Security Deep Dive
trulens
Security posture and CVE patch evidence from tracked releases.
39 critical dependency CVEs affects trulens-2.8.1.
Audit transitive dependencies; consider upgrading or pinning replacements.
Versions by Severity
CVEs are attributed to tracked releases published before the patch release.
| Version | Published | C | H | M | L | KEV | Notes |
|---|---|---|---|---|---|---|---|
| trulens-2.8.1 | 2026-05-14 | — | — | — | — | — |
Latest
Patches
CVE-2026-42208
|
| trulens-2.8.0 | 2026-04-30 | 1 | — | — | — | KEV 1 |
—
|
| trulens-2.7.2 | 2026-04-09 | 1 | — | — | — | KEV 1 |
—
|
| trulens-2.7.1 | 2026-03-10 | 1 | — | — | — | KEV 1 |
—
|
| trulens-2.7.0 | 2026-02-19 | 1 | — | — | — | KEV 1 |
—
|
| trulens-2.6.0 | 2026-02-04 | 1 | — | — | — | KEV 1 |
—
|
| trulens-2.5.3 | 2026-01-15 | 1 | — | — | — | KEV 1 |
—
|
Trust Signals — 2 of 9 Present
Evidence already collected from releases and repository metadata.
Security Score
A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.
epss
0.25 / 0.5
Max EPSS 0.569
freshness
1.00 / 1.0
3d stale
scorecard
2.00 / 4.0
⚠ Estimated — not yet collected
cve health
0.00 / 2.5
No open CVEs
patch speed
0.50 / 0.5
⚠ Estimated — no CVE patch history
kev exposure
-1.50 / 1.5
KEV exposure detected
supply chain risk
-1.50 / 10.0
Risk 100.0/100
Score breakdown
schema v2Vulnerability posture
vulnerability posture
0.0
25%
Release responsiveness
release responsiveness
10.0
5%
Dependency exposure
dependency exposure
0.0
10%
Provenance trust
provenance trust
5.0
40%
Maintainer health
maintainer health
10.0
10%
Operational risk
operational risk
1.5
10%
How is this calculated?
The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.
Supply Chain Risk
Risk 100.0/100OpenSSF Badge
Badge indicates adherence to open-source best practices.
CVE Patch History
Tracks CVEs that were addressed in tagged releases. Shorter gap between disclosure and patch = faster response. EPSS = predicted probability of exploitation in next 30 days (FIRST.org); colored at ≥90%ile and ≥50%ile.
CVEs Patched by Year
| CVE | Severity | EPSS | Disclosed | Fixed in | Days to fix | vs Ecosystem Median | KEV |
|---|---|---|---|---|---|---|---|
| CVE-2026-42208 | CRITICAL | 98%ile | — | trulens-2.8.1 | — | — | KEV |
KEV = CISA Known Exploited Vulnerabilities catalog — actively exploited in the wild.
Dependency Vulnerabilities
Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.
Critical
39
High
101
Medium
112
Low
33
Unknown
10
| CVE | Severity | KEV | Dependency | Affected version | Cleared in release |
|---|---|---|---|---|---|
| CVE-2012-0805 | critical | — | sqlalchemy | — | trulens-2.8.1 |
| CVE-2019-6446 | critical | — | numpy | — | trulens-2.8.1 |
| CVE-2019-7164 | critical | — | sqlalchemy | — | trulens-2.8.1 |
| CVE-2019-7548 | critical | — | sqlalchemy | — | trulens-2.8.1 |
| CVE-2020-13092 | critical | — | scikit-learn | — | trulens-2.8.1 |
| CVE-2022-26184 | critical | — | poetry | — | trulens-2.8.1 |
| CVE-2022-45907 | critical | — | torch | — | trulens-2.8.1 |
| CVE-2023-29374 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-32785 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-34540 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-34541 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-36095 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-36188 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-36258 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-36281 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-38860 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-38896 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-39631 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-39659 | critical | — | langchain | — | trulens-2.8.1 |
| CVE-2023-39662 | critical | — | llama-index | — | trulens-2.8.1 |
| CVE-2023-44467 | critical | — | langchain-experimental | — | trulens-2.8.1 |
| CVE-2023-47248 | critical | — | pyarrow | — | trulens-2.8.1 |
| CVE-2023-6730 | critical | — | transformers | — | trulens-2.8.1 |
| CVE-2024-21513 | critical | — | langchain-experimental | — | trulens-2.8.1 |
| CVE-2024-23751 | critical | — | llama-index | — | trulens-2.8.1 |
| CVE-2024-27444 | critical | — | langchain-experimental | — | trulens-2.8.1 |
| CVE-2024-2952 | critical | — | litellm | — | trulens-2.8.1 |
| CVE-2024-46946 | critical | — | langchain-experimental | — | trulens-2.8.1 |
| CVE-2024-48063 | critical | — | torch | — | trulens-2.8.1 |
| CVE-2024-5751 | critical | — | litellm | — | trulens-2.8.1 |
| CVE-2025-14009 | critical | — | nltk | — | trulens-2.8.1 |
| CVE-2025-1793 | critical | — | llama-index | — | trulens-2.8.1 |
| CVE-2025-32434 | critical | — | torch | — | trulens-2.8.1 |
| CVE-2025-43859 | critical | — | h11 | 0.14.0 | trulens-2.8.1 |
| CVE-2025-64712 | critical | — | unstructured | 0.7.1 | trulens-2.8.1 |
| CVE-2025-68664 | critical | — | langchain-core | — | trulens-2.8.1 |
| CVE-2026-35030 | critical | — | litellm | — | trulens-2.8.1 |
| CVE-2026-42208 | critical | — | litellm | — | — |
| GHSA-5mg7-485q-xm76 | critical | — | litellm | — | trulens-2.8.1 |
| CVE-2013-4251 | high | — | scipy | — | trulens-2.8.1 |
| CVE-2014-1858 | high | — | numpy | — | trulens-2.8.1 |
| CVE-2014-1859 | high | — | numpy | — | trulens-2.8.1 |
| CVE-2016-10075 | high | — | tqdm | — | trulens-2.8.1 |
| CVE-2017-12852 | high | — | numpy | — | trulens-2.8.1 |
| CVE-2018-18074 | high | — | requests | — | trulens-2.8.1 |
| CVE-2019-12408 | high | — | pyarrow | — | trulens-2.8.1 |
| CVE-2019-12410 | high | — | pyarrow | — | trulens-2.8.1 |
| CVE-2019-14751 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2019-18874 | high | — | psutil | — | trulens-2.8.1 |
| CVE-2020-28975 | high | — | scikit-learn | — | trulens-2.8.1 |
| CVE-2020-7694 | high | — | uvicorn | — | trulens-2.8.1 |
| CVE-2020-7695 | high | — | uvicorn | — | trulens-2.8.1 |
| CVE-2021-3828 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2021-3842 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2021-41495 | high | — | numpy | — | trulens-2.8.1 |
| CVE-2021-43854 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2022-36069 | high | — | poetry | — | trulens-2.8.1 |
| CVE-2022-36070 | high | — | poetry | — | trulens-2.8.1 |
