PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-78681Highnltk: NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parsesCVE-2026-78682Highnltk: NLTK: pathsec SSRF protection can be bypassed when a proxy is configuredCVE-2026-78683Criticalnltk: NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code ExecutionCVE-2026-62383Mediumnltk: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirelyCVE-2026-62384Highnltk: NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)CVE-2026-62385Highnltk: NLTK: Stable FrameNet and NKJP readers parse outside-root XMLCVE-2026-12259Mediumnltk: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package InjectionCVE-2026-63312Highnltk: NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File ReadCVE-2026-65915Mediumnltk: NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocolCVE-2026-70626Highnltk: NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus rootCVE-2026-73557Mediumvllm: vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt partsCVE-2026-73556Mediumvllm: vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2mCVE-2026-73555Mediumvllm: vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error MessagesCVE-2026-71486Mediumvllm: vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsCVE-2026-73295Mediummkdocs-material: Material for MkDocs: DOM XSS in search suggestions via query parameterCVE-2026-71428Criticalunstructured: unstructured: Server-Side Request Forgery in the URL-based partitioningCVE-2026-84366Highscrapy: Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by defaultCVE-2026-62676Highomnigent: Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.pyCVE-2026-62677Highomnigent: Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACECVE-2026-62674Criticalomnigent: Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCECVE-2026-62675Highomnigent: Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable ToolsCVE-2026-62388Highnltk: NLTK: Default ENFORCE=False Disables All pathsec Security ControlsCVE-2026-63311Mediumnltk: NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution FailureCVE-2026-76098Highmistune: Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in MarkdownCVE-2026-82397Hightornado: Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

Stop the waste.
Protect your environment with Kodem.