-none-any.whl |
| CVE-2024-11394 | transformers-4.30.2-py3-none-any.whl |
| CVE-2022-45198 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-28219 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-3730 | torch-1.13.1-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2022-22816 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2022-24303 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| WS-2022-0097 | Pillow-8.4.0-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-53643 | aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-69229 | aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-50181 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2024-11393 | transformers-4.30.2-py3-none-any.whl |
Base branch total remaining vulnerabilities: 46
Base branch commit: 2d3a584d65ec03c086b8d9cead8e576023e13380
Total libraries scanned: 127
Scan token: 9333499c2fde49ae9507d77b50708b10