PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-29080Criticalrucio: Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search APICVE-2026-44405Lowparamiko: Paramiko rsakey.py allows the SHA-1 algorithmCVE-2026-44222Mediumvllm: vLLM Vulnerable to Remote DoS via Special-Token PlaceholdersGHSA-7WW3-XVF5-CXWMLowciguard: ciguard: Web UI is missing HTTP defence-in-depth headersCVE-2026-44220Lowciguard: ciguard: discover_pipeline_files follows symlinks out of scan rootCVE-2026-44218Lowciguard: ciguard: Container image runs as root (no USER directive)CVE-2026-44219Mediumciguard: ciguard: SCA HTTP client reads response body without size capCVE-2026-42997Highironic-python-agent: OpenStack Ironic has an Incorrect Resource Transfer Between SpheresCVE-2026-42315Highpyload-ng: PyLoad vulnerable to Path Traversal via Package Folder Name in set_package_dataCVE-2026-43891Highchangedetection.io: changedetection.io has an Arbitrary Local File Read via a crafted backup restoreCVE-2026-42314Mediumpyload-ng: PyLoad Vulnerable to Path Traversal via Package Folder NameCVE-2026-42304HighTwisted: Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer ChainsCVE-2026-42303Mediumethyca-fides: Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate DetectionCVE-2026-42266Highjupyterlab: JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST requestCVE-2026-43901Mediumwireshark-mcp: wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configuredCVE-2026-42196Criticaldjango-s3file: django-s3file is vulnerable to relative path traversalCVE-2026-42175Mediumrequests-hardened: requests-hardened is Vulnerable to Server-Side Request ForgeryCVE-2026-42080Mediumpptagent: PPTAgent: Arbitrary File Write via `save_generated_slides`CVE-2026-42079Highpptagent: PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in ScopeCVE-2026-42078Mediumpptagent: PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_imageCVE-2026-42874Lowmicrodot: Microdot has HTTP response splitting in Response.set_cookie()CVE-2026-43002Mediumhorizon: OpenStack Horizon has Incorrect Behavior OrderCVE-2026-7847Lowlangchain-chatchat: Langchain-Chatchat Uses Insufficiently Random ValuesCVE-2026-7846Lowlangchain-chatchat: Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload APICVE-2026-5766MediumDjango: Django has an Improper Handling of Length Parameter Inconsistency

Stop the waste.
Protect your environment with Kodem.