| CVE-2023-32786 | high | — | langchain | — | trulens-2.8.1 |
| CVE-2023-34233 | high | — | snowflake-connector-python | — | trulens-2.8.1 |
| CVE-2023-36189 | high | — | langchain | — | trulens-2.8.1 |
| CVE-2023-46229 | high | — | langchain | — | trulens-2.8.1 |
| CVE-2023-7018 | high | — | transformers | — | trulens-2.8.1 |
| CVE-2024-10188 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2024-11392 | high | — | transformers | — | trulens-2.8.1 |
| CVE-2024-11393 | high | — | transformers | — | trulens-2.8.1 |
| CVE-2024-11394 | high | — | transformers | — | trulens-2.8.1 |
| CVE-2024-12704 | high | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2024-12911 | high | — | llama-index | — | trulens-2.8.1 |
| CVE-2024-21538 | high | — | cross-spawn | 7.0.3 | trulens-2.8.1 |
| CVE-2024-24762 | high | — | fastapi | 0.100 | trulens-2.8.1 |
| CVE-2024-31580 | high | — | torch | — | trulens-2.8.1 |
| CVE-2024-31583 | high | — | torch | — | trulens-2.8.1 |
| CVE-2024-38459 | high | — | langchain-experimental | — | trulens-2.8.1 |
| CVE-2024-39705 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2024-4181 | high | — | llama-index | — | trulens-2.8.1 |
| CVE-2024-4264 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2024-4888 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2024-5998 | high | — | langchain-community | — | trulens-2.8.1 |
| CVE-2024-6587 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2024-6825 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2024-8984 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2024-9606 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2025-0330 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2025-0628 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2025-1752 | high | — | llama-index | — | trulens-2.8.1 |
| CVE-2025-1753 | high | — | llama-index-cli | 0.3.1 | trulens-2.8.1 |
| CVE-2025-24793 | high | — | snowflake-connector-python | — | trulens-2.8.1 |
| CVE-2025-2828 | high | — | langchain-community | — | trulens-2.8.1 |
| CVE-2025-4565 | high | — | protobuf | 5.29.0 | trulens-2.8.1 |
| CVE-2025-47273 | high | — | setuptools | 75.3.0 | trulens-2.8.1 |
| CVE-2025-53000 | high | — | nbconvert | 7.14.2 | trulens-2.8.1 |
| CVE-2025-5302 | high | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2025-6209 | high | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2025-62727 | high | — | starlette | 0.41.3 | trulens-2.8.1 |
| CVE-2025-64512 | high | — | pdfminer-six | 20221105 | trulens-2.8.1 |
| CVE-2025-65106 | high | — | langchain-core | — | trulens-2.8.1 |
| CVE-2025-66418 | high | — | urllib3 | 2.5.0 | trulens-2.8.1 |
| CVE-2025-66471 | high | — | urllib3 | 2.5.0 | trulens-2.8.1 |
| CVE-2025-67221 | high | — | orjson | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69223 | high | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-6984 | high | — | langchain-community | — | trulens-2.8.1 |
| CVE-2025-6985 | high | — | langchain-text-splitters | 0.2.2 | trulens-2.8.1 |
| CVE-2025-70559 | high | — | pdfminer-six | 20221105 | trulens-2.8.1 |
| CVE-2025-7647 | high | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2025-7707 | high | — | llama-index | — | trulens-2.8.1 |
| CVE-2026-0846 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2026-0847 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2026-0994 | high | — | protobuf | 5.29.5 | trulens-2.8.1 |
| CVE-2026-1260 | high | — | sentencepiece | 0.1.97 | trulens-2.8.1 |
| CVE-2026-21441 | high | — | urllib3 | 2.5.0 | trulens-2.8.1 |
| CVE-2026-23490 | high | — | pyasn1 | 0.6.1 | trulens-2.8.1 |
| CVE-2026-24049 | high | — | wheel | 0.45.0 | trulens-2.8.1 |
| CVE-2026-2473 | high | — | google-cloud-aiplatform | 1.73.0 | trulens-2.8.1 |
| CVE-2026-25990 | high | — | pillow | 11.0.0 | trulens-2.8.1 |
| CVE-2026-26007 | high | — | cryptography | 46.0.0 | trulens-2.8.1 |
