PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-7845Lowlangchain-chatchat: Langchain-Chatchat Uses a Broken or Risky Cryptographic AlgorithmCVE-2026-6907LowDjango: Django Uses Cache Containing Sensitive InformationCVE-2026-35192LowDjango: Django Uses Persistent Cookies Containing Sensitive Information CVE-2026-42048Criticallangflow: Langflow Knowledge Bases API is Vulnerable to Path TraversalCVE-2026-42864Criticalfirefighter-incident: FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theftCVE-2026-40864Mediumjupyterhub: JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)CVE-2026-25660Criticalcodechecker: Codechecker has an authentication bypass for certain API callsCVE-2026-42860Highedx-enterprise: edx-enterprise has SSRF via SAML metadata URL in sync_provider_data endpointCVE-2026-40934Highjupyter-server: Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server RestartCVE-2026-40110Highjupyter-server: Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)CVE-2026-35397Highjupyter-server: Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directoriesCVE-2025-61669Mediumjupyter-server: Jupyter Server has an open redirection vulnerability in `next` query parameterGHSA-8PQQ-224H-X875Mediumogham-mcp: ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API keyCVE-2026-42313Highpyload-ng: pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*`…CVE-2026-42312Mediumpyload-ng: pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification via unrestricted `ssl_verify` config (incomplete fix for…CVE-2025-67796Highrdiffweb: IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other usersCVE-2026-42601Criticalarchivebox: ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddViewCVE-2026-41895Highchangedetection.io: changedetection.io project has an XXE vulnerabilityCVE-2026-42311Highpillow: Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)CVE-2026-42310Mediumpillow: Pillow has a PDF Parsing Trailer Infinite Loop (DoS)CVE-2026-42308Mediumpillow: Pillow has an integer overflow when processing fontsCVE-2026-42309Mediumpillow: Pillow has a heap buffer overflow with nested list coordinatesCVE-2026-42301Highpyp2spec: pyp2spec is Vulnerable to Code InjectionCVE-2026-7725Lowprefect: Prefect Git Argument Injection in GitRepository Pull StepsCVE-2026-7724Lowprefect: Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Stop the waste.
Protect your environment with Kodem.