{"data":{"slug":"lxf746-any-auto-register","name":"any-auto-register","trust":{"provenance":{"is_fork":false,"github_id":1185330299,"owner_type":"User","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-09-20T04:50:13.059Z","maintenance":{"label":"Active","score":82,"methodology":"github_public_v1","releases_90d":0,"days_since_push":25,"last_release_at":"2026-05-06T08:11:51Z","stars_delta_30d":171,"open_issues_delta_30d":5},"security_summary":{"status":"no_lockfile","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-07-15T10:54:41.265Z","medium_count":0,"scan_profile":"none","critical_count":0}},"findings":[{"id":"GHSA-qw2m-4pqf-rmpp","severity":"high","title":"curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)","package":"curl_cffi@0.6.0","cve":"CVE-2026-33752","location":"https://osv.dev/vulnerability/GHSA-qw2m-4pqf-rmpp","sources":["deps.dev@v1"]},{"id":"GHSA-3c37-wwvx-h642","severity":"high","title":"cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads","package":"cbor2@5.4.0","cve":"CVE-2026-26209","location":"https://osv.dev/vulnerability/GHSA-3c37-wwvx-h642","sources":["deps.dev@v1"]},{"id":"GHSA-9q9c-vjxh-p795","severity":"high","title":"cbor2 C extension decoder flaws can cause denial of service","package":"cbor2@5.4.0","cve":"CVE-2025-64076","location":"https://osv.dev/vulnerability/GHSA-9q9c-vjxh-p795","sources":["deps.dev@v1"]},{"id":"GHSA-q34m-jh98-gwm2","severity":"high","title":"Werkzeug possible resource exhaustion when parsing file data in forms","package":"quart@0.19.0","cve":"CVE-2024-49767","location":"https://osv.dev/vulnerability/GHSA-q34m-jh98-gwm2","sources":["deps.dev@v1"]},{"id":"GHSA-9hjg-9r4m-mvj7","severity":"medium","title":"Requests vulnerable to .netrc credentials leak via malicious URLs","package":"requests@2.31.0","cve":"CVE-2024-47081","location":"https://osv.dev/vulnerability/GHSA-9hjg-9r4m-mvj7","sources":["deps.dev@v1"]},{"id":"GHSA-9wx4-h78v-vm56","severity":"medium","title":"Requests `Session` object does not verify requests after making first request with verify=False","package":"requests@2.31.0","cve":"CVE-2024-35195","location":"https://osv.dev/vulnerability/GHSA-9wx4-h78v-vm56","sources":["deps.dev@v1"]},{"id":"GHSA-gc5v-m9x4-r6x2","severity":"medium","title":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","package":"requests@2.31.0","cve":"CVE-2026-25645","location":"https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2","sources":["deps.dev@v1"]},{"id":"GHSA-mr82-8j83-vxmv","severity":"medium","title":"Pydantic regular expression denial of service","package":"pydantic@2.0.0","cve":"CVE-2024-3772","location":"https://osv.dev/vulnerability/GHSA-mr82-8j83-vxmv","sources":["deps.dev@v1"]},{"id":"GHSA-cw2r-4p82-qv79","severity":"medium","title":"DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value","package":"jwcrypto@1.5.0","cve":"CVE-2023-6681","location":"https://osv.dev/vulnerability/GHSA-cw2r-4p82-qv79","sources":["deps.dev@v1"]},{"id":"GHSA-fjrm-76x2-c4q4","severity":"medium","title":"JWCrypto: JWE ZIP decompression bomb","package":"jwcrypto@1.5.0","cve":"CVE-2026-39373","location":"https://osv.dev/vulnerability/GHSA-fjrm-76x2-c4q4","sources":["deps.dev@v1"]},{"id":"GHSA-j857-7rvv-vj97","severity":"medium","title":"JWCrypto vulnerable to JWT bomb Attack in `deserialize` function","package":"jwcrypto@1.5.0","cve":"CVE-2024-28102","location":"https://osv.dev/vulnerability/GHSA-j857-7rvv-vj97","sources":["deps.dev@v1"]},{"id":"GHSA-6w46-j5rx-g56g","severity":"medium","title":"pytest has vulnerable tmpdir handling","package":"pytest@8.0.0","cve":"CVE-2025-71176","location":"https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g","sources":["deps.dev@v1"]},{"id":"GHSA-3vpc-4p9p-47hc","severity":"low","title":"curl_cffi bundles a version of libcurl affected by High Severity vulnerability","package":"curl_cffi@0.6.0","location":"https://osv.dev/vulnerability/GHSA-3vpc-4p9p-47hc","sources":["deps.dev@v1"]},{"id":"GHSA-wcj4-jw5j-44wh","severity":"low","title":"CBORDecoder reuse can leak shareable values across decode calls","package":"cbor2@5.4.0","cve":"CVE-2025-68131","location":"https://osv.dev/vulnerability/GHSA-wcj4-jw5j-44wh","sources":["deps.dev@v1"]}],"security_intelligence":{"sources":[{"profile":"deps","scanner":"osv@v1","label":"OSV dependency advisories","status":"no_lockfile","status_label":"No lockfile (source not