PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54021Mediumopen-webui: Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameterCVE-2026-54019Mediumopen-webui: Open WebUI: RAG ACL Bypass in Milvus Multitenancy ModeCVE-2026-54018Highopen-webui: Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP RedirectsCVE-2026-54017Highopen-webui: Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversalCVE-2026-54016Mediumopen-webui: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File EnumerationCVE-2026-54015Mediumopen-webui: Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletionCVE-2026-54014Mediumopen-webui: Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}CVE-2026-54013Highopen-webui: Open WebUI: Stored XSS to Account Takeover via Model Profile Images CVE-2026-54012Highopen-webui: Open WebUI: Forged model meta.knowledge allows cross-user file read and deletionCVE-2026-54011Highopen-webui: Open WebUI: Stored XSS in Mermaid Markdown PreviewCVE-2026-54010Highopen-webui: Open WebUI: Forged chat-file link allows cross-user file read and deletionCVE-2026-54009Mediumopen-webui: Open WebUI: Cross-user file disclosure via /api/chat/completions image_url fieldCVE-2026-54008Highopen-webui: Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)CVE-2026-54007Highopen-webui: Open WebUI: Cross-origin postMessage confirmation bypass via action:submitCVE-2026-54006Mediumopen-webui: Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendarCVE-2026-54233Mediumvllm: vLLM: OOM Denial of Service via Audio Decompression BombCVE-2026-54236Mediumvllm: vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic routerCVE-2026-53923Mediumvllm: vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant servingCVE-2026-12491Mediumvllm: vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and ExpectationsCVE-2026-54235Mediumvllm: vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsCVE-2026-49468Criticallitellm: LiteLLM: Authentication Bypass via Host Header InjectionGHSA-69QJ-PVH9-C5WGHighyt-dlp: yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlpCVE-2026-46448Mediumnova: OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraintsCVE-2026-50574Highyt-dlp: yt-dlp: Arbitrary code execution via manifest downloads with aria2cCVE-2026-53755Highcrawl4ai: Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

Stop the waste.
Protect your environment with Kodem.