Responsible Disclosure

74 Confirmed Bugs

Security and logic bugs found by Nightjar in popular Python packages. All 74 reproduced by direct execution. Verified 2026-03-29.

21HIGH
44MEDIUM
7LOW
74/74CONFIRMED
HIGH— 21 bugs
HIGH
fastmcp2.14.5

JWT expiry check skipped when exp=None (falsy check)

HIGH
fastmcp2.14.5

JWT expiry bypassed when exp=0 (Unix epoch is falsy)

HIGH
fastmcp2.14.5

fnmatch OAuth redirect URI allows query-param injection and fake-port attacks

HIGH
fastmcp2.14.5

OAuthProxyProvider(allowed_client_redirect_uris=None) allows ALL redirect URIs

HIGH
litellm1.82.6

create_budget mutable default created_at=time.time() frozen at import

HIGH
python-jose3.5.0CVE-2024-33663

jwt.decode(algorithms=None) skips algorithm allowlist entirely

HIGH
passlib1.7.4

Complete incompatibility with bcrypt 4.x/5.x — bcrypt.hash() broken

HIGH
MiroFishlatest

Infinite loop in split_text_into_chunks when overlap >= chunk_size

HIGH
MiroFishlatest

Full Python tracebacks returned in HTTP error responses

HIGH
MiroFishlatest

Hardcoded SECRET_KEY='mirofish-secret-key' and DEBUG=True defaults

HIGH
MiroFishlatest

Path traversal via platform query parameter

HIGH
MiroFishlatest

Path traversal via unvalidated simulation_id parameter

HIGH
hermes-agentlatest

Duplicate close() method silently discards WAL checkpoint

HIGH
hermes-agentlatest

fuzzy_find_and_replace with replace_all=True corrupts unrelated code

HIGH
DeerFlowlatest

asyncio.Lock() at module level causes cross-thread deadlock

HIGH
open-swelatest

Middleware safety net skips recovery when commit_and_open_pr tool fails

HIGH
open-swelatest

git checkout -B force-resets existing branch on agent retry

HIGH
openai-agents0.13.2

Handoff conversation history markers allow developer-role trust escalation

HIGH
web37.14.1

ENS normalize_name() silently maps 62 fullwidth Unicode chars to ASCII — phishing vector

HIGH
RestrictedPython8.1

Sandbox fully bypassed when caller provides __import__ + getattr — confirmed RCE

HIGH
ragas0.4.3

9+ metric functions return np.nan as score sentinel — silently poisons aggregations

MEDIUM— 44 bugs
MED
httpx0.28.1

unquote("") raises IndexError on empty string

MED
fastapi0.135.1

decimal_encoder(Decimal("sNaN")) raises ValueError

MED
fastmcp2.14.5

compress_schema mutates input dict in-place despite immutable design claim

MED
litellm1.82.6

getattr(dict, "ended") always returns time.time() — dict key ignored

MED
litellm1.82.6

X-Forwarded-For multi-hop format fails exact-match IP allowlist

MED
python-jose3.5.0

Empty string accepted as HMAC secret key without warning

MED
passlib1.7.4

pbkdf2_sha256.hash("") succeeds — no minimum password length

MED
itsdangerous2.2.0

URLSafeSerializer("") accepted — empty string creates HMAC-less tokens

MED
PyJWT2.11.0

3-byte HMAC key accepted — enforce_minimum_key_length defaults to False

MED
authlib1.6.9

OctKey.import_key(b"short") — 5-byte key accepted without warning for HS256

MED
authlib1.6.9

JWTClaims.validate() skips iss and aud validation by default

MED
minbpelatest

train() crashes with ValueError when vocab_size exceeds mergeable pairs

MED
minbpelatest

load() crashes when special token name contains a space

MED
pydantic2.12.5

model_validator(mode='before') raises raw TypeError on bad input (not ValidationError)

MED
pydantic2.12.5

model_copy() is shallow by default — mutating copy mutates original

MED
pydantic2.12.5

model_copy(update=) bypasses all validators

MED
click8.3.1

required=True option allows empty string and whitespace-only values

MED
MiroFishlatest

Non-ASCII (CJK) characters pass isalnum() filter unchanged

MED
hermes-agentlatest

_suggest_similar_files char-set heuristic returns semantically unrelated files

MED
hermes-agentlatest

choose_cheap_model_route misses inflected keyword forms

MED
DeerFlowlatest

_UPLOAD_SENTENCE_RE word boundary \b prevents /mnt/ path matching

MED
DeerFlowlatest

_UPLOAD_SENTENCE_RE leaves garbled text when filename contains periods

MED
DeerFlowlatest

str_replace_tool returns OK for empty files without checking old_str

MED
DeerFlowlatest

UploadsMiddleware discards non-text content blocks in multi-modal messages

MED
open-swelatest

extract_repo_from_text returns repo name with embedded slash

MED
open-swelatest

GitHub URL with .git suffix produces invalid repo name

MED
llm0.29

truncate_string violates length contract when max_length < 3

MED
watchfiles1.1.1

Forward-slash .git paths not filtered on Windows (os.sep='\\' splits on backslash)

MED
langgraph1.1.3

add_conditional_edges() silently drops routing when no path_map and node is unregistered

MED
browser-use0.12.5

_filter_sensitive_data_from_string leaks suffix when secrets share a prefix

MED
openai-agents0.13.2

_parse_function_tool_json_input returns non-dict for valid JSON scalars

MED
google-adk1.28.0

InMemorySessionService silently overwrites existing session via whitespace-padded ID

MED
docling-coreHEAD

resolve_source_to_stream() reads arbitrary OS paths — no base-directory guard

MED
cryptography46.0.5

HKDF.derive(length=0) returns empty bytes instead of raising ValueError

MED
cryptography46.0.5

Fernet.decrypt(ttl=0) accepts same-second tokens — off-by-one in TTL check

MED
mlflow3.10.1

log_metric() silently stores NaN, inf, and -inf without raising

MED
celery5.6.2

set_chord_size(0) stored silently — chord body fires immediately with no results

MED
RestrictedPython8.1

compile_restricted() returns code object for dangerous patterns — no SyntaxError raised

MED
mcp1.26.0

Tool description field: no sanitization — prompt injection payloads preserved verbatim in wire JSON

MED
mcp1.26.0

Parameter description fields: injection payloads preserved in inputSchema.properties

MED
ragas0.4.3

DataCompyScore raises ZeroDivisionError when both precision and recall are zero

MED
ragas0.4.3

AnswerAccuracy.average_scores silently returns NaN when both sub-scores are NaN

MED
ragas0.4.3

Background analytics thread POSTs telemetry on every score() call — opt-out only

MED
opik1.10.54

factuality/parser.py raises ZeroDivisionError when LLM returns empty claims list

LOW— 7 bugs
LOW
python-jose3.5.0

jwt.decode(None) raises AttributeError instead of JWTError

LOW
itsdangerous2.2.0

loads(token, max_age=0) does NOT expire tokens

LOW
openai-agents0.13.2

null JSON input silently invokes tool with all default argument values

LOW
google-adk1.28.0

BashToolPolicy prefix validation bypassable via shell metacharacters

LOW
ormar0.23.0

order_by() lacks explicit field-name whitelist guard analogous to aggregate patch

LOW
crewaiHEAD

_execute_single_listener exceptions swallowed by asyncio.gather — non-deterministic flow state

LOW
mcp1.26.0

validate_and_warn_tool_name return value ignored — invalid names register without error