PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32228Highapache-airflow-core: Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissionsCVE-2026-25917Highapache-airflow-core: Apache Airflow allows code execution through crafted XCom payloadsCVE-2026-41241Highpretalx: pretalx vulnerable to stored cross-site scripting in organizer search typeaheadCVE-2026-41426Mediumpretalx: pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholdersCVE-2026-41490Highdagster-duckdb: Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager IntegrationsCVE-2026-41496Highpraisonai: PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)CVE-2026-41497Criticalpraisonai: PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection CVE-2026-40525Criticalopenviking: OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routesCVE-2026-35402Lowmcp-neo4j-cypher: Neo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL ProceduresCVE-2026-27197Criticalsentry: Sentry: Improper authentication on SAML SSO process allows user identity linkingCVE-2026-41488Lowlangchain-openai: langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebindingCVE-2026-41481Mediumlangchain-text-splitters: LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect BypassCVE-2026-41425Mediumauthlib: Authlib: Cross-site request forging when using cacheCVE-2026-41314Mediumpypdf: pypdf: Manipulated FlateDecode image dimensions can exhaust RAMCVE-2026-41313Mediumpypdf: pypdf: Possible long runtimes for wrong size values in incremental modeCVE-2026-41312Mediumpypdf: pypdf: Manipulated FlateDecode predictor parameters can exhaust RAMCVE-2026-40602Mediumhomeassistant-cli: Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templatesCVE-2026-41205HighMako: Mako: Path traversal via double-slash URI prefix in TemplateLookupCVE-2026-40256Mediumweblate: Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionCVE-2026-39845Mediumweblate: Weblate: SSRF via the webhook add-on using unprotected fetch_url()CVE-2026-34393Highweblate: Weblate: Privilege escalation in the user API endpointCVE-2026-34244Mediumweblate: Weblate: SSRF via Project-Level Machinery Configuration CVE-2026-34242Highweblate: Weblate: Arbitrary File Read via SymlinkCVE-2026-33440Mediumweblate: Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsCVE-2026-33435Highweblate: Weblate: Remote code execution during backup restoration

Stop the waste.
Protect your environment with Kodem.