Skip to content

Security scan: Dependency CVEs + minor observationsΒ #308

@Lucky3mc

Description

@Lucky3mc

Ran blitz_api through debuggix.space. Findings below.

🟠 Dependency CVEs
β€’ CVE-2026-33155 β€” deepdiff DoS
β€’ CVE-2026-32597 β€” pyjwt crit header bypass
β€’ CVE-2026-42561 β€” python-multipart DoS
In requirements.txt and uv.lock.

🟑 Binding to all interfaces β€” app/main.py:75

🟑 Requests without timeout β€” app/bitcoind/utils.py:58

SSH credentials in sync_to_blitz.sh are placeholder variables
per README β€” not flagged.

Scan took 60 seconds. Full report: debuggix.space

  • Lucky3mc

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions