PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47419Highpraisonai-platform: praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDORCVE-2026-37737Mediumsanic-cors: sanic-cors contains an improper regular expression in the try_match() functionCVE-2024-27928Mediumvantage6: Vantage6: 2FA can be circumvented with hacked email accessCVE-2024-24769Lowvantage6: Vantage6: No limit on emails sent for password/MFA resetCVE-2026-11332Highansible-core: ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code executionCVE-2026-11312Lowinfinistore: bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV MapCVE-2026-50589Mediumironic: OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service CrashCVE-2026-47708Criticalstata-mcp: MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapperCVE-2026-50266Lowneutron: OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networksCVE-2026-44393Highoslo.messaging: OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshakeCVE-2026-10813Lowlmcache: LMCache: 16-bit multimodal hash collision can poison KV cache entriesCVE-2026-47192Lowkas: kas's late signature validation may allow unnoticed repository manipulationsCVE-2026-10812Lowgptcache: GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefixCVE-2026-47707Mediumstrawberry-graphql: Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias AmplificationCVE-2026-47706Mediumstrawberry-graphql: Strawberry GraphQL has a Circular Fragment Reference DOSCVE-2026-44889Mediumwebob: WebOb: Location header normalization during redirect leads to open redirect - againCVE-2026-48710Mediumstarlette: Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksCVE-2026-10804Lowstreamlit: Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omissionCVE-2026-10803Lowmlflow: MLflow: Deterministic sampling in dataset digest enables predictable collisionsCVE-2026-10801Lowms-swift: ms-swift: Image Cache Hash Collision via Missing Dimension MetadataCVE-2026-41283Criticalmistral: OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposedCVE-2026-48681Mediumironic: OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO imageCVE-2026-46447Mediumironic: OpenStack Ironic allows Boot Script InjectionCVE-2026-10783Lowgradio: Gradio: Audio cache key ignores metadata when saving numpy audio outputsCVE-2026-44182Criticaljupyter_enterprise_gateway: Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering

Stop the waste.
Protect your environment with Kodem.