queried)","scanned_at":"2026-07-15T10:54:41.847149+00:00","findings_count":0,"evidence_url":"https://osv.dev/","error":null,"caveat":null},{"profile":"deps_dev","scanner":"deps.dev@v1","label":"deps.dev advisories","status":"findings","status_label":"Published findings","scanned_at":"2026-09-06T04:00:49.885233+00:00","findings_count":14,"evidence_url":"https://osv.dev/vulnerability/GHSA-3vpc-4p9p-47hc","error":null,"caveat":null},{"profile":"openssf_scorecard","scanner":"openssf-scorecard@v1","label":"OpenSSF Scorecard","status":"not_available","status_label":"No public record from this source","scanned_at":"2026-08-23T04:00:18.952388+00:00","findings_count":0,"evidence_url":"https://api.securityscorecards.dev/projects/github.com/lxf746/any-auto-register","error":null,"caveat":"Weekly public scans omit some checks at scale."}],"dependency_findings":[{"id":"GHSA-qw2m-4pqf-rmpp","severity":"high","title":"curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)","package":"curl_cffi@0.6.0","cve":"CVE-2026-33752","location":"https://osv.dev/vulnerability/GHSA-qw2m-4pqf-rmpp","sources":["deps.dev@v1"]},{"id":"GHSA-3c37-wwvx-h642","severity":"high","title":"cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads","package":"cbor2@5.4.0","cve":"CVE-2026-26209","location":"https://osv.dev/vulnerability/GHSA-3c37-wwvx-h642","sources":["deps.dev@v1"]},{"id":"GHSA-9q9c-vjxh-p795","severity":"high","title":"cbor2 C extension decoder flaws can cause denial of service","package":"cbor2@5.4.0","cve":"CVE-2025-64076","location":"https://osv.dev/vulnerability/GHSA-9q9c-vjxh-p795","sources":["deps.dev@v1"]},{"id":"GHSA-q34m-jh98-gwm2","severity":"high","title":"Werkzeug possible resource exhaustion when parsing file data in forms","package":"quart@0.19.0","cve":"CVE-2024-49767","location":"https://osv.dev/vulnerability/GHSA-q34m-jh98-gwm2","sources":["deps.dev@v1"]},{"id":"GHSA-9hjg-9r4m-mvj7","severity":"medium","title":"Requests vulnerable to .netrc credentials leak via malicious URLs","package":"requests@2.31.0","cve":"CVE-2024-47081","location":"https://osv.dev/vulnerability/GHSA-9hjg-9r4m-mvj7","sources":["deps.dev@v1"]},{"id":"GHSA-9wx4-h78v-vm56","severity":"medium","title":"Requests `Session` object does not verify requests after making first request with verify=False","package":"requests@2.31.0","cve":"CVE-2024-35195","location":"https://osv.dev/vulnerability/GHSA-9wx4-h78v-vm56","sources":["deps.dev@v1"]},{"id":"GHSA-gc5v-m9x4-r6x2","severity":"medium","title":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","package":"requests@2.31.0","cve":"CVE-2026-25645","location":"https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2","sources":["deps.dev@v1"]},{"id":"GHSA-mr82-8j83-vxmv","severity":"medium","title":"Pydantic regular expression denial of service","package":"pydantic@2.0.0","cve":"CVE-2024-3772","location":"https://osv.dev/vulnerability/GHSA-mr82-8j83-vxmv","sources":["deps.dev@v1"]},{"id":"GHSA-cw2r-4p82-qv79","severity":"medium","title":"DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value","package":"jwcrypto@1.5.0","cve":"CVE-2023-6681","location":"https://osv.dev/vulnerability/GHSA-cw2r-4p82-qv79","sources":["deps.dev@v1"]},{"id":"GHSA-fjrm-76x2-c4q4","severity":"medium","title":"JWCrypto: JWE ZIP decompression bomb","package":"jwcrypto@1.5.0","cve":"CVE-2026-39373","location":"https://osv.dev/vulnerability/GHSA-fjrm-76x2-c4q4","sources":["deps.dev@v1"]},{"id":"GHSA-j857-7rvv-vj97","severity":"medium","title":"JWCrypto vulnerable to JWT bomb Attack in `deserialize` function","package":"jwcrypto@1.5.0","cve":"CVE-2024-28102","location":"https://osv.dev/vulnerability/GHSA-j857-7rvv-vj97","sources":["deps.dev@v1"]},{"id":"GHSA-6w46-j5rx-g56g","severity":"medium","title":"pytest has vulnerable tmpdir handling","package":"pytest@8.0.0","cve":"CVE-2025-71176","location":"https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g","sources":["deps.dev@v1"]},{"id":"GHSA-3vpc-4p9p-47hc","severity":"low","title":"curl_cffi bundles a version of libcurl affected by High Severity vulnerability","package":"curl_cffi@0.6.0","location":"https://osv.dev/vulnerability/GHSA-3vpc-4p9p-47hc","sources":["deps.dev@v1"]},{"id":"GHSA-wcj4-jw5j-44wh","severity":"low","title":"CBORDecoder reuse can leak shareable values across decode calls","package":"cbor2@5.4.0","cve":"CVE-2025-68131","location":"https://osv.dev/vulnerability/GHSA-wcj4-jw5j-44wh","sources":["deps.dev@v1"]}],"scorecard_findings":[]},"methodology":"github_public_v1"}}