PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-H4G2-XFMW-Q2C9Highclauster: Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unsetGHSA-G5R6-GV6M-F5JVHighmcp-atlassian: mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachmentGHSA-WM45-QH3G-V83FHighmcp-atlassian: mcp-atlassian: Arbitrary server-side file read via attachment uploadCVE-2026-54071HighBabelDOC: BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.pyGHSA-9MQM-QCWF-5QHGMediumcredsweeper: CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resourcesGHSA-489G-7RXV-6C8QMediummcp-atlassian: MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)CVE-2026-49851Highmistune: Mistune: Potential DoS via quadratic-time parsing in parse_link_textCVE-2026-49836Mediumpsd-tools: psd-tools vulnerable to arbitrary file write via smart-object filenameCVE-2026-53956Mediumrattler_cache: Rattler vulnerable to package cache path traversal via conda package build stringCVE-2026-54651Mediumpypdf: pypdf: Possible infinite loop when processing threads/articles in writerCVE-2026-53720Mediumpymonocypher: pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too smallCVE-2026-49477Highsoupsieve: Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector ParserCVE-2026-49476Highsoupsieve: Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector ListsGHSA-52VM-MXX8-F227Highphantom-audio: Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool pathsCVE-2026-48987Mediumpyload-ng: pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerCVE-2026-48737Mediumpyload-ng: pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPsCVE-2026-49471Highserena-agent: Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEGHSA-MXWC-WH95-PW4GMediumtrapster: Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handlerCVE-2026-49825Highlxml_html_clean: `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributesCVE-2026-50127Mediumweblate: Weblate SSRF: outbound URL guard misses some private rangesGHSA-F66Q-9RF6-8795MediumFlask-Security-Too: Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertionGHSA-Q855-8RH5-JFGQMediumha-mcp: ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root pathCVE-2026-53533Mediumaiosmtplib: aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient addressCVE-2026-34225Mediumopen-webui: Open WebUI has Blind Server Side Request Forgery in its Image Edit FunctionalityCVE-2026-26193Highopen-webui: Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Stop the waste.
Protect your environment with Kodem.