PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44550Mediumopen-webui: Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' AccountsCVE-2026-44551Criticalopen-webui: Open WebUI has an LDAP Empty Password Authentication BypassCVE-2026-44502Mediumbugsink: Bunsink has an SSRF bypass in `validate_webhook_url`CVE-2026-44721Highopen-webui: open-webui Vulnerable to Stored XSS via Model DescriptionCVE-2026-38360Criticaldash-uploader: dash-uploader has a directory traversal vulnerabilityGHSA-R8CJ-3554-33MRLowjusthtml: justhtml introduces denial-of-service hardeningGHSA-Q9M2-FHV9-3JCFMediumpotato-annotation: `potato-annotation` has a Project-Boundary BypassGHSA-52CQ-7V8R-62C6Highgmaps-mcp: gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expenseCVE-2026-40214Mediumopenstack-cyborg: OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layerCVE-2026-40213Highopenstack-cyborg: OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpointsCVE-2026-44661Mediumutcp-http: utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocolGHSA-V7QW-HX66-4W9XHighnetbox-data-flows: netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tablesCVE-2026-44641Highapm-cli: Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during installCVE-2026-8088LowGDAL: OSGeo GDAL vulnerable to out-of-bounds readCVE-2026-8087LowGDAL: OSGeo GDAL vulnerable to heap-based buffer overflowCVE-2026-44742Highpostorius: Postorius is vulnerable to XSSCVE-2026-40610Mediumbentoml: BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build contextCVE-2026-44513Highdiffusers: Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom componentsCVE-2026-44520Mediumdocling-graph: docling-graph has SSRF via Missing Internal IP Validation in URLInputHandlerCVE-2026-44504Highaegra-api: Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)CVE-2026-44503Highcom.microsoft.kiota:microsoft-kiota-abstractions: Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirectCVE-2026-44484Criticalpytorch-lightning: Compromise of PyTorch Lightning PyPi Package VersionsCVE-2026-44264Mediumweblate: Weblate vulnerable to XSS via crafted MarkdownCVE-2026-44263Mediumweblate: Weblate Vulnerable to Private Translation Enumeration via Screenshot APICVE-2026-44439MediumPlaywrightCapture: Playwright Capture permits access to local files and internal network resources during page capture

Stop the waste.
Protect your environment with Kodem.