Package
py3.13-babel
Component
py3.13-babel
Latest update
3.2
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 affects the npm package @babel/core (github.com/babel/babel, the JavaScript compiler): arbitrary file read via a crafted //# sourceMappingURL comment, fixed in @babel/core 7.29.6 and 8.0.0-rc.6.
This package is python-babel/babel, the unrelated Python i18n/CLDR library published to PyPI as "babel". The advisory has no PyPI-ecosystem entry; the only PyPI advisory ever filed against babel is CVE-2021-42771, fixed in 2.9.1 (we ship 2.18.0). The v2.18.0 source tree contains no package.json, package-lock.json, or node_modules, and nothing under an @babel/* scope is installed. Grype matched the APK name/version recorded in /.PKGINFO rather than any package content.
Name collision only -- not applicable.
Status