PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-69244Highaiohttp: AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)CVE-2026-69243Mediumaiohttp: AIOHTTP: HTTP request smuggling via WebSocket upgradeCVE-2026-59881Mediumaiohttp: AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflateGHSA-P538-C434-8V24MediumGitPython: GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countGHSA-539M-9XH6-Q6RRMediumGitPython: GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via…GHSA-3F7W-8RR8-F37FHighGitPython: GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary…CVE-2026-9335Mediumkeras: Keras: HDF5 links can disclose local file contentsCVE-2026-54785Mediumgemini-bridge: gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline modeCVE-2026-53502Highthumbor: Thumbor has path traversal via post-validation URL decoding bypass in file_loaderCVE-2026-53505Highthumbor: Thumbor proportion filter allows unbounded post-transform resize leading to remote DoSCVE-2026-53504Highthumbor: Thumbor has Regex Denial of Service (ReDoS) in `convolution` filterCVE-2026-53503Highthumbor: Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoSCVE-2026-53501Highthumbor: Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signatureCVE-2026-53500Highthumbor: Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dotCVE-2026-12075Highnltk: Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE…CVE-2026-12061Highnltk: Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexCVE-2026-12072Highnltk: Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox…CVE-2026-12074Highnltk: Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the…CVE-2026-54706Mediumonionshare-cli: OnionShare follows symlinks in shared directories, allowing unintended disclosure of local filesCVE-2026-54707Mediumonionshare-cli: OnionShare Receive mode writes uploaded files even when file uploads are disabledCVE-2026-67424Highflyto-core: Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationCVE-2026-67428Highflyto-core: Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to…CVE-2026-67426Criticalflyto-core: Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationCVE-2026-67425Highflyto-core: Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlCVE-2026-67427Highflyto-core: Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Stop the waste.
Protect your environment with Kodem.