PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33220Mediumweblate: Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryCVE-2026-33214Mediumweblate: Weblate: Improper access control for the translation memory in APICVE-2026-33212Lowweblate: Weblate: Improper access control for pending tasks in APICVE-2026-31987Mediumapache-airflow: Apache Airflow: JWT token appearing in logsCVE-2025-54550Highapache-airflow: Apache Airflow: RCE by race condition in example_xcom dagCVE-2026-40353Mediumwger: wger has Stored XSS via Unescaped License Attribution FieldsCVE-2026-40474Highwger: wger has Broken Access Control in Global Gym Configuration Update EndpointCVE-2026-54334Criticaluefi-firmware: UEFI Firmware Parser has a heap out-of-bounds write in tiano decompressor ReadCLenCVE-2026-54333Criticaluefi-firmware: UEFI Firmware Parser has a stack out-of-bounds write in tiano decompressor MakeTableCVE-2026-40594Mediumpyload-ng: pyLoad has a Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)CVE-2026-41182Mediumlangsmith: LangSmith SDK: Streaming token events bypass output redactionCVE-2026-41206Mediumpyspector: PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_codeCVE-2026-40347Mediumpython-multipart: python-multipart affected by Denial of Service via large multipart preamble or epilogue dataCVE-2026-41168Mediumpypdf: pypdf has long runtimes for wrong size values in cross-reference and object streamsCVE-2026-30625Criticalupsonic: Upsonic: remote code execution vulnerability in its MCP server/task creation functionalityCVE-2026-25219Mediumapache-airflow: Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view accessGHSA-FJ52-5G4H-GMQ8Lowpyload-ng: pyLoad's Session Not Invalidated After Permission ChangesCVE-2026-41133Highpyload-ng: pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)CVE-2026-40320Mediumgiskard-checks: Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheckCVE-2026-40319Lowgiskard-checks: Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching CheckCVE-2026-40683Highkeystone: OpenStack Keystone: LDAP identity backend does not convert enabled attribute to booleanGHSA-4P64-V8F5-R2GXLowjusthtml: Multiple security fixes in justhtmlCVE-2026-40491Mediumgdown: gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractallCVE-2026-40606Mediummitmproxy: mitmproxy has an LDAP InjectionCVE-2026-40576Criticalexcel-mcp-server: excel-mcp-server has a Path Traversal issue

Stop the waste.
Protect your environment with Kodem.