compliance-trestle
PyPI9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting compliance-trestlepage 1 of 1
- CVE-2026-45725HIGHCVSS 7.1EG 7.1fixed in 4.0.3 or 3.12.2, by version range2026-05-27
vulnerable: 0.0.2 ... 4.0.2 (100 versions)
compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file …
- CVE-2026-45774MEDIUMCVSS 6.9EG 6.9fixed in 4.0.3 or 3.12.2, by version range2026-05-28
vulnerable: 0.0.2 ... 4.0.2 (100 versions)
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them with…
- CVE-2026-46345HIGHCVSS 8.4EG 8.4fixed in 4.0.3 or 3.12.2, by version range2026-05-28
vulnerable: 0.0.2 ... 4.0.2 (100 versions)
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does no…
- CVE-2026-46380MEDIUMCVSS 6.7EG 6.7fixed in 4.0.3 or 3.12.2, by version range2026-05-28
vulnerable: 0.0.2 ... 4.0.2 (100 versions)
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an atta…
- CVE-2026-46439HIGHCVSS 7.8EG 7.8fixed in 3.12.2 or 4.0.3, by version range2026-05-28
vulnerable: 0.0.2 ... 4.0.2 (100 versions)
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively e…
- CVE-2026-52776HIGHCVSS 8.6EG 8.6fixed in 4.1.02026-08-12
vulnerable: 0.0.2 ... 4.0.3 (104 versions)
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request f…
- CVE-2026-54757HIGHCVSS 7.8EG 7.8fixed in 3.12.4 or 4.1.0, by version range2026-08-25
vulnerable: 0.0.2 ... 4.0.3 (103 versions)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead t…
- CVE-2026-57170HIGHCVSS 7.8EG 7.8fixed in 3.12.4 or 4.1.0, by version range2026-08-25
vulnerable: 0.0.2 ... 4.0.3 (103 versions)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse…
- CVE-2026-57171HIGHCVSS 7.7EG 7.7fixed in 3.12.4 or 4.1.0, by version range2026-08-25
vulnerable: 0.0.2 ... 4.0.3 (103 versions)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author command…
Check whether compliance-trestle is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for compliance-trestle CVEs against the assets you own.
Book a Demo →