PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45078Highmatrix-synapse: Synapse CPU starvation (Denial of Service)CVE-2026-44722Mediumpyzipper: pyzipper has an encryption bypass for small files encrypted using itCVE-2026-43978Highwger: wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym managerCVE-2026-43977Highwger: wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine APICVE-2026-44919Mediumironic: OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block DevicesGHSA-V25J-WQCW-FVHJMediumwger: wger has an Uncontrolled Resource Consumption issueCVE-2026-44798Highnautobot: Nautobot: GitRepository.current_head field should not be writable through REST APICVE-2026-44797Highnautobot: Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)CVE-2026-44796Mediumnautobot: Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)CVE-2026-44794Mediumnautobot: Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to referenceCVE-2026-45134Highlangsmith: LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningCVE-2026-44681Mediumauthlib: Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open RedirectCVE-2026-44660Highujson: UltraJSON has a Memory Leak in ujson.dump() on Write FailureCVE-2026-31241Mediummem0ai: mem0 server lacks authentication and authorization controls for its memory deletion API endpointCVE-2026-31239Criticalmamba-ssm: mamba language model framework vulnerable to insecure deserialization when loading pre-trained models from HuggingFace HubCVE-2026-31245Mediummem0ai: mem0 server lacks authentication and authorization controls for its memory creation API endpointCVE-2026-31235Criticalimgaug: imgaug contains an insecure deserialization vulnerability in BackgroundAugmenter class within multicore.py moduleCVE-2026-31236Criticalllm: llm CLI tool contains a code injection vulnerability via `--functions` command-line argumentCVE-2026-31240Highmem0ai: mem0 server lacks authentication and authorization controls for its memory management API endpointsCVE-2026-31238Criticalludwig: Ludwig framework is vulnerable to insecure deserialization in its model serving componentCVE-2026-31237Criticalludwig: Ludwig framework is vulnerable to insecure deserialization through its predict() method.CVE-2026-31233Criticalguardrails-ai: Guardrails AI contains a code injection vulnerability in its Hub package installation mechanismCVE-2026-31234Criticalhorovod: Horovod contains an insecure deserialization vulnerability in its KVStore HTTP server componentCVE-2025-65719Criticalkubectl-mcp-server: Open Source Kubectl MCP Server vulnerable to arbitrary code execution via user interaction with crafted HTML pageCVE-2026-31225Highsuperduper-framework: Superduper: Remote code execution via unsafe eval in superduper query parsing

Stop the waste.
Protect your environment with Kodem.