PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-35490Criticalchangedetection.io: changedetection.io Vulnerable to Authentication Bypass via Decorator OrderingCVE-2026-35492Mediumkedro-datasets: kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file writeCVE-2026-26981MediumOpenEXR: OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cppCVE-2025-64183MediumOpenEXR: OpenEXR has use after free in PyObject_StealAttrStringCVE-2025-64182MediumOpenEXR: OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()CVE-2025-64181LowOpenEXR: OpenEXR Makes Use of Uninitialized MemoryCVE-2026-5559Lowpyblade: PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.pyCVE-2026-35464Highpyload-ng: pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for…CVE-2026-35463Highpyload-ng: pyLoad: Improper Neutralization of Special Elements used in an OS CommandCVE-2026-35459Criticalpyload-ng: pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992)CVE-2026-40072Mediumweb3: web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handlingCVE-2026-30762Highlightrag-hku: LightRAG: Hardcoded JWT Signing Secret Allows Authentication BypassCVE-2026-35187Highpyload-ng: pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameterCVE-2026-35044Highbentoml: BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile GenerationCVE-2026-35043Highbentoml: BentoML: Command Injection in cloud deployment setup scriptCVE-2026-35030Criticallitellm: LiteLLM: Authentication bypass via OIDC userinfo cache key collisionCVE-2026-35029Highlitellm: LiteLLM: Privilege escalation via unrestricted proxy configuration endpointCVE-2026-34824Highmesop: Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of ServiceCVE-2026-34755Mediumvllm: vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 ProcessingCVE-2026-34753Mediumvllm: vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `CVE-2026-34543Highopenexr: OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)CVE-2026-34544Highopenexr: OpenEXR: integer overflow to OOB write in uncompress_b44_impl()CVE-2026-34052Mediumjupyterhub-ltiauthenticator: LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)CVE-2026-33752Highcurl_cffi: curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)CVE-2026-33709Mediumjupyterhub: JupyterHub has an Open Redirect Vulnerability

Stop the waste.
Protect your environment with Kodem.