| CVE-2026-27459 | high | — | pyopenssl | 25.3.0 | trulens-2.8.1 |
| CVE-2026-27489 | high | — | onnx | 1.17.0 | trulens-2.8.1 |
| CVE-2026-28500 | high | — | onnx | 1.17.0 | trulens-2.8.1 |
| CVE-2026-30922 | high | — | pyasn1 | 0.6.1 | trulens-2.8.1 |
| CVE-2026-32597 | high | — | pyjwt | 2.9.0 | trulens-2.8.1 |
| CVE-2026-32640 | high | — | simpleeval | 0.9.13 | trulens-2.8.1 |
| CVE-2026-33079 | high | — | mistune | 3.2.0 | trulens-2.8.1 |
| CVE-2026-33231 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2026-33236 | high | — | nltk | — | trulens-2.8.1 |
| CVE-2026-34070 | high | — | langchain-core | — | trulens-2.8.1 |
| CVE-2026-34445 | high | — | onnx | 1.17.0 | trulens-2.8.1 |
| CVE-2026-34591 | high | — | poetry | 1.8.4 | trulens-2.8.1 |
| CVE-2026-35029 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2026-35397 | high | — | jupyter-server | 2.17.0 | trulens-2.8.1 |
| CVE-2026-40110 | high | — | jupyter-server | 2.17.0 | trulens-2.8.1 |
| CVE-2026-40192 | high | — | pillow | 11.0.0 | trulens-2.8.1 |
| CVE-2026-40934 | high | — | jupyter-server | 2.17.0 | trulens-2.8.1 |
| CVE-2026-42203 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2026-42264 | high | — | axios | 1.15.1 | trulens-2.8.1 |
| CVE-2026-42271 | high | — | litellm | — | trulens-2.8.1 |
| CVE-2026-42311 | high | — | pillow | 11.0.0 | trulens-2.8.1 |
| CVE-2026-44307 | high | — | mako | 1.3.10 | trulens-2.8.1 |
| GHSA-69x8-hrgq-fjj8 | high | — | litellm | — | trulens-2.8.1 |
| GHSA-q56x-g2fj-4rj6 | high | — | onnx | 1.17.0 | trulens-2.8.1 |
| CVE-2014-1829 | medium | — | requests | — | trulens-2.8.1 |
| CVE-2014-1830 | medium | — | requests | — | trulens-2.8.1 |
| CVE-2015-2296 | medium | — | requests | — | trulens-2.8.1 |
| CVE-2021-29510 | medium | — | pydantic | — | trulens-2.8.1 |
| CVE-2021-33430 | medium | — | numpy | — | trulens-2.8.1 |
| CVE-2021-34141 | medium | — | numpy | — | trulens-2.8.1 |
| CVE-2021-41496 | medium | — | numpy | — | trulens-2.8.1 |
| CVE-2022-35918 | medium | — | streamlit | — | trulens-2.8.1 |
| CVE-2022-42965 | medium | — | snowflake-connector-python | — | trulens-2.8.1 |
| CVE-2023-27494 | medium | — | streamlit | — | trulens-2.8.1 |
| CVE-2023-2800 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2023-32681 | medium | — | requests | — | trulens-2.8.1 |
| CVE-2023-37365 | medium | — | hnswlib | 0.7.0 | trulens-2.8.1 |
| CVE-2023-46250 | medium | — | pypdf | 3.9.0 | trulens-2.8.1 |
| CVE-2024-10940 | medium | — | langchain-core | — | trulens-2.8.1 |
| CVE-2024-12720 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2024-12910 | medium | — | llama-index | — | trulens-2.8.1 |
| CVE-2024-1455 | medium | — | langchain-core | — | trulens-2.8.1 |
| CVE-2024-2965 | medium | — | langchain | — | trulens-2.8.1 |
| CVE-2024-2965 | medium | — | langchain-community | — | trulens-2.8.1 |
| CVE-2024-3095 | medium | — | langchain-community | — | trulens-2.8.1 |
| CVE-2024-35195 | medium | — | requests | — | trulens-2.8.1 |
| CVE-2024-3571 | medium | — | langchain | — | trulens-2.8.1 |
| CVE-2024-3772 | medium | — | pydantic | — | trulens-2.8.1 |
| CVE-2024-42474 | medium | — | streamlit | — | trulens-2.8.1 |
| CVE-2024-46455 | medium | — | unstructured | 0.7.1 | trulens-2.8.1 |
| CVE-2024-47081 | medium | — | requests | — | trulens-2.8.1 |
| CVE-2024-4890 | medium | — | litellm | — | trulens-2.8.1 |
| CVE-2024-49750 | medium | — | snowflake-connector-python | — | trulens-2.8.1 |
| CVE-2024-5206 | medium | — | scikit-learn | — | trulens-2.8.1 |
| CVE-2024-5225 | medium | — | litellm | — | trulens-2.8.1 |
| CVE-2024-56201 | medium | — | jinja2 | 3.1.4 | trulens-2.8.1 |
| CVE-2024-56326 | medium | — | jinja2 | 3.1.4 | trulens-2.8.1 |
| CVE-2024-5710 | medium | — | litellm | — | trulens-2.8.1 |
