PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54282LowStarlette: Starlette: Unvalidated request path concatenated into authority poisons request.url.hostnameGHSA-PW6J-QG29-8W7FMediumtornado: Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuseCVE-2026-53539Highpython-multipart: python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of serviceCVE-2026-53540Lowpython-multipart: python-multipart: Negative Content-Length in parse_form buffers the entire body in memoryCVE-2026-53538Lowpython-multipart: python-multipart: Semicolon treated as querystring field separator enables parameter smugglingCVE-2026-53537Lowpython-multipart: python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parametersCVE-2026-49853Hightornado: Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientCVE-2026-49855Hightornado: tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)CVE-2026-48818Highstarlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsCVE-2026-48817Mediumstarlette: Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`GHSA-537C-GMF6-5CCFHighcryptography: Vulnerable OpenSSL included in cryptography wheelsCVE-2026-54274Mediumaiohttp: aiohttp: Incomplete websocket frame payloads bypass memory limitsCVE-2026-54275Lowaiohttp: aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS ConnectionsCVE-2026-54280Lowaiohttp: aiohttp: Payload Response Resources Are Not Closed After Mid-Body DisconnectCVE-2026-54273Mediumaiohttp: aiohttp: HTTP/1 Pipelined Requests Queue Without LimitCVE-2026-54278Mediumaiohttp: aiohttp: Unread Compressed Request Bodies Bypass client_max_size During CleanupCVE-2026-54277Mediumaiohttp: aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented LinesCVE-2026-54276Mediumaiohttp: aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesCVE-2026-54279Lowaiohttp: aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar PersistenceCVE-2026-50269Lowaiohttp: aiohttp: CRLF injection in multipart headersCVE-2026-48525Mediumpyjwt: PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWSCVE-2026-48522MediumPyJWT: PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemesCVE-2026-48526Highpyjwt: PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowedCVE-2026-48523Mediumpyjwt: PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keysCVE-2026-48524Lowpyjwt: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

Stop the waste.
Protect your environment with Kodem.