PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-39373Mediumjwcrypto: JWCrypto: JWE ZIP decompression bombCVE-2026-39376Highfastfeedparser: FastFeedParser has an infinite redirect loop DoS via meta-refresh chainGHSA-R758-8HXW-4845Lowjusthtml: justhtml: Mutation XSS with custom foreign-namespace sanitization policiesCVE-2026-35592Mediumpyload-ng: pyload-ng: Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix BypassCVE-2026-35586Mediumpyload-ng: pyload-ng: Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ngGHSA-69X8-HRGQ-FJJ8Highlitellm: LiteLLM: Password hash exposure and pass-the-hash authentication bypassGHSA-89GG-P5R5-Q6R4Highmonai: MONAI: Unsafe functions lead to pickle deserialization rceCVE-2026-22680MediumOpenViking: OpenViking contains a missing authorization vulnerability in the task polling endpointsCVE-2026-34444Highlupa: Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattrCVE-2026-4277LowDjango: Django vulnerable to privilege abuse in GenericInlineModelAdminCVE-2026-3902HighDjango: Django vulnerable to ASGI header spoofing via underscore/hyphen conflationCVE-2026-4292LowDjango: Django vulnerable to privilege abuse in ModelAdmin.list_editableCVE-2026-33034HighDjango: Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limitCVE-2026-33033MediumDjango: Django has potential DoS via MultiPartParser through crafted multipart uploadsCVE-2026-33866Mediummlflow: MLflow is vulnerable to an authorization bypass affecting the AJAX endpointCVE-2026-33865Mediummlflow: MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interfaceCVE-2026-1114Criticallollms: LoLLMs is vulnerable to Improper Access Control through weak secret keyCVE-2026-1839Mediumtransformers: HuggingFace Transformers allows for arbitrary code execution in the `Trainer` classCVE-2026-35615CriticalPraisonAI: PraisonAI Has Path Traversal in FileToolsCVE-2026-39308HighPraisonAI: PraisonAI recipe registry publish path traversal allows out-of-root file writeCVE-2026-39306HighPraisonAI: PraisonAI recipe registry pull path traversal writes files outside the chosen output directoryCVE-2026-39305CriticalPraisonAI: PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action OrchestratorCVE-2026-39307HighPraisonAI: PraisonAI Has Arbitrary File Write (Zip Slip) in Templates ExtractionCVE-2026-35526Highstrawberry-graphql: strawberry-graphql: Denial of Service via unbounded WebSocket subscriptionsCVE-2026-35523Highstrawberry-graphql: strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol

Stop the waste.
Protect your environment with Kodem.