@@ -268,6 +268,24 @@ advisories:
268268 data :
269269 fixed-version : 0.6.34-r3
270270
271+ - id : CGA-fv2w-mj69-6xmc
272+ aliases :
273+ - CVE-2025-69223
274+ - GHSA-6mq8-rvhq-8wgg
275+ events :
276+ - timestamp : 2026-01-06T12:59:32Z
277+ type : detection
278+ data :
279+ type : scan/v1
280+ data :
281+ subpackageName : open-webui
282+ componentID : a217018cfe2ee26e
283+ componentName : aiohttp
284+ componentVersion : 3.13.2
285+ componentType : python
286+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
287+ scanner : grype
288+
271289 - id : CGA-g8hp-px9w-7gwr
272290 aliases :
273291 - GHSA-m449-cwjh-6pw7
@@ -289,6 +307,60 @@ advisories:
289307 data :
290308 fixed-version : 0.6.40-r0
291309
310+ - id : CGA-gxcf-8845-xc8c
311+ aliases :
312+ - CVE-2025-69229
313+ - GHSA-g84x-mcqj-x9qq
314+ events :
315+ - timestamp : 2026-01-06T12:59:33Z
316+ type : detection
317+ data :
318+ type : scan/v1
319+ data :
320+ subpackageName : open-webui
321+ componentID : a217018cfe2ee26e
322+ componentName : aiohttp
323+ componentVersion : 3.13.2
324+ componentType : python
325+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
326+ scanner : grype
327+
328+ - id : CGA-h6c6-hqp6-f5g3
329+ aliases :
330+ - CVE-2025-69224
331+ - GHSA-69f9-5gxw-wvc2
332+ events :
333+ - timestamp : 2026-01-06T12:59:31Z
334+ type : detection
335+ data :
336+ type : scan/v1
337+ data :
338+ subpackageName : open-webui
339+ componentID : a217018cfe2ee26e
340+ componentName : aiohttp
341+ componentVersion : 3.13.2
342+ componentType : python
343+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
344+ scanner : grype
345+
346+ - id : CGA-hp4p-rvh5-mf3f
347+ aliases :
348+ - CVE-2025-69230
349+ - GHSA-fh55-r93g-j68g
350+ events :
351+ - timestamp : 2026-01-06T12:59:32Z
352+ type : detection
353+ data :
354+ type : scan/v1
355+ data :
356+ subpackageName : open-webui
357+ componentID : a217018cfe2ee26e
358+ componentName : aiohttp
359+ componentVersion : 3.13.2
360+ componentType : python
361+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
362+ scanner : grype
363+
292364 - id : CGA-j22w-9fw9-v4vm
293365 aliases :
294366 - CVE-2025-54121
@@ -333,6 +405,24 @@ advisories:
333405 data :
334406 note : The latest urllib3 package distributed by Pyodide is 2.5.0 (per https://pyodide.org/en/stable/usage/packages-in-pyodide.html). Pyodide will need to release a newer compatible version, and open-webui will need to integrate it.
335407
408+ - id : CGA-m8cw-3xrc-pq3p
409+ aliases :
410+ - CVE-2025-69227
411+ - GHSA-jj3x-wxrx-4x23
412+ events :
413+ - timestamp : 2026-01-06T12:59:33Z
414+ type : detection
415+ data :
416+ type : scan/v1
417+ data :
418+ subpackageName : open-webui
419+ componentID : a217018cfe2ee26e
420+ componentName : aiohttp
421+ componentVersion : 3.13.2
422+ componentType : python
423+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
424+ scanner : grype
425+
336426 - id : CGA-mmqg-f57g-9jcp
337427 aliases :
338428 - CVE-2025-3730
@@ -421,6 +511,24 @@ advisories:
421511 data :
422512 note : Bumping aiohttp to 3.12.14+ causes build failures. No upstream PRs currently address this incompatibility. Upstream maintainers must implement changes to accommodate aiohttp 3.12.14+ before this CVE can be resolved.
423513
514+ - id : CGA-pv6h-3mvc-3x7v
515+ aliases :
516+ - CVE-2025-69228
517+ - GHSA-6jhg-hg63-jvvf
518+ events :
519+ - timestamp : 2026-01-06T12:59:31Z
520+ type : detection
521+ data :
522+ type : scan/v1
523+ data :
524+ subpackageName : open-webui
525+ componentID : a217018cfe2ee26e
526+ componentName : aiohttp
527+ componentVersion : 3.13.2
528+ componentType : python
529+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
530+ scanner : grype
531+
424532 - id : CGA-pxpq-4523-7gg6
425533 aliases :
426534 - CVE-2024-23342
@@ -465,6 +573,24 @@ advisories:
465573 data :
466574 fixed-version : 0.6.34-r2
467575
576+ - id : CGA-qfcj-96fx-f3v2
577+ aliases :
578+ - CVE-2025-69225
579+ - GHSA-mqqc-3gqh-h2x8
580+ events :
581+ - timestamp : 2026-01-06T12:59:34Z
582+ type : detection
583+ data :
584+ type : scan/v1
585+ data :
586+ subpackageName : open-webui
587+ componentID : a217018cfe2ee26e
588+ componentName : aiohttp
589+ componentVersion : 3.13.2
590+ componentType : python
591+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
592+ scanner : grype
593+
468594 - id : CGA-qg34-qp8g-rhvg
469595 aliases :
470596 - CVE-2025-50182
@@ -509,6 +635,24 @@ advisories:
509635 data :
510636 note : The latest fonttools package distributed by Pyodide is 4.56.0 (per https://pyodide.org/en/stable/usage/packages-in-pyodide.html). Pyodide will need to release a newer compatible version, and open-webui will need to integrate it.
511637
638+ - id : CGA-vg7j-gwvp-hh92
639+ aliases :
640+ - CVE-2025-69226
641+ - GHSA-54jq-c3m8-4m76
642+ events :
643+ - timestamp : 2026-01-06T12:59:30Z
644+ type : detection
645+ data :
646+ type : scan/v1
647+ data :
648+ subpackageName : open-webui
649+ componentID : a217018cfe2ee26e
650+ componentName : aiohttp
651+ componentVersion : 3.13.2
652+ componentType : python
653+ componentLocation : /usr/share/open-webui/lib/python3.11/site-packages/aiohttp-3.13.2.dist-info/METADATA
654+ scanner : grype
655+
512656 - id : CGA-vp8f-xf9w-8jwj
513657 aliases :
514658 - CVE-2024-35195
0 commit comments