Skip to content

Update dependency gradio to v6#40

Open
mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/gradio-6.x
Open

Update dependency gradio to v6#40
mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/gradio-6.x

Update dependency gradio to v6

8ed1157
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Jul 9, 2026 in 6m 8s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

pip

/tmp/ws-scm/stable-diffusion-webui/requirements.txt

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260709174551_URBTSZ/cmd_EGEZWM/20260709174615/UAKAQO_script.sh
    Error lines:
    [ERROR: Cannot install -r /tmp/ws-scm/stable-diffusion-webui/requirements.txt (line 11) and -r /tmp/ws-scm/stable-diffusion-webui/requirements.txt (line 33) because these package versions have conflicting dependencies., ERROR: ResolutionImpossible: for help visit https://p...
  • pip install command failed, trying to install dependencies one by one
  • Failed to resolve the following dependencies: *[nvidia-curand-10.4.0.35, charset-normalizer-3.4.9, six-1.17.0, certifi-2026.6.17, nvidia-nvtx-13.0.85, python-dateutil-2.9.0.post0, smmap-5.0.3, triton-3.7.1, Pygments-2.20.0, nvidia-nvshmem-cu13-3.4.5, regex-2026.6.28, tqdm-4.68.4, matplotlib-3.10.9, yarl-1.24.2, cycler-0.12.1, cuda-pathfinder-1.5.6, python-multipart-0.0.32, pytz-2026.2, jsonsche...

You have successfully remediated 85 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-0994

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260709174551_URBTSZ/python_VGMQGQ/202607091745521/env/lib/python3.10/site-packages/protobuf-3.20.0.dist-info

Dependency Hierarchy:

-> ❌ protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)

High 8.6 Direct protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl protobuf - 6.33.5,https://github.com/protocolbuffers/protobuf.git - v33.5,https://github.com/protocolbuffers/protobuf.git - v29.6,https://github.com/protocolbuffers/protobuf.git - v3.29.6-objectivec,https://github.com/protocolbuffers/protobuf.git - v5.29.6-cpp,https://github.com/protocolbuffers/protobuf.git - v5.35.0-objectivec,https://github.com/protocolbuffers/protobuf.git - v4.33.5-objectivec,protobuf - 6.33.5 None
CVE-2025-4565

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260709174551_URBTSZ/python_VGMQGQ/202607091745521/env/lib/python3.10/site-packages/protobuf-3.20.0.dist-info

Dependency Hierarchy:

-> ❌ protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)

High 7.5 Direct protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl 4.25.8 None
CVE-2022-1941

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260709174551_URBTSZ/python_VGMQGQ/202607091745521/env/lib/python3.10/site-packages/protobuf-3.20.0.dist-info

Dependency Hierarchy:

-> ❌ protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)

