Skip to content

DO NOT MERGE: Test adding requirements.txt with known vulnerabilities#227

Open
sumau wants to merge 2 commits into
mainfrom
do-not-merge/test-dependency-review-requirements-in
Open

DO NOT MERGE: Test adding requirements.txt with known vulnerabilities#227
sumau wants to merge 2 commits into
mainfrom
do-not-merge/test-dependency-review-requirements-in

Conversation

@sumau

@sumau sumau commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Test Datadog and GitHub Dependency review picks up vulnerabilities when adding requirements.txt with known vulnerabilities

@sumau
sumau requested a review from a team as a code owner July 16, 2026 10:44
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ❌ 6 vulnerable package(s)
See the Details below.

Vulnerabilities

requirements.txt

NameVersionVulnerabilitySeverity
django1.5.10Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.critical
SQL injection in Djangocritical
Django Potential account hijack via password reset formcritical
Django CSRF Protection Bypasshigh
Django vulnerable to Reflected File Download attackhigh
Django Denial-of-service by filling session storehigh
Django Vulnerable to HTTP Response Splitting Attackhigh
Django is subject to SQL injection through its column aliaseshigh
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windowshigh
Path Traversal in Djangomoderate
Django Cross-site scripting Vulnerabilitymoderate
Django XSS Vulnerabilitymoderate
Django Cross-site Scripting Vulnerabilitymoderate
Django cross-site scripting (XSS) attack via user-supplied redirect URLsmoderate
Django allows enumeration of user e-mail addressesmoderate
Django Improper Output Neutralization for Logs vulnerabilitymoderate
Django User Enumeration Vulnerabilitylow
aiohttp3.7.0AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombhigh
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requestshigh
aiohttp is vulnerable to directory traversalhigh
AIOHTTP vulnerable to DoS when bypassing assertsmoderate
AIOHTTP vulnerable to denial of service through large payloadsmoderate
AIOHTTP vulnerable to DoS through chunked messagesmoderate
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usagemoderate
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windowsmoderate
AIOHTTP has a Multipart Header Size Bypassmoderate
AIOHTTP accepts duplicate Host headersmoderate
AIOHTTP is Vulnerable to Deserialization of Untrusted Datamoderate
AIOHTTP is vulnerable to cross-origin redirect with per-request cookiesmoderate
aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challengesmoderate
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Linesmoderate
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanupmoderate
aiohttp: HTTP/1 Pipelined Requests Queue Without Limitmoderate
aiohttp: Incomplete websocket frame payloads bypass memory limitsmoderate
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parsermoderate
AIOHTTP has problems in HTTP parser (the python one, not llhttp)moderate
aiohttp has vulnerable dependency that is vulnerable to request smugglingmoderate
aiohttp allows request smuggling due to incorrect parsing of chunk extensionsmoderate
aiohttp Cross-site Scripting vulnerability on index pages for static file handlingmoderate
aiohttp's ClientSession is vulnerable to CRLF injection via methodmoderate
aiohttp's ClientSession is vulnerable to CRLF injection via versionmoderate
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separatorsmoderate
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)low
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connectionslow
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnectlow
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbackslow
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistencelow
aiohttp: CRLF injection in multipart headerslow
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypasslow
AIOHTTP has HTTP response splitting via \r in reason phraselow
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirectlow
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoSlow
AIOHTTP has CRLF injection through multipart part content type header constructionlow
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnectorlow
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sectionslow
AIOHTTP Vulnerable to Cookie Parser Warning Stormlow
AIOHTTP's unicode processing of header values could cause parsing discrepancieslow
AIOHTTP has unicode match groups in regexes for ASCII protocol elementslow
AIOHTTP vulnerable to brute-force leak of internal static file path componentslow
apache-airflow2.6.3Apache Airflow proxy credentials for various providers might leak in task logshigh
Apache Airflow information exposure vulnerabilityhigh
Apache Airflow: Bypass permission verification to read code of other dagshigh
Apache Airflow Vulnerable to Deserialization of Untrusted Datahigh
Apache Airflow: pickle deserialization vulnerability in XComshigh
Apache Airflow denial of service vulnerabilityhigh
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerabilityhigh
Apache Airflow Session Fixation vulnerabilityhigh
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actorhigh
Apache Airflow: Authenticated users can bypass the `is_safe_url` checkhigh
Apache Airflow vulnerable to Execution with Unnecessary Privilegeshigh
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate tablehigh
Apache Airflow has DAG Author Code Execution possibility in airflow-schedulerhigh
Apache Airflow: RCE by race condition in example_xcom daghigh
Apache Airflow error reporting may expose full kwargsmoderate
Apache Airflow exposes sensitive information in its log filesmoderate
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view accessmoderate
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance recordmoderate
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissionsmoderate
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted usersmoderate
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logoutmoderate
Apache Airflow has a Link Following issuemoderate
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actormoderate
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actormoderate
Apache Airflow has an Authorization Bypass Through User-Controlled Keymoderate
Apache Airflow has no certificate validation on SMTP STARTTLS connectionsmoderate
Apache Airflow missing Certificate Validationmoderate
Apache Airflow Incorrect Authorization vulnerabilitymoderate
Apache Airflow vulnerable to sensitive information exposuremoderate
Apache Airflow vulnerable to privilege escalationmoderate
Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGsmoderate
Apache Airflow vulnerable to Exposure of Sensitive Informationmoderate
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notesmoderate
Apache Airflow Improper Access Control vulnerabilitymoderate
Apache Airflow vulnerable to Exposure of Resource to Wrong Spheremoderate
Apache Airflow has a stored cross-site scripting vulnerabilitymoderate
Apache Airflow: DAG Code and Import Error Permissions Ignoredmoderate
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers usersmoderate
Apache Airflow Potential Cross-site Scripting Vulnerabilitymoderate
Apache Airflow Cross-site Scripting Vulnerabilitymoderate
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Usersmoderate
Apache Airflow does not return the "Cache-Control" header for dynamic contentlow
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Datalow
flask2.2.4Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie headerhigh
Flask session does not add `Vary: Cookie` header when accessed in some wayslow
jupyterhub4.0.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossinghigh
JupyterHub has a privilege escalation vulnerability with the `admin:users` scopehigh
JupyterHub has an Open Redirect Vulnerabilitymoderate
torch2.7.1PyTorch Improper Resource Shutdown or Release vulnerabilitymoderate
PyTorch is vulnerable to memory corruption through its unpack_sequence functionmoderate
PyTorch is vulnerable to memory corruption through its torch.jit.script functionlow
PyTorch is vulnerable to memory corruption through its torch.lstm_cell functionlow

OpenSSF Scorecard

PackageVersionScoreDetails
pip/django 1.5.10 UnknownUnknown
pip/aiohttp 3.7.0 🟢 7.1
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 4Found 7/15 approved changesets -- score normalized to 4
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
License🟢 10license file detected
Fuzzing🟢 10project is fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Signed-Releases🟢 64 out of the last 5 releases have a total of 4 signed artifacts.
pip/apache-airflow 2.6.3 UnknownUnknown
pip/flask 2.2.4 UnknownUnknown
pip/jupyterhub 4.0.1 UnknownUnknown
pip/torch 2.7.1 UnknownUnknown

Scanned Files

  • requirements.txt

@github-actions

Copy link
Copy Markdown

Your PR has commits that are missing the Signed-off-by trailer. This is likely due to the pre-commit hook not being configured on your local machine. The usual fix for this issue is to run pre-commit install --install-hooks --overwrite -t commit-msg -t pre-commit, however for more detailed help in setting up the pre-commit hooks, follow the instructions at https://github.com/uktrade/github-standards/blob/main/README.md#usage

@github-actions

Copy link
Copy Markdown

Your PR has commits that are missing the Signed-off-by trailer. This is likely due to the pre-commit hook not being configured on your local machine. The usual fix for this issue is to run pre-commit install --install-hooks --overwrite -t commit-msg -t pre-commit, however for more detailed help in setting up the pre-commit hooks, follow the instructions at https://github.com/uktrade/github-standards/blob/main/README.md#usage

@datadog-uktrade

datadog-uktrade Bot commented Jul 16, 2026

Copy link
Copy Markdown

Library Vulnerabilities  Code Quality  Code Vulnerabilities  IaC  Secrets

🛑 Gate Violations

📚 5 Library vulnerabilities detected

A No new library vulnerabilities gate may be blocking this PR.

Critical: apache-airflow 2.6.3 Component with known vulnerability
Critical: django 1.5.10 Django Potential account hijack via password reset form
High: flask 2.2.4 Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
View all

ℹ️ Info

No other issues found (see more)

🛠️ No new code quality issues
🛡️ No new code vulnerabilities
🧱 No new Infrastructure as Code (IaC) issues
🔑 No new secrets detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 81c2a9a | Docs | Give us feedback!

Comment thread requirements.txt
jupyterhub==4.0.1
torch==2.7.1
flask==2.2.4
apache-airflow==2.6.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚫ Critical: Library Vulnerability

apache-airflow@2.6.3

Suggested change
apache-airflow==2.6.3
apache-airflow==3.3.0

Component with known vulnerability

Helpful? 👍/👎View in Datadog  Leave us feedback  Documentation

Comment thread requirements.txt
@@ -0,0 +1,6 @@
aiohttp==3.7.0
django==1.5.10

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚫ Critical: Library Vulnerability

django@1.5.10

View all suggested fixes
Suggested change
django==1.5.10
django==6.1b1
Suggested change
django==1.5.10
django==4.2.30
Suggested change
django==1.5.10
django==4.2.28

Django Potential account hijack via password reset form

Helpful? 👍/👎View in Datadog  Leave us feedback  Documentation

Comment thread requirements.txt
django==1.5.10
jupyterhub==4.0.1
torch==2.7.1
flask==2.2.4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 High: Library Vulnerability

flask@2.2.4

Suggested change
flask==2.2.4
flask==3.1.3

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

Helpful? 👍/👎View in Datadog  Leave us feedback  Documentation

Comment thread requirements.txt
@@ -0,0 +1,6 @@
aiohttp==3.7.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 High: Library Vulnerability

aiohttp@3.7.0

View all suggested fixes
Suggested change
aiohttp==3.7.0
aiohttp==4.0.0a1
Suggested change
aiohttp==3.7.0
aiohttp==3.14.1

aiohttp is vulnerable to directory traversal

Helpful? 👍/👎View in Datadog  Leave us feedback  Documentation

Comment thread requirements.txt
aiohttp==3.7.0
django==1.5.10
jupyterhub==4.0.1
torch==2.7.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 High: Library Vulnerability

torch@2.7.1

View all suggested fixes
Suggested change
torch==2.7.1
torch==2.13.0
Suggested change
torch==2.7.1
torch==2.12.1

Component with known vulnerability

Helpful? 👍/👎View in Datadog  Leave us feedback  Documentation

@sumau sumau changed the title DO NOT MERGE: Test adding requirements.in with known vulnerabilities DO NOT MERGE: Test adding requirements.txt with known vulnerabilities Jul 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant