0 critical · 0 high · 5 medium · 1 low · 6 total (deduped by CVE) · 0 reviewed not-affected
Image datagrok/api-tests-apitests-docker-test1:1.10.3 · digest sha256:220007dfc6938fbc1225a51d77a84302394469014c253952d9d7d9a7558baa17
OpenVEX status affected (an upstream fix exists — the action is to
apply it) or under_investigation (no upstream fix is available yet; a version match
alone does not establish exploitability).
| Vulnerability | Status | Severity | Package | Installed | Fixed in | CVSS | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-8869 | affected | MEDIUM | pip | 25.0.1 | 25.3 | CVE-2025-8869 | |
| CVE-2026-13346 | affected | MEDIUM | pip | 25.0.1 | 26.2 | 6.5 | CVE-2026-13346 |
| CVE-2026-3219 | affected | MEDIUM | pip | 25.0.1 | 26.1 | CVE-2026-3219 | |
| CVE-2026-6357 | affected | MEDIUM | pip | 25.0.1 | 26.1 | CVE-2026-6357 | |
| CVE-2026-8643 | affected | MEDIUM | pip | 25.0.1 | 26.1.2 | 5.5 | CVE-2026-8643 |
| CVE-2026-1703 | affected | LOW | pip | 25.0.1 | 26 | CVE-2026-1703 |