PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-48054Highlocalstack: Missing SSL certificate validation in localstackCVE-2023-48052Highhttpie: HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attackCVE-2023-6022Highprefect: Cross-Site Request Forgery vulnerability in PrefectCVE-2023-6021Criticalray: Ray Path Traversal vulnerabilityCVE-2023-48224Highethyca-fides: Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity VerificationCVE-2023-46121Mediumyt-dlp: yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy InjectionCVE-2023-5189Mediumgalaxy-importer: Ansible galaxy-importer Path Traversal vulnerabilityCVE-2023-47631Highvantage6-server: vantage6-server node accepts non-whitelisted algorithms from malicious serverCVE-2023-47627Mediumaiohttp: AIOHTTP has problems in HTTP parser (the python one, not llhttp)CVE-2023-47641Lowaiohttp: Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacksCVE-2023-47117Highlabel-studio: Label Studio Object Relational Mapper Leak Vulnerability in Filtering TaskCVE-2023-47163Highremarshal: Remarshal expands YAML alias nodes unlimitedly, hence Remarshal is vulnerable to Billion Laughs AttackCVE-2023-47128Criticalpiccolo: piccolo SQL Injection via named transaction savepointsCVE-2023-42781Highapache-airflow: Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2023-47037Mediumapache-airflow: Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notesCVE-2023-46446Highasyncssh: AsyncSSH Rogue Session AttackCVE-2023-46894Highesptool: esptool allows attackers to view sensitive information via weak cryptographic algorithmCVE-2023-46445Mediumasyncssh: AsyncSSH Rogue Extension NegotiationCVE-2023-43791Criticallabel-studio: Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session TokensCVE-2023-47248Criticalpyarrow: PyArrow: Arbitrary code execution when loading a malicious data fileCVE-2023-47114Mediumethyca-fides: Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR PackagesCVE-2023-44271Highpillow: Pillow Denial of Service vulnerabilityCVE-2023-43665HighDjango: Django Denial-of-service in django.utils.text.TruncatorCVE-2023-41164Mediumdjango: Django Denial of service vulnerability in django.utils.encoding.uri_to_iriCVE-2023-47204Criticaltransmute-core: transmute-core unsafe YAML deserialization vulnerability

Stop the waste.
Protect your environment with Kodem.