PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55379Highpillow: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadingCVE-2026-54060Highpillow: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`CVE-2026-54059Highpillow: Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF…CVE-2026-54058Highpillow: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)CVE-2026-55514Highvllm: vLLM denial of service via prompt embeds on M-RoPE modelsCVE-2026-28231Mediumpi-heif: pillow-heif: Integer Overflow in Encode Path Buffer Validation Leads to Heap Out-of-Bounds ReadCVE-2026-25527Mediumchangedetection.io: changedetection.io is vulnerable to unauthenticated static path traversalCVE-2025-67726Hightornado: Tornado: Quadratic DoS via Crafted Multipart ParametersCVE-2025-67725Hightornado: Tornado: Quadratic DoS via Repeated Header CoalescingCVE-2025-67724Mediumtornado: Tornado vulnerable to Header Injection and XSS via reason argumentCVE-2026-54559Mediumpocketsphinx: PocketSphinx: Buffer overflows in language and acoustic model loading codeGHSA-MFR4-MQ8W-VMG6Mediumproot-distro: PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container RootfsCVE-2026-54567HighFlask-Reuploaded: Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)CVE-2026-53598Highprompty: Prompty: Arbitrary file read via file reference expansionCVE-2026-54547Highmeta-ads-mcp: meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta TokenCVE-2026-54549Highmeta-ads-mcp: meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` FetchCVE-2026-54552Highsh: sh _uid does not drop supplementary groups (incomplete privilege drop)GHSA-8RQH-VXPR-X77PMediumplone.restapi: plone.restapi: Stored XSS by spoofing mime typeCVE-2026-54503Mediumplone.app.textfield: plone.app.textfield: Stored XSS by spoofing mime type CVE-2026-55646Mediumvllm: vLLM: Speech-to-text upload size limit is enforced after full UploadFile readCVE-2026-55574Highvllm: vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backendsCVE-2026-54234Highvllm: vLLM has Remote DoS via Invalid Recovered Token ReinjectionCVE-2026-34760Mediumvllm: vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio modelsCVE-2026-59950Highmcp: MCP Python SDK: WebSocket server transport does not support Host/Origin validationCVE-2026-52869Highmcp: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

Stop the waste.
Protect your environment with Kodem.