| CVE-2025-1194 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-2099 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-24794 | medium | — | snowflake-connector-python | — | trulens-2.8.1 |
| CVE-2025-24795 | medium | — | snowflake-connector-python | — | trulens-2.8.1 |
| CVE-2025-27516 | medium | — | jinja2 | 3.1.4 | trulens-2.8.1 |
| CVE-2025-3108 | medium | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2025-3262 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-3263 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-3264 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-3730 | medium | — | torch | 2.7.1 | trulens-2.8.1 |
| CVE-2025-3933 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-50181 | medium | — | urllib3 | 1.26.20 | trulens-2.8.1 |
| CVE-2025-50182 | medium | — | urllib3 | 2.2.3 | trulens-2.8.1 |
| CVE-2025-5150 | medium | — | docarray | 0.39.1 | trulens-2.8.1 |
| CVE-2025-5197 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-54121 | medium | — | starlette | 0.41.3 | trulens-2.8.1 |
| CVE-2025-5472 | medium | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2025-55197 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2025-6051 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-61669 | medium | — | jupyter-server | 2.17.0 | trulens-2.8.1 |
| CVE-2025-6208 | medium | — | llama-index-core | 0.11.23 | trulens-2.8.1 |
| CVE-2025-6211 | medium | — | llama-index | — | trulens-2.8.1 |
| CVE-2025-62707 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2025-62708 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2025-66019 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2025-6638 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-68146 | medium | — | filelock | 3.16.1 | trulens-2.8.1 |
| CVE-2025-68480 | medium | — | marshmallow | 3.23.1 | trulens-2.8.1 |
| CVE-2025-6921 | medium | — | transformers | — | trulens-2.8.1 |
| CVE-2025-69227 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69228 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69229 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69873 | medium | — | ajv | 6.12.6 | trulens-2.8.1 |
| CVE-2025-71176 | medium | — | pytest | 8.3.4 | trulens-2.8.1 |
| CVE-2025-8869 | medium | — | pip | 24.3.1 | trulens-2.8.1 |
| CVE-2026-1839 | medium | — | transformers | 4.57.6 | trulens-2.8.1 |
| CVE-2026-22701 | medium | — | filelock | 3.16.1 | trulens-2.8.1 |
| CVE-2026-22815 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-24688 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-25645 | medium | — | requests | 2.32.4 | trulens-2.8.1 |
| CVE-2026-27024 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-27025 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-27026 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-27888 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-28277 | medium | — | langgraph | — | trulens-2.8.1 |
| CVE-2026-28351 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-28684 | medium | — | python-dotenv | 1.1.0 | trulens-2.8.1 |
| CVE-2026-28804 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-31826 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-3219 | medium | — | pip | 24.3.1 | trulens-2.8.1 |
| CVE-2026-33123 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-33230 | medium | — | nltk | — | trulens-2.8.1 |
| CVE-2026-33682 | medium | — | streamlit | — | trulens-2.8.1 |
| CVE-2026-33699 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-33750 | medium | — | brace-expansion | 1.1.11 | trulens-2.8.1 |
| CVE-2026-34446 | medium | — | onnx | 1.17.0 | trulens-2.8.1 |
| CVE-2026-34447 | medium | — | onnx | 1.17.0 | trulens-2.8.1 |
| CVE-2026-34515 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34516 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34525 | medium | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-39377 | medium | — | nbconvert | 7.14.2 | trulens-2.8.1 |
