PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-49854Lowtornado: Tornado has out-of-bounds memory access via C extensionCVE-2026-48156Mediumpypdf: pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference…CVE-2026-48155Mediumpypdf: pypdf: Possible large memory usage for large offsets for layout mode textCVE-2026-48099Highwsgidav: WsgiDAV encoded dot segments can escape filesystem share rootsCVE-2026-48053Mediumkolibri: Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewsetCVE-2026-48045Mediumzeroconf: python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source floodCVE-2026-48039Criticalmeta-ads-mcp: Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access TokenCVE-2026-47781Highpdm: PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI ParsingCVE-2026-47764Highpdm: PDM wheel installation leads to Path Traversal via overridden write_to_fsCVE-2026-47763Mediumpdm: PDM: Project-Local State and Config Writes Follow SymlinksCVE-2026-48061Mediumlitestar: Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host headerCVE-2026-48060Highlitestar: Litestar has HTML Injection Through its CSRF TokenCVE-2026-47155Mediumvllm: vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processorsCVE-2026-47734Mediumdulwich: Dulwich has unbounded memory allocation in receive-pack from crafted thin packsCVE-2026-47712Lowdulwich: Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`CVE-2026-11529Lowmysql-mcp-server: MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI HandlerCVE-2026-41479Mediumauthlib: Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_typeCVE-2026-39922Mediumgeonode: GeoNode contains a server-side request forgery vulnerability in the service registration endpointCVE-2026-53954Mediumbugsink: Bugsink: DOS using large numbers of event tagsCVE-2026-47728Mediumbugsink: Bugsink: Project scoping missing in sourcemap and debug-file lookupCVE-2026-47716Lowbugsink: Bugsink: Issue bulk actions can affect another project’s issue if its UUID is knownCVE-2026-47715Lowbugsink: Bugsink: Issue event views can show an event from another project if its UUID is knownCVE-2026-47731Criticalait-core: NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated…CVE-2026-54533Mediumvantage6: vantage6 node has an Improper Access Control issueCVE-2026-54445Mediumvantage6: Vantage6: Set admin user and password from environment or configuration

Stop the waste.
Protect your environment with Kodem.