PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-7723Mediumprefect: Prefect Unauthenticated Event Injection via /api/events/in WebSocketCVE-2026-7722Mediumprefect: Prefect Auth Bypass via endswith() Health Check ExemptionCVE-2026-7711MediumMindsDB: MindsDB has an Improper Access Control IssueCVE-2026-7669Mediumsglang: SGLang has an Improper Input Validation/Injection IssueCVE-2026-7597Lowmem0ai: mem0ai mem0 has an Improper Input Validation IssueCVE-2026-7579MediumAstrBot: AstrBot Makes Use of Hard-coded PasswordCVE-2026-43003Highironic-python-agent: OpenStack Ironic Python Agent Includes Functionality from Untrusted Control SphereCVE-2026-43001Highkeystone: OpenStack Keystone has an Incorrect Authorization IssueCVE-2026-42354Criticalsentry: Sentry's improper authentication on SAML SSO process allows user identity linkingCVE-2026-42032Mediumckan: CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`CVE-2026-41654Mediumweblate: Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlCVE-2026-41519Mediumweblate: Weblate Doesn't Invalidate API Token on Password ChangeCVE-2026-40171High@jupyter-notebook/help-extension: Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSSCVE-2026-41016Mediumapache-airflow-providers-smtp: apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP providerCVE-2025-13030Lowdjango-mdeditor: django-mdeditor is Missing Authentication for Critical FunctionCVE-2026-42031Highckan: CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`CVE-2026-42352Highpygeoapi: pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber CVE-2026-42351Highpygeoapi: pygeoapi 0.23.x: Path Traversal in STAC FileSystemProviderCVE-2026-7404Mediummcpo-simple-server: mcpo-simple-server has a Path Traversal issueCVE-2026-41255Mediumckan: CKAN has CSRF exemption primed by anonymous requestsCVE-2026-41132Mediumckan: CKAN has no certificate validation on STMP connectionCVE-2026-42052Mediumbeets: beets has a Cross-site Scripting vulnerabilityCVE-2026-24178Criticalnvflare: NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication systemCVE-2026-42510Mediumironic: OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control SphereCVE-2026-7206Mediumsqlite-mcp: sqlite-mcp has an Injection issue

Stop the waste.
Protect your environment with Kodem.