Package
py3.11-babel
Component
py3.11-babel
Latest update
6.2
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
GHSA-968p-4wvh-cqc8 / CVE-2025-27789 affects the npm packages @babel/helpers, @babel/runtime, @babel/runtime-corejs2 and @babel/runtime-corejs3 (github.com/babel/babel, the JavaScript compiler): inefficient RegExp complexity in code generated by .replace when transpiling named capturing groups, fixed in 7.26.10 and 8.0.0-alpha.17.
This package is python-babel/babel, the unrelated Python i18n/CLDR library published to PyPI as "babel". The advisory has no PyPI-ecosystem entry, and neither the vulnerable helper code nor any @babel/* npm package is present: the v2.18.0 source tree contains no package.json, package-lock.json, or node_modules. Grype matched the APK name/version recorded in /.PKGINFO rather than any package content.
Name collision only -- not applicable.
Status