PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44181Criticaljupyter_enterprise_gateway: Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code ExecutionCVE-2026-47265Mediumaiohttp: AIOHTTP is vulnerable to cross-origin redirect with per-request cookiesCVE-2026-10766Lowmlrun: mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruptionCVE-2026-44180Criticaljupyter_enterprise_gateway: Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids BypassCVE-2026-44023Highdocling-core: Docling Core: Unsafe remote filename resolutionCVE-2026-44019Highdocling-core: Docling Core: Insufficient validation of image reference URIsCVE-2026-47214Highdocling: Docling: Unsafe URI and Path Handling in HTML BackendCVE-2026-44022Mediumdocling: Docling: Potential Path Traversal via LaTeX \includegraphics and \input CommandsCVE-2026-44020Highdocling: Docling: Unsafe XML Entity Expansion in USPTO Patent BackendCVE-2026-44018Mediumdocling: Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS BackendCVE-2026-44016Highdocling: Docling: Unsafe Playwright-based HTML RenderingCVE-2026-43980Mediummalla: malla: Stored XSS via Meshtastic node names in multiple frontend pagesCVE-2026-34993Mediumaiohttp: AIOHTTP is Vulnerable to Deserialization of Untrusted DataCVE-2026-44017Highdocling: Docling: Unsafe Zip Extraction in EasyOCR Model DownloadCVE-2026-6657Mediumjupyter-server: jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is usedCVE-2026-7666Lowdjango: Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshakeCVE-2026-5241Hightransformers: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading PathCVE-2026-44546Lowdaphne: daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separatorsCVE-2026-44545Mediumdaphne: daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/framesCVE-2026-4035Criticalmlflow: MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltrationCVE-2026-10692Lowcode-index-mcp: Code Index MCP is vulnerable to Uncontrolled Resource ConsumptionCVE-2026-47117Criticalopenmed: OpenMed vulnerable to remote code injection through privacy-filter model loading pathCVE-2026-5422Mediumjupyter-server: Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path() CVE-2026-3514Highprefect: Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'CVE-2026-3198Mediummlflow: MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions

Stop the waste.
Protect your environment with Kodem.