PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-10566Lowmetagpt: FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()CVE-2026-10300Lowsglang: SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of DerviceCVE-2026-49138Mediumnanobot-ai: Nanobot contains a server-side request forgery vulnerability in the web_fetch toolCVE-2026-8643Mediumpip: pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directoryCVE-2026-47191Lowkas: kas checks out SHA-like git branches as valid commitsCVE-2026-47412Highpraisonai-platform: praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}CVE-2026-47415Highpraisonai-platform: praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDORCVE-2026-47413Criticalpraisonai-platform: praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/membersCVE-2026-47411Mediumpraisonai-platform: praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}CVE-2026-47417Highpraisonai-platform: praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDORCVE-2026-47418Highpraisonai-platform: praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDORCVE-2026-47425Mediumrattler: rattler has an entry-point path traversal in noarch:python install (arbitrary file write)CVE-2026-46764Mediumapache-airflow: Apache Airflow has an Authorization Bypass Through User-Controlled KeyCVE-2026-49267Mediumapache-airflow: Apache Airflow has no certificate validation on SMTP STARTTLS connectionsCVE-2026-49298Highapache-airflow-core: Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line argsCVE-2026-48726Mediumapache-airflow: Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logoutCVE-2026-42360Mediumapache-airflow: Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2026-41084Highapache-airflow: Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled KeyCVE-2026-45426Lowapache-airflow: Apache Airflow has an Incorrect Authorization issueCVE-2026-42359Highapache-airflow: Apache Airflow has a Deserialization of Untrusted Data vulnerabilityCVE-2026-45360Highapache-airflow: Apache Airflow Vulnerable to Deserialization of Untrusted DataCVE-2026-42358Mediumapache-airflow: Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2026-42252Criticalapache-airflow: Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template EngineCVE-2026-41017Mediumapache-airflow: Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' AttributeCVE-2026-41014Mediumapache-airflow: Apache Airflow has a Missing Authorization issue

Stop the waste.
Protect your environment with Kodem.