High 7.5 Direct protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl protobuf-3.20.0-cp310-cp310-manylinux_2_12_x86_64.manylinux2010_x86_64.whl 3.20.2 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-48545 gradio-3.41.2-py3-none-any.whl
CVE-2026-44243 gitpython-3.1.46-py3-none-any.whl
CVE-2025-68146 filelock-3.19.1-py3-none-any.whl
CVE-2024-47872 gradio-3.41.2-py3-none-any.whl
CVE-2025-14925 accelerate-1.10.1-py3-none-any.whl
CVE-2026-42561 python_multipart-0.0.20-py3-none-any.whl
CVE-2026-59806 gradio-3.41.2-py3-none-any.whl
CVE-2024-1561 gradio-3.41.2-py3-none-any.whl
CVE-2024-1540 gradio-3.41.2-py3-none-any.whl
CVE-2026-48710 starlette-0.49.3-py3-none-any.whl
CVE-2026-9375 urllib3-2.6.3-py3-none-any.whl
CVE-2024-47168 gradio-3.41.2-py3-none-any.whl
CVE-2025-23042 gradio-3.41.2-py3-none-any.whl
CVE-2025-48889 gradio-3.41.2-py3-none-any.whl
CVE-2026-53537 python_multipart-0.0.20-py3-none-any.whl
CVE-2026-42311 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2024-47165 gradio-3.41.2-py3-none-any.whl
CVE-2026-45409 idna-3.11-py3-none-any.whl
CVE-2024-1728 gradio-3.41.2-py3-none-any.whl
CVE-2026-49119 gradio-3.41.2-py3-none-any.whl
CVE-2024-0964 gradio-3.41.2-py3-none-any.whl
CVE-2026-44431 urllib3-2.6.3-py3-none-any.whl
CVE-2026-31221 pytorch_lightning-2.6.0-py3-none-any.whl
CVE-2026-25645 requests-2.32.5-py3-none-any.whl
CVE-2026-54059 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2024-1729 gradio-3.41.2-py3-none-any.whl
CVE-2024-4325 gradio-3.41.2-py3-none-any.whl
CVE-2024-34510 gradio-3.41.2-py3-none-any.whl
CVE-2026-28415 gradio-3.41.2-py3-none-any.whl
CVE-2026-48818 starlette-0.49.3-py3-none-any.whl
CVE-2026-53538 python_multipart-0.0.20-py3-none-any.whl
CVE-2024-8966 gradio-3.41.2-py3-none-any.whl
CVE-2024-10648 gradio-3.41.2-py3-none-any.whl
CVE-2026-42284 gitpython-3.1.46-py3-none-any.whl
CVE-2024-10624 gradio-3.41.2-py3-none-any.whl
CVE-2026-55379 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2024-47164 gradio-3.41.2-py3-none-any.whl
CVE-2026-53540 python_multipart-0.0.20-py3-none-any.whl
CVE-2024-47868 gradio-3.41.2-py3-none-any.whl
CVE-2025-67221 orjson-3.11.5-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-2998 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2025-55551 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2025-2999 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2024-47867 gradio-3.41.2-py3-none-any.whl
CVE-2026-28416 gradio-3.41.2-py3-none-any.whl
CVE-2024-12217 gradio-3.41.2-py3-none-any.whl
CVE-2025-55552 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2025-4565 protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl
CVE-2026-54283 starlette-0.49.3-py3-none-any.whl
CVE-2026-7246 click-8.1.8-py3-none-any.whl
CVE-2026-44432 urllib3-2.6.3-py3-none-any.whl
CVE-2024-47084 gradio-3.41.2-py3-none-any.whl
CVE-2024-47869 gradio-3.41.2-py3-none-any.whl
CVE-2026-54282 starlette-0.49.3-py3-none-any.whl
CVE-2026-22701 filelock-3.19.1-py3-none-any.whl
CVE-2024-1727 gradio-3.41.2-py3-none-any.whl
CVE-2026-28414 gradio-3.41.2-py3-none-any.whl
CVE-2026-53539 python_multipart-0.0.20-py3-none-any.whl
CVE-2026-54060 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2025-63396 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2024-4940 gradio-3.41.2-py3-none-any.whl
CVE-2026-24486 python_multipart-0.0.20-py3-none-any.whl
CVE-2024-2206 gradio-3.41.2-py3-none-any.whl
CVE-2026-4538 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2026-40192 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2022-1941 protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl
CVE-2024-47166 gradio-3.41.2-py3-none-any.whl
CVE-2025-3000 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2024-4941 gradio-3.41.2-py3-none-any.whl
CVE-2024-8021 gradio-3.41.2-py3-none-any.whl
CVE-2024-47871 gradio-3.41.2-py3-none-any.whl
CVE-2024-47167 gradio-3.41.2-py3-none-any.whl
CVE-2026-40347 python_multipart-0.0.20-py3-none-any.whl
CVE-2026-24747 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2026-55380 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2024-10569 gradio-3.41.2-py3-none-any.whl
CVE-2025-3001 torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
CVE-2023-51449 gradio-3.41.2-py3-none-any.whl
CVE-2026-44244 gitpython-3.1.46-py3-none-any.whl
CVE-2024-47870 gradio-3.41.2-py3-none-any.whl
CVE-2026-25990 pillow-10.4.0-cp39-cp39-manylinux_2_28_x86_64.whl
CVE-2026-0994 protobuf-3.20.0-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl
CVE-2026-48817 starlette-0.49.3-py3-none-any.whl
CVE-2024-48052 gradio-3.41.2-py3-none-any.whl
CVE-2024-1183 gradio-3.41.2-py3-none-any.whl

Base branch total remaining vulnerabilities: 115
Base branch commit: c5914a21ae954deee909aaaafbb8ad722da7ffa9


Total libraries scanned: 31

Scan token: 9eb51ef9de2f4c458030f21e7766eb74