Skip to content
Tools / phoenix / Security

Security Deep Dive

phoenix

Security posture and CVE patch evidence from tracked releases.

Back to Tool

22 critical dependency CVEs affects arize-phoenix-v17.2.0.

Audit transitive dependencies; consider upgrading or pinning replacements.

— Signed — SLSA — SBOM ✓ Security policy Weekly cadence · 0d median Active maintainer

Trust Signals — 3 of 9 Present

Evidence already collected from releases and repository metadata.

3/9 Present
Signed releases Unknown
Latest release artifact signature Latest release
SLSA provenance Unknown
Attestation predicate level Latest release
SBOM published Unknown
GitHub SBOM API Latest release
SECURITY.md Present
GitHub repository metadata Repository policy
Checked: 23d ago
Release cadence: weekly Present
0d median over recent releases Release history
Latest release: today
Maintainer active Present
Recent commit activity Repository
Last commit: 1d ago
Checksums (SHA256SUMS) Not active yet
SHA256SUMS or equivalent Release asset
Latest release: today
GitHub Actions attestation Not active yet
actions/attest-build-provenance Workflow file
Latest release: today
Signing assets Not active yet
.sig, .crt, cosign.pub, or similar Release asset
Latest release: today
0.8/10 Security Score
Dependency Exposure 198 transitive dependency CVEs found in the latest SBOM. 22 critical.

Security Score

A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.

epss

0.25 / 0.5

Max EPSS 0.543

freshness

1.00 / 1.0

Up to date

scorecard

2.00 / 4.0

⚠ Estimated — not yet collected

cve health

0.00 / 2.5

⚠ No direct scan — 22c/79h transitive CVEs

patch speed

0.50 / 0.5

⚠ Estimated — no CVE patch history

kev exposure

-1.50 / 1.5

KEV exposure detected

supply chain risk

-1.50 / 10.0

Risk 100.0/100

Score breakdown

schema v2

Vulnerability posture

vulnerability posture

0.0

25%

direct cves: clear cve scan: estimated

Release responsiveness

release responsiveness

10.0

5%

patch speed days: no_history

Dependency exposure

dependency exposure

0.0

10%

supply chain risk: 100.0 transitive cves: 22c/79h

Provenance trust

provenance trust

5.0

40%

scorecard score: estimated openssf badge: none

Maintainer health

maintainer health

10.0

10%

activity freshness: 0d

Operational risk

operational risk

1.5

10%

kev exposure: detected epss max: 0.543
How is this calculated?

The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.

Supply Chain Risk

Risk 100.0/100
22 Transitive critical CVEs
0 KEV-transitive CVEs
47% Dependency freshness

OpenSSF Badge

OpenSSF none

Badge indicates adherence to open-source best practices.

CVE Patch History

Tracks CVEs that were addressed in tagged releases. Shorter gap between disclosure and patch = faster response. EPSS = predicted probability of exploitation in next 30 days (FIRST.org); colored at ≥90%ile and ≥50%ile.

CVEs Patched by Year

Critical High Medium Low
2026
1
CVE Severity EPSS Disclosed Fixed in Days to fix vs Ecosystem Median KEV
CVE-2026-42208 CRITICAL 98%ile arize-phoenix-v15.5.0 KEV

KEV = CISA Known Exploited Vulnerabilities catalog — actively exploited in the wild.

Dependency Vulnerabilities

4516 dependencies scanned View full dependency list →

Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.

Critical

22

High

79

Medium

81

Low

10

Unknown

6

Critical 22 High 79 Medium 81 Low 10 Unknown 6
CVE Severity KEV Dependency Affected version Cleared in release
CVE-2012-0805 critical sqlalchemy arize-phoenix-v15.5.0
CVE-2017-18342 critical pyyaml arize-phoenix-v15.5.0
CVE-2019-20477 critical pyyaml arize-phoenix-v15.5.0
CVE-2019-6446 critical numpy arize-phoenix-v15.5.0
CVE-2019-7164 critical sqlalchemy arize-phoenix-v15.5.0
CVE-2019-7548 critical sqlalchemy arize-phoenix-v15.5.0
CVE-2020-14343 critical pyyaml arize-phoenix-v15.5.0
CVE-2020-17446 critical asyncpg arize-phoenix-v15.5.0
CVE-2020-1747 critical pyyaml arize-phoenix-v15.5.0
CVE-2021-41945 critical httpx arize-phoenix-v15.5.0
CVE-2021-43831 critical gradio arize-phoenix-v15.5.0
CVE-2023-6572 critical gradio arize-phoenix-v15.5.0
CVE-2024-1728 critical gradio arize-phoenix-v15.5.0
CVE-2024-2952 critical litellm arize-phoenix-v15.5.0
CVE-2024-3829 critical qdrant-client arize-phoenix-v15.5.0
CVE-2024-5751 critical litellm arize-phoenix-v15.5.0
CVE-2025-23042 critical gradio arize-phoenix-v15.5.0
CVE-2025-68664 critical langchain-core 1.0.0 arize-phoenix-v15.5.0
CVE-2026-35030 critical litellm 1.82.6 arize-phoenix-v15.5.0
CVE-2026-41242 critical protobufjs 7.5.4 arize-phoenix-v15.5.0
CVE-2026-42208 critical litellm 1.82.6 arize-phoenix-v15.5.1
GHSA-5mg7-485q-xm76 critical litellm arize-phoenix-v15.5.0
CVE-2014-1858 high numpy arize-phoenix-v15.5.0
CVE-2014-1859 high numpy arize-phoenix-v15.5.0
CVE-2015-5237 high protobuf arize-phoenix-v15.5.0
CVE-2016-10075 high tqdm arize-phoenix-v15.5.0
CVE-2017-11424 high pyjwt arize-phoenix-v15.5.0
CVE-2017-12852 high numpy arize-phoenix-v15.5.0
CVE-2018-18074 high requests arize-phoenix-v15.5.0
CVE-2019-18874 high psutil arize-phoenix-v15.5.0
CVE-2020-7694 high uvicorn arize-phoenix-v15.5.0
CVE-2020-7695 high uvicorn arize-phoenix-v15.5.0
CVE-2021-32677 high fastapi arize-phoenix-v15.5.0
CVE-2021-41495 high numpy arize-phoenix-v15.5.0
CVE-2022-1941 high protobuf arize-phoenix-v15.5.0
CVE-2022-24770 high gradio arize-phoenix-v15.5.0
CVE-2022-29217 high pyjwt arize-phoenix-v15.5.0
CVE-2023-1428 high grpcio arize-phoenix-v15.5.0
CVE-2023-32731 high grpcio arize-phoenix-v15.5.0
CVE-2023-33953 high grpcio arize-phoenix-v15.5.0
CVE-2023-4785 high grpcio arize-phoenix-v15.5.0
CVE-2023-51449 high gradio arize-phoenix-v15.5.0
CVE-2024-0964 high gradio arize-phoenix-v15.5.0
CVE-2024-10188 high litellm arize-phoenix-v15.5.0
CVE-2024-10569 high gradio arize-phoenix-v15.5.0
CVE-2024-10624 high gradio arize-phoenix-v15.5.0
CVE-2024-10648 high gradio arize-phoenix-v15.5.0
CVE-2024-1561 high gradio arize-phoenix-v15.5.0
CVE-2024-2206 high gradio arize-phoenix-v15.5.0
CVE-2024-24762 high fastapi arize-phoenix-v15.5.0
