PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41140Lowpoetry: Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4CVE-2026-41066Highlxml: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local filesCVE-2026-39378Mediumnbconvert: nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image EmbeddingCVE-2026-39377Mediumnbconvert: nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment FilenamesCVE-2026-35588Mediumglances: Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config ValuesCVE-2026-35587Highglances: Glances has SSRF in IP Plugin via public_api leading to credential leakageCVE-2026-34839HighGlances: Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORSCVE-2026-33626Highlmdeploy: LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image LoadingCVE-2026-28684Mediumpython-dotenv: python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallbackCVE-2026-3219Mediumpip: pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP filesCVE-2025-66335Mediumdoris-mcp-server: Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralizationCVE-2026-6608Mediumfschat: FastChat has a Content Moderation Bypass via Arena Side-by-Side ViewsCVE-2026-6606Mediumagentscope: AgentScope vulnerable to Server-Side Request ForgeryCVE-2026-6607Mediumfschat: FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)CVE-2026-6603Mediumagentscope: AgentScope Vulnerable to Remote Code InjectionCVE-2026-6598Lowlangflow: Langflow: Cleartext Storage of Authentication Settings in Project Creation EndpointCVE-2026-6605Mediumagentscope: AgentScope vulnerable to Server-Side Request ForgeryCVE-2026-6604Mediumagentscope: AgentScope vulnerable to Server-Side Request ForgeryCVE-2026-6599Lowlangflow: Langflow vulnerable to injectionCVE-2026-6596Mediumlangflow-base: Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload APICVE-2026-6597Lowlangflow: Langflow has an Information Leak through Incomplete API Key RedactionCVE-2026-6587Lowragas: RAGAS has SSRF via Multi-Modal Faithfulness Collections ModuleCVE-2026-40948Mediumapache-airflow-providers-keycloak: apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session FixationCVE-2026-32690Lowapache-airflow-core: Apache Airflow Exposes Secrets in Variables Saved as JSON DictionariesCVE-2026-30912Mediumapache-airflow-core: Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

Stop the waste.
Protect your environment with Kodem.