PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-70494Highopen-webui: Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolderCVE-2026-70493Mediumopen-webui: Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophicallyCVE-2026-70492Highopen-webui: Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messagesCVE-2026-70491Mediumopen-webui: Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpointsCVE-2026-70490Mediumopen-webui: Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role checkCVE-2026-70489Mediumopen-webui: Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsingCVE-2026-54020Mediumopen-webui: Open WebUI: DNS Rebinding SSRF BypassCVE-2026-70487Mediumopen-webui: Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadataCVE-2026-70488Mediumopen-webui: Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanupCVE-2026-70486Highopen-webui: Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-originCVE-2026-70485Highopen-webui: Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLsCVE-2026-70484Mediumopen-webui: Open WebUI: Users denied the image-generation permission can still generate images via chat completionsCVE-2026-70480Mediumopen-webui: Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart renderingCVE-2026-70483Lowopen-webui: Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpointCVE-2026-70482Highopen-webui: Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientCVE-2026-70481Mediumopen-webui: Open WebUI: Any member with write access to a standard channel can edit or delete other members' messagesCVE-2026-70479Highopen-webui: Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loaderCVE-2026-69248Mediumcryptography: python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtreesCVE-2026-69249Highcryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-buildingCVE-2026-69247Highcryptography: cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingCVE-2026-69244Highaiohttp: AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)CVE-2026-69243Mediumaiohttp: AIOHTTP: HTTP request smuggling via WebSocket upgradeCVE-2026-59881Mediumaiohttp: AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflateGHSA-P538-C434-8V24MediumGitPython: GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countGHSA-539M-9XH6-Q6RRMediumGitPython: GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via…

Stop the waste.
Protect your environment with Kodem.