PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44431Highurllib3: urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsCVE-2026-44971Highguarddog: GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltrationCVE-2026-44972Mediumguarddog: GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package contentCVE-2026-6420Mediumkeylime: Keylime has a hardcoded attestation challenge nonce that allows replay attacksCVE-2026-44353Mediumstreamlink: Streamlink has an arbitrary local file read via file:// URI in HLS and DASHCVE-2026-44346Highbentoml: Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043)CVE-2026-44345Highbentoml: BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043)CVE-2026-44570Highopen-webui: Open WebUI has inconsistent authorization controls within memories APICVE-2026-44571Mediumopen-webui: Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read PermissionCVE-2026-44569Highopen-webui: Open WebUI's Insecure Message Access Breaks AuthorizationCVE-2026-44565Highopen-webui: Open WebUI Arbitrary File Write, Delete via Path TraversalGHSA-6XCP-7MPR-M7WMHighopen-webui: Open WebUI has a CORS misconfiguration and session validation issueCVE-2026-44340HighPraisonAI: PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`CVE-2026-44339Highpraisonaiagents: PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables executeCVE-2026-44336CriticalPraisonAI: PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injectionCVE-2026-44337MediumPraisonAI: PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queriesCVE-2026-44338HighPraisonAI: PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow executionCVE-2026-41018Mediumapache-airflow-providers-elasticsearch: Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URLCVE-2026-43826Mediumapache-airflow-providers-opensearch: Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URLCVE-2021-47935Highsentry: Sentry: Superusers can execute arbitrary commands by injecting malicious pickle-serialized objects through audit log entry data parameterCVE-2026-8212LowGDAL: OSGeo gdal has a heap-based buffer overflowCVE-2026-44897Mediummistune: Mistune Heading ID Attribute has Injection XSSCVE-2026-44896Mediummistune: Mistune has XSS via unescaped figclass/figwidth in Figure directiveCVE-2026-44708Mediummistune: Mistune Math Plugin has an XSS Escape BypassGHSA-MV93-W799-CJ2WHighGitPython: GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

Stop the waste.
Protect your environment with Kodem.