PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-42526Mediumapache-airflow-providers-amazon: Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backendsCVE-2026-46374Highsqlfluff: SQLFluff: Uncontrolled Resource Consumption in SQLFluff ParserCVE-2026-46373Highsqlfluff: SQLFluff: Recursive Stack Overflow in ParserCVE-2026-46338Mediumpymdown-extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_pathCVE-2026-31072Criticalapscheduler: APScheduler's JSONSerializer and CBORSerializer are vulnerable to Remote Code Execution (RCE) via Insecure DeserializationCVE-2026-45739Lowstrawberry-graphql: Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLsCVE-2026-45758Criticalguardrails-ai: Malicious code in guardrails-ai 0.10.1 (supply chain compromise)CVE-2025-51427Highmodelscope: ModelScope is vulnerable to arbitrary code injection via a crafted moduleCVE-2026-45568Criticalzrok: rok Python ProxyShare can be used as an SSRF proxy through absolute URL pathsCVE-2026-45409Mediumidna: Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fixCVE-2026-2611Criticalmlflow: MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command ExecutionCVE-2026-4137Highmlflow: MLFlow Creates a Temporary File With Insecure Permissions CVE-2026-45554Mediumnicegui: NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routesCVE-2026-45553Highnicegui: NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()CVE-2026-45829Criticalchromadb: ChromaDB Python project has a pre-authentication code injection vulnerabilityGHSA-WX9M-WX4F-4CMGCriticalmistralai: Malicious dropper in mistralai 2.4.6 PyPI packageCVE-2026-45727Highcloakbrowser: CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletionGHSA-J5RM-V3VH-VX94Highedumfa: eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges GHSA-QQ2P-4282-CFC5Highedumfa: eduMFA: Incorrect InnoDB snapshot isolation possibly allows token reusageGHSA-74R7-3MJM-JC5VMediumedumfa: eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/checkGHSA-QW48-84F6-28GVHighgraphitedb: Graphite Has a Pickle Deserialization VulnerabilityCVE-2026-45539Highapm: Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents…CVE-2026-7302Criticalsglang: SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerabilityCVE-2026-7301Criticalsglang: SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socketCVE-2026-7304Criticalsglang: SGLang: Unauthenticated RCE via --enable-custom-logit-processor

Stop the waste.
Protect your environment with Kodem.