PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55195Mediumpy7zr: py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction sizeGHSA-RPJ2-4HQ8-938GHighvcrpy: VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette filesCVE-2026-55837Mediumdbt-mcp: dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensGHSA-P5WC-9W9R-M232Highultimate-sitemap-parser: Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParserGHSA-8823-QG2X-PV9FHighultimate-sitemap-parser: Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size LimitCVE-2026-54911Mediumujson: UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()CVE-2026-55865Mediumpython-liquid: Python Liquid: Infinite loop when parsing malformed `{% case %}` tagsCVE-2026-54528Highjupyterlab-git: jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded DirectoriesCVE-2026-54527Highjupyterlab-git: jupyterlab-git extension: Stored XSS leading to RCECVE-2026-54499Highstanza: Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model LoadersCVE-2026-54317Highhomeassistant: Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANCVE-2026-23879Highpy7zr: py7zr: Arbitrary File Write VulnerabilityGHSA-JV2H-4P9V-WF5WHighouroboros-ai: ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keysGHSA-VMHF-C436-HXJ4Mediumjupyterlab: JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocolGHSA-WG5P-8H9P-3MR7Highagent-coderag: agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code ExecutionCVE-2026-12530Highbedrock-agentcore: Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()GHSA-WM69-2PC3-RMMFHighcrawl4ai: Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)GHSA-R253-R9JW-QG44Criticalcrawl4ai: Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsGHSA-2JQ4-Q6VV-4CP3Criticalcrawl4ai: Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCECVE-2026-57496Criticalnetlicensing-mcp: netlicensing-mcp: REST Path Traversal Bypasses Token RedactionCVE-2026-54711Lowpghoard: PGHoard: Password written to debug logCVE-2026-54695Highpipecat-ai: Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SIDCVE-2026-44727Criticaljupyter-server: Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP CVE-2026-12567Lowbbot: BBOT: Symlink-Following Arbitrary Write via github_workflows ModuleCVE-2026-12568Mediumbbot: BBOT: Arbitrary File Write in postman_download Module

Stop the waste.
Protect your environment with Kodem.