CRITICAL9.8
PYSEC-2026-337
Use of hard-coded, security-relevant constants in deepset-ai/haystack
Details
Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack in version 1.15.0 and prior. A patch is available at commit 5fc84904f198de661d5b933fde756aa922bf09f1.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/farm-haystack
Introduced in:
0No fixed version published yet for farm-haystack (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-1712[ADVISORY]
- https://github.com/deepset-ai/haystack/pull/4535[WEB]
- https://github.com/deepset-ai/haystack/commit/5fc84904f198de661d5b933fde756aa922bf09f1[WEB]
- https://github.com/deepset-ai/haystack[PACKAGE]
- https://huntr.dev/bounties/9a6b1fb4-ec9b-4cfa-af1e-9ce304924829[WEB]
- https://pypi.org/project/farm-haystack[PACKAGE]
- https://github.com/advisories/GHSA-w7qg-j435-78qw[ADVISORY]