PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47144Mediumshamefile: Shamefile has an arbitrary file read via shamefile.yaml in shame nextCVE-2026-46526Mediumlocal-deep-research: local-deep-research has an SSRF bypass in `safe_get`CVE-2026-46439Highcompliance-trestle: compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)CVE-2026-46380Mediumcompliance-trestle: compliance-trestle Vulnerable to SSRF in Remote Fetching SubsystemCVE-2026-44730Highpycti: OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAddCVE-2026-46345Highcompliance-trestle: compliance-trestle - jinja has an Arbitrary File Write via Path TraversalCVE-2026-45774Mediumcompliance-trestle: compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path TraversalCVE-2026-45725Highcompliance-trestle: compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path TraversalCVE-2026-45309Mediumasyncssh: AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal usernameCVE-2026-25879Criticallangroid: Langroid has Prompt to SQL Injection, Leading to RCECVE-2026-9712Lowpretix: pretix vulnerable to Authorization Bypass Through User-Controlled KeyCVE-2026-48544Hightaipy: Taipy contains a path traversal vulnerabilityCVE-2026-48545Highgradio: Gradio contains a cookie injection vulnerabilityCVE-2026-49017Highswift: OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request bodyCVE-2026-49014Highgdal: GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflowCVE-2025-66407MediumWeblate: Weblate has a Server-Side Request Forgery issueCVE-2026-9540Mediumvllm: vllm has Improper Resource Shutdown or Release CVE-2026-46745Mediumapache-airflow-providers-fab: Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerabilityCVE-2026-45361Highapache-airflow-providers-google: Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by defaultCVE-2026-2651Criticalmlflow: MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabledCVE-2026-4372Hightransformers: HuggingFace transformers vulnerable to remote code executionCVE-2026-9369Lowhermes-agent: hermes-agent has an Incorrect ComparisonCVE-2026-9368Mediumhermes-agent: hermes-agent has a sandbox issueCVE-2026-9366Mediumhermes-agent: hermes-agent has an Injection issueCVE-2026-9353Mediumhermes-agent: hermes-agent has an Injection issue

Stop the waste.
Protect your environment with Kodem.