PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-3515Highprefect: Prefect has an Argument Injection issueGHSA-GGXF-37HM-9WQFMediuminstagrapi: instagrapi: Unsafe signup challenge path handling in instagrapiCVE-2026-47157Mediumaiograpi: aiograpi: Unsafe signup challenge path handlingCVE-2026-46715MediumFlask-Security-Too: Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptanceGHSA-7M8F-HGJQ-8GC9Highaiosend: aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handlerCVE-2026-46703Criticalboxlite: Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the HostCVE-2026-46695Criticalboxlite: BoxLite: Permission Bypass Allows Modification of Read-Only FilesCVE-2026-46678Mediumpydantic-ai: Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)CVE-2026-46645Mediumsqladmin: SQLAdmin: Authorization Bypass on `ajax_lookup`CVE-2026-47102Highlitellm: LiteLLM allows a user to modify their own user_role via the /user/update endpointCVE-2026-47101Highlitellm: LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permitCVE-2026-46556Mediumflaskbb: FlaskBB: SSRF in get_image_info() via unrestricted avatar URLCVE-2026-46561Mediumpyload-ng: pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls APICVE-2026-46517Highlmdeploy: lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-outCVE-2026-46497Lowcrawlee: Crawlee for Python: SSRF via sitemap-derived URLsCVE-2026-48207Criticalpyfory: Apache Fory PyFory Deserialization of Untrusted Data CVE-2026-8597Mediumsagemaker: Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handlerCVE-2026-8596Highsagemaker: Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve pathCVE-2026-46432Highlmdeploy: LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initializationCVE-2026-46486Mediummvt: Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processingCVE-2026-48989Highwindows-mcp: Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORSCVE-2026-2734Mediummlflow: MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checksGHSA-MW8F-W6P8-XRF4Highwger: wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=NoneCVE-2026-45804Highdiffusers: Diffusers: TOCTOU Trust Remote Code BypassCVE-2026-27173Highapache-airflow-providers-cncf-kubernetes: Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments

Stop the waste.
Protect your environment with Kodem.