PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47390Mediumpraisonaiagents: PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodingsCVE-2026-47398HighPraisonAI: PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334GHSA-9VP8-3HMV-8FGHCriticalstigmem-node: stigmem-node's federation peer registration lacked explicit out-of-band approvalGHSA-W7PM-9G55-MXFMHighstigmem-node: stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgmentGHSA-JMFC-HFJQ-PXCPCriticalstigmem-node: stigmem-node's federation insecure transport settings may allow non-loopback cleartext federationGHSA-9PC9-4CRJ-MHPJHighstigmem-node: stigmem-node's Postgres schema identifier handling required defensive quotingGHSA-XH5J-XJFQ-QVVXHighstigmem-node: stigmem-node's federation peer token timestamp validation may reject valid peer tokensGHSA-FP6W-8WPG-74G5Criticalstigmem-node: stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopbackCVE-2026-47213Mediumboxlite: BoxLite has a Timeout Bypass VulnerabilityCVE-2026-47211Highouroboros-ai: ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .envCVE-2026-47184Mediumzeroconf: zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast floodCVE-2026-47183Mediumzeroconf: zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustionCVE-2026-47180Mediumzeroconf: zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of serviceCVE-2026-8838Criticalredshift-connector: amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() InjectionGHSA-4GG8-GXPX-9RPHMediumuv: uv is vulnerable to arbitrary file write through entry point namesCVE-2026-10108Highxiaomusic: xiaomusic contains an unauthenticated path traversal vulnerabilityCVE-2026-10105Highagno: agno contains a SQL injection vulnerabilityCVE-2026-49299Mediumneutron: OpenStack Neutron has an Incorrect Authorization issueGHSA-QP9X-WP8F-QGJJMediumtuf: tuf has platform-dependent delegation path matchingCVE-2026-42563Highdulwich: Dulwich Vulnerable to Command Injection via Merge Driver PathCVE-2026-42305Highdulwich: Dulwich has an arbitrary file write via NTFS-hostile tree entries on WindowsCVE-2026-43000Mediumkeystone: OpenStack Keystone has an Incorrect Authorization issueCVE-2026-44394Mediumkeystone: OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued tokenCVE-2026-42999Mediumkeystone: OpenStack Keystone has an Authorization BypassCVE-2026-42998Mediumkeystone: OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

Stop the waste.
Protect your environment with Kodem.