{"data":{"ecosystem":"pypi","name":"redis","url":"https://aisecwatch.com/packages/pypi/redis","latestVersion":"8.1.0","firstReleaseAt":"2012-10-08T06:40:56.248Z","repository":"https://github.com/redis/redis-py","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"async-timeout","versionSpec":">=4.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"cryptography","versionSpec":">=36.0.1","scope":"extra:ocsp"},{"ecosystem":"pypi","name":"hiredis","versionSpec":">=3.2.0","scope":"extra:hiredis"},{"ecosystem":"pypi","name":"opentelemetry-api","versionSpec":">=1.39.1","scope":"extra:otel"},{"ecosystem":"pypi","name":"opentelemetry-exporter-otlp-proto-http","versionSpec":">=1.39.1","scope":"extra:otel"},{"ecosystem":"pypi","name":"opentelemetry-sdk","versionSpec":">=1.39.1","scope":"extra:otel"},{"ecosystem":"pypi","name":"pybreaker","versionSpec":">=1.4.0","scope":"extra:circuit-breaker"},{"ecosystem":"pypi","name":"pyjwt","versionSpec":">=2.13.0","scope":"extra:jwt"},{"ecosystem":"pypi","name":"pyopenssl","versionSpec":">=20.0.1","scope":"extra:ocsp"},{"ecosystem":"pypi","name":"requests","versionSpec":">=2.31.0","scope":"extra:ocsp"},{"ecosystem":"pypi","name":"xxhash","versionSpec":"~=3.6.0","scope":"extra:xxhash"}],"advisories":[{"id":"ac8a22a8-c4e1-4f09-8c7e-8ab1d5ae7be6","url":"https://aisecwatch.com/issues/ac8a22a8-c4e1-4f09-8c7e-8ab1d5ae7be6","cveId":"CVE-2023-28858","title":"CVE-2023-28858: redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can…","headline":"redis-py async connection leaks response data to unrelated requests","severity":"low","publishedAt":"2023-03-26T23:15:06.780Z","affected":["redis@>= 4.4.0, < 4.4.3 (fixed: 4.4.3)","redis@>= 4.5.0, < 4.5.3 (fixed: 4.5.3)","redis@>= 4.2.0, < 4.3.6 (fixed: 4.3.6)"],"epssScore":0.01018}],"checkedAt":"2026-10-09T21:54:07.230Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}