CVE-2024-34510 high gradio arize-phoenix-v15.5.0
CVE-2024-4264 high litellm arize-phoenix-v15.5.0
CVE-2024-4325 high gradio arize-phoenix-v15.5.0
CVE-2024-47084 high gradio arize-phoenix-v15.5.0
CVE-2024-47867 high gradio arize-phoenix-v15.5.0
CVE-2024-47870 high gradio arize-phoenix-v15.5.0
CVE-2024-47871 high gradio arize-phoenix-v15.5.0
CVE-2024-4888 high litellm arize-phoenix-v15.5.0
CVE-2024-4941 high gradio arize-phoenix-v15.5.0
CVE-2024-6587 high litellm arize-phoenix-v15.5.0
CVE-2024-6825 high litellm arize-phoenix-v15.5.0
CVE-2024-8966 high gradio arize-phoenix-v15.5.0
CVE-2024-8984 high litellm arize-phoenix-v15.5.0
CVE-2024-9606 high litellm arize-phoenix-v15.5.0
CVE-2025-0330 high litellm arize-phoenix-v15.5.0
CVE-2025-0628 high litellm arize-phoenix-v15.5.0
CVE-2025-4565 high protobuf arize-phoenix-v15.5.0
CVE-2025-65106 high langchain-core 1.0.0 arize-phoenix-v15.5.0
CVE-2026-0994 high protobuf arize-phoenix-v15.5.0
CVE-2026-28414 high gradio arize-phoenix-v15.5.0
CVE-2026-28416 high gradio arize-phoenix-v15.5.0
CVE-2026-32597 high pyjwt arize-phoenix-v15.5.0
CVE-2026-33079 high mistune 3.2.0 arize-phoenix-v15.5.0
CVE-2026-33671 high picomatch 4.0.3 arize-phoenix-v15.5.0
CVE-2026-34070 high langchain-core 1.0.0 arize-phoenix-v15.5.0
CVE-2026-35029 high litellm 1.82.6 arize-phoenix-v15.5.0
CVE-2026-35397 high jupyter-server 2.17.0 arize-phoenix-v15.5.0
CVE-2026-39363 high vite 8.0.2 arize-phoenix-v15.5.0
CVE-2026-39364 high vite 8.0.2 arize-phoenix-v15.5.0
CVE-2026-40110 high jupyter-server 2.17.0 arize-phoenix-v15.5.0
CVE-2026-40171 high jupyterlab 4.5.6 arize-phoenix-v15.5.0
CVE-2026-40171 high notebook 7.5.5 arize-phoenix-v15.5.0
CVE-2026-40192 high pillow 12.1.1 arize-phoenix-v15.5.0
CVE-2026-40934 high jupyter-server 2.17.0 arize-phoenix-v15.5.0
CVE-2026-42203 high litellm 1.82.6 arize-phoenix-v15.5.0
CVE-2026-42266 high jupyterlab 4.5.6 arize-phoenix-v15.5.0
CVE-2026-42271 high litellm 1.82.6 arize-phoenix-v15.5.0
CVE-2026-42311 high pillow 12.1.1 arize-phoenix-v15.5.0
CVE-2026-42557 high notebook 7.5.5 arize-phoenix-v15.5.0
CVE-2026-42557 high jupyterlab 4.5.6 arize-phoenix-v15.5.0
CVE-2026-44243 high gitpython 3.1.47 arize-phoenix-v15.5.0
CVE-2026-44244 high gitpython 3.1.47 arize-phoenix-v15.5.0
CVE-2026-44307 high mako 1.3.11 arize-phoenix-v15.5.0
CVE-2026-44665 high fast-xml-builder 1.1.4 arize-phoenix-v15.5.0
CVE-2026-4800 high lodash 4.17.23 arize-phoenix-v15.5.0
CVE-2026-4800 high lodash-es 4.17.23 arize-phoenix-v15.5.0
CVE-2026-4867 high path-to-regexp 0.1.12 arize-phoenix-v15.5.0
CVE-2026-4926 high path-to-regexp 8.3.0 arize-phoenix-v15.5.0
CVE-2026-6321 high fast-uri 3.1.0 arize-phoenix-v15.5.0
CVE-2026-6322 high fast-uri 3.1.0 arize-phoenix-v15.5.0
