CRITICAL 9.8
PYSEC-2026-337
Use of hard-coded, security-relevant constants in deepset-ai/haystack
Details
Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack in version 1.15.0 and prior. A patch is available at commit 5fc84904f198de661d5b933fde756aa922bf09f1.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / farm-haystack
Introduced in:
0 No fixed version published yet for farm-haystack (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-1712 [ADVISORY]
- https://github.com/deepset-ai/haystack/pull/4535 [WEB]
- https://github.com/deepset-ai/haystack/commit/5fc84904f198de661d5b933fde756aa922bf09f1 [WEB]
- https://github.com/deepset-ai/haystack [PACKAGE]
- https://huntr.dev/bounties/9a6b1fb4-ec9b-4cfa-af1e-9ce304924829 [WEB]
- https://pypi.org/project/farm-haystack [PACKAGE]
- https://github.com/advisories/GHSA-w7qg-j435-78qw [ADVISORY]