{"source":"ghsa-pip","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/ghsa-pip/changes.","question":"Which new security vulnerabilities / CVEs affecting PyPI packages were published since T, and how severe (CVSS) are they?","sample":[{"source":"ghsa-pip","entityId":"ghsa:GHSA-6c4r-fmh3-7rh8","type":"advisory","title":"GHSA-6c4r-fmh3-7rh8 / CVE-2026-34760: vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models","summary":"MEDIUM severity. Affected: vllm.","significance":6,"detectedAt":"2026-07-18T23:42:08.810Z","effectiveDate":"2026-07-17T16:52:53Z","sourceUrl":"https://github.com/advisories/GHSA-6c4r-fmh3-7rh8","detail":{"severity":"medium","cve":"CVE-2026-34760","packages":"vllm","cvss":5.9}},{"source":"ghsa-pip","entityId":"ghsa:GHSA-8wr5-jm2h-8r4f","type":"advisory","title":"GHSA-8wr5-jm2h-8r4f / CVE-2026-54234: vLLM has Remote DoS via Invalid Recovered Token Reinjection","summary":"HIGH severity. Affected: vllm.","significance":8,"detectedAt":"2026-07-18T23:42:08.810Z","effectiveDate":"2026-07-17T17:08:03Z","sourceUrl":"https://github.com/advisories/GHSA-8wr5-jm2h-8r4f","detail":{"severity":"high","cve":"CVE-2026-54234","packages":"vllm","cvss":7.5}},{"source":"ghsa-pip","entityId":"ghsa:GHSA-rwxx-mrjm-wc2m","type":"advisory","title":"GHSA-rwxx-mrjm-wc2m / CVE-2026-55574: vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends","summary":"HIGH severity. Affected: vllm.","significance":8,"detectedAt":"2026-07-18T23:42:08.810Z","effectiveDate":"2026-07-17T17:10:37Z","sourceUrl":"https://github.com/advisories/GHSA-rwxx-mrjm-wc2m","detail":{"severity":"high","cve":"CVE-2026-55574","packages":"vllm","cvss":7.5}},{"source":"ghsa-pip","entityId":"ghsa:GHSA-v82g-2437-67m2","type":"advisory","title":"GHSA-v82g-2437-67m2 / CVE-2026-55646: vLLM: Speech-to-text upload size limit is enforced after full UploadFile read","summary":"MEDIUM severity. Affected: vllm.","significance":7,"detectedAt":"2026-07-18T23:42:08.810Z","effectiveDate":"2026-07-17T17:16:17Z","sourceUrl":"https://github.com/advisories/GHSA-v82g-2437-67m2","detail":{"severity":"medium","cve":"CVE-2026-55646","packages":"vllm","cvss":6.5}},{"source":"ghsa-pip","entityId":"ghsa:GHSA-4r4f-gg25-rmg5","type":"advisory","title":"GHSA-4r4f-gg25-rmg5 / CVE-2026-54503: plone.app.textfield: Stored XSS by spoofing mime type","summary":"MEDIUM severity. Affected: plone.app.textfield, plone.app.textfield, plone.app.textfield.","significance":4,"detectedAt":"2026-07-18T23:42:08.810Z","effectiveDate":"2026-07-17T18:35:57Z","sourceUrl":"https://github.com/advisories/GHSA-4r4f-gg25-rmg5","detail":{"severity":"medium","cve":"CVE-2026-54503","packages":"plone.app.textfield, plone.app.textfield, plone.app.textfield","cvss":4.3}}]}