GHSA-69x8-hrgq-fjj8 high litellm 1.82.6 arize-phoenix-v15.5.0
CVE-2014-1829 medium requests arize-phoenix-v15.5.0
CVE-2014-1830 medium requests arize-phoenix-v15.5.0
CVE-2015-2296 medium requests arize-phoenix-v15.5.0
CVE-2021-29510 medium pydantic arize-phoenix-v15.5.0
CVE-2021-33430 medium numpy arize-phoenix-v15.5.0
CVE-2021-34141 medium numpy arize-phoenix-v15.5.0
CVE-2021-41496 medium numpy arize-phoenix-v15.5.0
CVE-2022-35918 medium streamlit arize-phoenix-v15.5.0
CVE-2023-25823 medium gradio arize-phoenix-v15.5.0
CVE-2023-27494 medium streamlit arize-phoenix-v15.5.0
CVE-2023-32681 medium requests arize-phoenix-v15.5.0
CVE-2023-32732 medium grpcio arize-phoenix-v15.5.0
CVE-2023-34239 medium gradio arize-phoenix-v15.5.0
CVE-2023-41626 medium gradio arize-phoenix-v15.5.0
CVE-2024-1183 medium gradio arize-phoenix-v15.5.0
CVE-2024-12217 medium gradio arize-phoenix-v15.5.0
CVE-2024-1727 medium gradio arize-phoenix-v15.5.0
CVE-2024-1729 medium gradio arize-phoenix-v15.5.0
CVE-2024-34511 medium gradio arize-phoenix-v15.5.0
CVE-2024-35195 medium requests arize-phoenix-v15.5.0
CVE-2024-35255 medium azure-identity arize-phoenix-v15.5.0
CVE-2024-3651 medium idna 3.6 arize-phoenix-v15.5.0
CVE-2024-3772 medium pydantic arize-phoenix-v15.5.0
CVE-2024-42474 medium streamlit arize-phoenix-v15.5.0
CVE-2024-47081 medium requests arize-phoenix-v15.5.0
CVE-2024-47164 medium gradio arize-phoenix-v15.5.0
CVE-2024-47165 medium gradio arize-phoenix-v15.5.0
CVE-2024-47166 medium gradio arize-phoenix-v15.5.0
CVE-2024-47167 medium gradio arize-phoenix-v15.5.0
CVE-2024-47868 medium gradio arize-phoenix-v15.5.0
CVE-2024-47869 medium gradio arize-phoenix-v15.5.0
CVE-2024-47872 medium gradio arize-phoenix-v15.5.0
CVE-2024-48052 medium gradio arize-phoenix-v15.5.0
CVE-2024-4890 medium litellm arize-phoenix-v15.5.0
CVE-2024-4940 medium gradio arize-phoenix-v15.5.0
CVE-2024-51751 medium gradio arize-phoenix-v15.5.0
CVE-2024-5225 medium litellm arize-phoenix-v15.5.0
CVE-2024-5710 medium litellm arize-phoenix-v15.5.0
CVE-2024-8021 medium gradio arize-phoenix-v15.5.0
CVE-2025-48889 medium gradio arize-phoenix-v15.5.0
CVE-2025-61669 medium jupyter-server 2.17.0 arize-phoenix-v15.5.0
CVE-2025-71176 medium pytest arize-phoenix-v15.5.0
CVE-2026-25645 medium requests 2.32.4 arize-phoenix-v15.5.0
CVE-2026-28277 medium langgraph 0.2 arize-phoenix-v15.5.0
CVE-2026-28415 medium gradio arize-phoenix-v15.5.0
CVE-2026-28684 medium python-dotenv 1.0.1 arize-phoenix-v15.5.0
CVE-2026-2950 medium lodash 4.17.23 arize-phoenix-v15.5.0
CVE-2026-2950 medium lodash-es 4.17.23 arize-phoenix-v15.5.0
CVE-2026-33532 medium yaml 2.8.1 arize-phoenix-v15.5.0
CVE-2026-33672 medium picomatch 4.0.3 arize-phoenix-v15.5.0
CVE-2026-33682 medium streamlit 1.37.0 arize-phoenix-v15.5.0
CVE-2026-33750 medium brace-expansion 5.0.4 arize-phoenix-v15.5.0
CVE-2026-34450 medium anthropic arize-phoenix-v15.5.0
CVE-2026-34452 medium anthropic arize-phoenix-v15.5.0
CVE-2026-39365 medium vite 8.0.2 arize-phoenix-v15.5.0
CVE-2026-39406 medium @hono/node-server 1.19.11 arize-phoenix-v15.5.0
CVE-2026-39407 medium hono 4.12.9 arize-phoenix-v15.5.0
CVE-2026-39408 medium hono 4.12.9 arize-phoenix-v15.5.0
CVE-2026-39409 medium hono 4.12.9 arize-phoenix-v15.5.0
CVE-2026-39410 medium hono 4.12.9 arize-phoenix-v15.5.0
CVE-2026-40087 medium langchain-core 1.0.0 arize-phoenix-v15.5.0
CVE-2026-40190 medium langsmith 0.5.5 arize-phoenix-v15.5.0
CVE-2026-41182 medium langsmith 0.5.5 arize-phoenix-v15.5.0
CVE-2026-41238 medium dompurify 3.3.3 arize-phoenix-v15.5.0
CVE-2026-41239 medium dompurify 3.3.3 arize-phoenix-v15.5.0
CVE-2026-41240 medium dompurify 3.3.3 arize-phoenix-v15.5.0
CVE-2026-41305 medium postcss 8.5.8 arize-phoenix-v15.5.0
CVE-2026-41481 medium langchain-text-splitters 1.0.0 arize-phoenix-v15.5.0
CVE-2026-41650 medium fast-xml-parser 5.5.9 arize-phoenix-v15.5.0
CVE-2026-41907 medium uuid 11.1.0 arize-phoenix-v15.5.0
CVE-2026-42308 medium pillow 12.1.1 arize-phoenix-v15.5.0
CVE-2026-42309 medium pillow 12.1.1 arize-phoenix-v15.5.0
CVE-2026-42310 medium pillow 12.1.1 arize-phoenix-v15.5.0
CVE-2026-42338 medium ip-address 10.1.0 arize-phoenix-v15.5.0
CVE-2026-44455 medium hono 4.12.9 arize-phoenix-v15.5.0
CVE-2026-44456 medium hono 4.12.9 arize-phoenix-v15.5.0
CVE-2026-4923 medium path-to-regexp 8.3.0 arize-phoenix-v15.5.0
GHSA-26pp-8wgv-hjvm medium hono 4.12.9 arize-phoenix-v15.5.0
GHSA-39q2-94rc-95cp medium dompurify 3.3.3 arize-phoenix-v15.5.0
GHSA-458j-xx4x-4375 medium hono 4.12.9 arize-phoenix-v15.5.0
GHSA-vvjj-xcjg-gr5g medium nodemailer 7.0.13 arize-phoenix-v15.5.0
CVE-2024-34062 low tqdm arize-phoenix-v15.5.0
CVE-2024-47168 low gradio arize-phoenix-v15.5.0
CVE-2024-53861 low pyjwt arize-phoenix-v15.5.0
CVE-2025-5320 low gradio arize-phoenix-v15.5.0
CVE-2026-26013 low langchain-core 1.0.0 arize-phoenix-v15.5.0
CVE-2026-27167 low gradio arize-phoenix-v15.5.0
CVE-2026-41488 low langchain-openai 0.3 arize-phoenix-v15.5.0
GHSA-26jh-r8g2-6fpr low gradio arize-phoenix-v15.5.0
GHSA-8qw9-gf7w-42x5 low streamlit arize-phoenix-v15.5.0
GHSA-c7w3-x93f-qmm8 low nodemailer 7.0.13 arize-phoenix-v15.5.0
CVE-2017-8359 unknown grpcio arize-phoenix-v15.5.0
CVE-2020-13091 unknown pandas arize-phoenix-v15.5.0
CVE-2021-22570 unknown protobuf arize-phoenix-v15.5.0
CVE-2024-52338 unknown pyarrow 15.0.2 arize-phoenix-v15.5.0
MAL-2026-2144 unknown litellm arize-phoenix-v15.5.0
PYSEC-2026-2 unknown litellm arize-phoenix-v15.5.0

Showing 198 of 198

Beta — feedback welcome: [email protected]