PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-70483Lowopen-webui: Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpointCVE-2026-70482Highopen-webui: Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientCVE-2026-70481Mediumopen-webui: Open WebUI: Any member with write access to a standard channel can edit or delete other members' messagesCVE-2026-70479Highopen-webui: Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loaderCVE-2026-69248Mediumcryptography: python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtreesCVE-2026-69249Highcryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-buildingCVE-2026-69247Highcryptography: cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingCVE-2026-69244Highaiohttp: AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)CVE-2026-69243Mediumaiohttp: AIOHTTP: HTTP request smuggling via WebSocket upgradeCVE-2026-59881Mediumaiohttp: AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflateGHSA-P538-C434-8V24MediumGitPython: GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countGHSA-539M-9XH6-Q6RRMediumGitPython: GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via…GHSA-3F7W-8RR8-F37FHighGitPython: GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary…CVE-2026-9335Mediumkeras: Keras: HDF5 links can disclose local file contentsCVE-2026-54785Mediumgemini-bridge: gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline modeCVE-2026-53502Highthumbor: Thumbor has path traversal via post-validation URL decoding bypass in file_loaderCVE-2026-53505Highthumbor: Thumbor proportion filter allows unbounded post-transform resize leading to remote DoSCVE-2026-53504Highthumbor: Thumbor has Regex Denial of Service (ReDoS) in `convolution` filterCVE-2026-53503Highthumbor: Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoSCVE-2026-53501Highthumbor: Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signatureCVE-2026-53500Highthumbor: Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dotCVE-2026-12075Highnltk: Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE…CVE-2026-12061Highnltk: Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexCVE-2026-12072Highnltk: Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox…CVE-2026-12074Highnltk: Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the…

Stop the waste.
Protect your environment with Kodem.