PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-84382Highhttpx2: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)CVE-2026-84380Mediumhttpx2: HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generatedCVE-2026-84379Mediumhttpx2: HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersCVE-2026-84378Mediumhttpx2: HTTPX2: Quadratic SSE line buffering can cause CPU denial of serviceCVE-2026-84381Highhttpcore2: HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxiesCVE-2026-73560Mediumvllm: vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsCVE-2026-81725Mediumnltk: NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocksCVE-2026-80206Highnltk: NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressionsCVE-2026-80205Highnltk: NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressionsCVE-2026-73558Mediumvllm: vLLM: Cross-User Data Leak VulnerabilityCVE-2026-78679MediumGitPython: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of…CVE-2026-78677HighGitPython: GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside…CVE-2026-78678MediumGitPython: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()CVE-2026-78676CriticalGitPython: GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated…CVE-2026-78675HighGitPython: GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…CVE-2026-73262Mediumprowler: Prowler: Stored XSS in HTML reports through unescaped cloud resource tagsCVE-2026-79674Highnltk: NLTK: Corpus Reader Sandbox BypassCVE-2026-79676Highnltk: NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcementCVE-2026-79657Criticalnltk: NLTK: Allowlisted pickle loaders still permit code execution in current sourceCVE-2026-78681Highnltk: NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parsesCVE-2026-78682Highnltk: NLTK: pathsec SSRF protection can be bypassed when a proxy is configuredCVE-2026-78683Criticalnltk: NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code ExecutionCVE-2026-62383Mediumnltk: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirelyCVE-2026-62384Highnltk: NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)CVE-2026-62385Highnltk: NLTK: Stable FrameNet and NKJP readers parse outside-root XML

Stop the waste.
Protect your environment with Kodem.