| CVE-2026-39378 | medium | — | nbconvert | 7.14.2 | trulens-2.8.1 |
| CVE-2026-39892 | medium | — | cryptography | 46.0.0 | trulens-2.8.1 |
| CVE-2026-40087 | medium | — | langchain-core | — | trulens-2.8.1 |
| CVE-2026-40260 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-41168 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-41182 | medium | — | langsmith | 0.1.143 | trulens-2.8.1 |
| CVE-2026-41205 | medium | — | mako | 1.3.10 | trulens-2.8.1 |
| CVE-2026-41305 | medium | — | postcss | 8.5.6 | trulens-2.8.1 |
| CVE-2026-41312 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-41313 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-41314 | medium | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-41481 | medium | — | langchain-text-splitters | 0.2.2 | trulens-2.8.1 |
| CVE-2026-42044 | medium | — | axios | 1.15.1 | trulens-2.8.1 |
| CVE-2026-42308 | medium | — | pillow | 11.0.0 | trulens-2.8.1 |
| CVE-2026-42310 | medium | — | pillow | 11.0.0 | trulens-2.8.1 |
| CVE-2026-6357 | medium | — | pip | 24.3.1 | trulens-2.8.1 |
| GHSA-rf74-v2fm-23pw | medium | — | nltk | — | trulens-2.8.1 |
| CVE-2024-0243 | low | — | langchain | — | trulens-2.8.1 |
| CVE-2024-12797 | low | — | cryptography | 43.0.3 | trulens-2.8.1 |
| CVE-2024-28088 | low | — | langchain | — | trulens-2.8.1 |
| CVE-2024-28088 | low | — | langchain-core | — | trulens-2.8.1 |
| CVE-2024-34062 | low | — | tqdm | — | trulens-2.8.1 |
| CVE-2024-3568 | low | — | transformers | — | trulens-2.8.1 |
| CVE-2024-8309 | low | — | langchain-community | — | trulens-2.8.1 |
| CVE-2024-8309 | low | — | langchain | — | trulens-2.8.1 |
| CVE-2025-2953 | low | — | torch | — | trulens-2.8.1 |
| CVE-2025-3777 | low | — | transformers | — | trulens-2.8.1 |
| CVE-2025-53643 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-5889 | low | — | brace-expansion | 1.1.11 | trulens-2.8.1 |
| CVE-2025-69224 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69225 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69226 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2025-69230 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-1703 | low | — | pip | 24.3.1 | trulens-2.8.1 |
| CVE-2026-22690 | low | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-22691 | low | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-26013 | low | — | langchain-core | — | trulens-2.8.1 |
| CVE-2026-27448 | low | — | pyopenssl | 25.3.0 | trulens-2.8.1 |
| CVE-2026-27628 | low | — | pypdf | 4.3.1 | trulens-2.8.1 |
| CVE-2026-34073 | low | — | cryptography | 46.0.0 | trulens-2.8.1 |
| CVE-2026-34513 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34514 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34517 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34518 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34519 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-34520 | low | — | aiohttp | 3.10.11 | trulens-2.8.1 |
| CVE-2026-41140 | low | — | poetry | 1.8.4 | trulens-2.8.1 |
| CVE-2026-41488 | low | — | langchain-openai | 0.1.7 | trulens-2.8.1 |
| CVE-2026-4539 | low | — | pygments | 2.19.1 | trulens-2.8.1 |
| GHSA-8qw9-gf7w-42x5 | low | — | streamlit | — | trulens-2.8.1 |
| CVE-2020-13091 | unknown | — | pandas | — | trulens-2.8.1 |
| CVE-2022-42969 | unknown | — | py | 1.11.0 | trulens-2.8.1 |
| CVE-2023-25399 | unknown | — | scipy | — | trulens-2.8.1 |
| CVE-2023-29824 | unknown | — | scipy | — | trulens-2.8.1 |
| CVE-2024-31584 | unknown | — | torch | — | trulens-2.8.1 |
| CVE-2024-45201 | unknown | — | llama-index | — | trulens-2.8.1 |
| CVE-2024-52338 | unknown | — | pyarrow | — | trulens-2.8.1 |
| CVE-2025-6209 | unknown | — | llama-index | — | trulens-2.8.1 |
| MAL-2026-2144 | unknown | — | litellm | — | trulens-2.8.1 |
| PYSEC-2026-2 | unknown | — | litellm | — | trulens-2.8.1 |
Showing 295 of 295