Skip to content

πŸ”’ Security Alerts β€” IBM/MAX-Image-Resolution-EnhancerΒ #75

Description

@security-ops-bot

πŸ”’ Security Alerts β€” IBM/MAX-Image-Resolution-Enhancer

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

πŸ“– New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: (no direct admin collaborators assigned to this repo β€” please add an admin to receive security notifications)

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Fix PR
πŸ”΄ critical CVE-2020-11538 Pillow < 7.1.0 7.1.0 β€”
πŸ”΄ critical CVE-2021-34552 pillow < 8.3.0 8.3.0 β€”
πŸ”΄ critical CVE-2021-41208 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
πŸ”΄ critical GHSA-h6gw-r52c-724r tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
πŸ”΄ critical CVE-2022-22817 Pillow < 9.0.1 9.0.1 β€”
πŸ”΄ critical CVE-2023-50447 Pillow < 10.2.0 10.2.0 β€”
πŸ”΄ critical CVE-2021-25289 pillow >= 0, < 8.1.1 8.1.1 β€”
🟠 high CVE-2020-10994 Pillow < 7.1.0 7.1.0 β€”
🟠 high CVE-2020-10379 Pillow < 7.1.0 7.1.0 β€”
🟠 high CVE-2020-10177 Pillow < 7.1.0 7.1.0 β€”
🟠 high CVE-2020-35654 Pillow < 8.1.0 8.1.0 β€”
🟠 high CVE-2021-25293 Pillow >= 4.3.0, < 8.1.1 8.1.1 β€”
🟠 high CVE-2021-25288 Pillow >= 2.4.0, < 8.2.0 8.2.0 β€”
🟠 high CVE-2021-25287 Pillow >= 2.4.0, < 8.2.0 8.2.0 β€”
🟠 high CVE-2021-28676 Pillow < 8.2.0 8.2.0 β€”
🟠 high CVE-2021-28675 Pillow < 8.2.0 8.2.0 β€”
🟠 high CVE-2021-28677 Pillow < 8.2.0 8.2.0 β€”
🟠 high CVE-2020-10378 Pillow < 7.1.0 7.1.0 β€”
🟠 high CVE-2022-23574 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23573 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23572 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23571 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23591 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23570 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23587 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high GHSA-43q8-3fv7-pr5x tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23569 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23568 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23567 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-21736 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-21737 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-21738 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-21739 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-21740 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-21741 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23557 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23565 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23558 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2022-23559 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟠 high CVE-2021-41221 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41220 tensorflow = 2.6.0 2.6.1 β€”
🟠 high CVE-2021-41219 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41214 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41212 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41211 tensorflow = 2.6.0 2.6.1 β€”
🟠 high CVE-2021-41210 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41206 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41203 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-41201 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟠 high CVE-2021-23437 pillow >= 5.2.0, < 8.3.2 8.3.2 β€”
🟠 high CVE-2023-4863 Pillow < 10.0.1 10.0.1 β€”
🟠 high CVE-2023-44271 pillow >= 0, < 10.0.0 10.0.0 β€”
🟠 high CVE-2024-28219 pillow < 10.3.0 10.3.0 β€”
🟠 high CVE-2023-33976 tensorflow < 2.12.1 2.12.1 β€”
🟠 high CVE-2020-35653 pillow >= 0, < 8.1.0 8.1.0 β€”
🟠 high CVE-2021-25290 pillow >= 0, < 8.1.1 8.1.1 β€”
🟠 high CVE-2021-27921 Pillow < 8.1.2 8.1.2 β€”
🟠 high CVE-2021-27922 pillow < 8.1.2 8.1.2 β€”
🟠 high CVE-2021-27923 pillow < 8.1.2 8.1.2 β€”
🟠 high CVE-2026-54058 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-54059 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-54060 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-55379 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-55380 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59199 Pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59197 Pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59205 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59200 Pillow >= 5.1.0, < 12.3.0 12.3.0 β€”
🟑 medium CVE-2021-25292 Pillow >= 5.1.0, < 8.1.1 8.1.1 β€”
🟑 medium GHSA-jgpv-4h4c-xhw3 pillow < 8.1.1 8.1.2 β€”
🟑 medium CVE-2021-28678 Pillow >= 5.1.0, < 8.2.0 8.2.0 β€”
🟑 medium CVE-2022-22815 Pillow < 9.0.0 9.0.0 β€”
🟑 medium CVE-2022-22816 Pillow < 9.0.0 9.0.0 β€”
🟑 medium CVE-2022-23585 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟑 medium CVE-2022-23586 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟑 medium CVE-2022-23588 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟑 medium CVE-2022-23589 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟑 medium CVE-2022-23595 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟑 medium GHSA-wcv5-vrvr-3rx2 tensorflow >= 2.6.0, < 2.6.3 2.6.3 β€”
🟑 medium CVE-2023-32681 requests >= 2.3.0, < 2.31.0 2.31.0 PR
🟑 medium CVE-2021-41228 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41227 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41226 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41225 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41224 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41223 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41222 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41218 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41217 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41216 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41215 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41213 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41209 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41207 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41205 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41204 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41202 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41200 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41199 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41198 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41197 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41196 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2021-41195 tensorflow >= 2.6.0, < 2.6.1 2.6.1 β€”
🟑 medium CVE-2024-35195 requests < 2.32.0 2.32.0 β€”
🟑 medium CVE-2020-35655 pillow >= 4.3.0, < 8.1.0 8.1.0 β€”
🟑 medium CVE-2024-47081 requests < 2.32.4 2.32.4 β€”
🟑 medium CVE-2026-25645 requests < 2.33.0 2.33.0 β€”
🟑 medium CVE-2025-71176 pytest < 9.0.3 9.0.3 β€”
🟑 medium CVE-2026-42308 pillow < 12.2.0 12.2.0 β€”
🟑 medium CVE-2026-42310 pillow >= 4.2.0, < 12.2.0 12.2.0 β€”
🟑 medium CVE-2026-55798 Pillow < 12.3.0 12.3.0 β€”
🟑 medium CVE-2026-59198 Pillow >= 5.2.0, < 12.3.0 12.3.0 β€”

Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions