PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-7CX2-G3H9-382PHighcrawl4ai: Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker serverGHSA-F989-C77F-R2CQHighcrawl4ai: Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolutionCVE-2026-53754Highcrawl4ai: Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)CVE-2026-50023Highyt-dlp: yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)CVE-2026-50019Mediumyt-dlp: yt-dlp: File Downloader cookie leak with curl CVE-2026-56266Criticalcrawl4ai: Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS ExecutionCVE-2026-53753Criticalcrawl4ai: Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker APICVE-2026-48746Criticalvllm: vLLM: OpenAI auth bypassCVE-2026-48520Mediumlangflow: Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file readCVE-2026-48519Criticallangflow: Langflow: Unauthenticated RCE in Shareable PlaygroundsCVE-2026-42867Mediumlangflow: Langflow: Path Traversal in Knowledge Bases API via Creation EndpointCVE-2026-41523Highvllm: vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code ExecutionCVE-2026-33760Highlangflow: Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints CVE-2026-12398Highgalaxy-ng: Galaxy NG: command injection vulnerabilityCVE-2026-55443Mediumlangchain: LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loadersCVE-2026-54293Highnltk: Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadGHSA-GJ48-438W-JH9VMediumbleach: Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributesGHSA-G75F-G53V-794XMediumbleach: Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanningGHSA-8RFP-98V4-MMR6Lowbleach: Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in outputCVE-2026-54531Mediumpypdf: pypdf: Possible infinite loop when processing outlines/bookmarks in writerCVE-2026-54530Mediumpypdf: pypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionCVE-2026-49461Mediumpypdf: pypdf: Possible large memory usage for form XObjects during text extractionCVE-2026-49460Mediumpypdf: pypdf: Inefficient decoding of FlateDecode PNG predictor streamsCVE-2026-48735Mediumpypdf: pypdf: Manipulated XMP metadata streams can exhaust RAMCVE-2026-54283Highstarlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

Stop the waste.
Protect your environment with Kodem.