PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-31222Highsnorkel: Snorkel Trainer.load uses an unsafe torch.loadCVE-2026-31220Criticalsyft: PySyft server-side arbitrary Python execution after code approvalCVE-2026-31223Highsnorkel: Snorkel BaseLabeler.load uses an unsafe pickle.loadCVE-2026-31224Highsnorkel: Snorkel MultitaskClassifier.load uses an unsafe torch.loadCVE-2026-31221Highpytorch-lightning: PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserializationCVE-2026-8319Mediumai-agents: aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory functionCVE-2026-2614Highmlflow: MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystemCVE-2026-43979Mediumlocal-deep-research: local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)CVE-2026-2393Highmlflow: MLflow Has a Server-Side Request Forgery (SSRF) VulnerabilityCVE-2026-7818Highpgadmin4: pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManagerCVE-2026-31253Highflash_attn: flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanismCVE-2026-31248Highdocling: Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacksCVE-2026-7816Highpgadmin4: pgAdmin 4: OS command injection vulnerability in Import/Export query exportCVE-2026-7817Highpgadmin4: pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilitiesCVE-2026-7820Mediumpgadmin4: pgAdmin 4: Improper restriction of excessive authentication attemptsCVE-2026-7814Mediumpgadmin4: pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modulesCVE-2026-7819Highpgadmin4: pgAdmin 4 File Manager has symbolic-link path traversalCVE-2026-7815Highpgadmin4: SQL injection vulnerability in pgAdmin 4 Maintenance ToolCVE-2026-7813Criticalpgadmin4: pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and…CVE-2026-31247Highdocling: Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacksCVE-2026-31246Mediumgpt-pilot: GPT-Pilot contains a command injection vulnerability in the Executor.run() methodCVE-2026-40217Highlitellm: LiteLLM has a sandbox escape in custom-code guardrailCVE-2026-45017Highpython-liquid: python-liquid: Absolute paths escape filesystem loader search pathGHSA-88Q9-CMP2-C2VQMediumoxidize-pdf: oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)CVE-2026-44432Highurllib3: urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Stop the waste.
Protect your environment with Kodem.