PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-34520Lowaiohttp: AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypassCVE-2026-34519Lowaiohttp: AIOHTTP has HTTP response splitting via \r in reason phraseCVE-2026-34518Lowaiohttp: AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirectCVE-2026-34517Lowaiohttp: AIOHTTP has late size enforcement for non-file multipart fields causes memory DoSCVE-2026-34516Mediumaiohttp: AIOHTTP has a Multipart Header Size BypassCVE-2026-34515Mediumaiohttp: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on WindowsCVE-2026-34514Lowaiohttp: AIOHTTP has CRLF injection through multipart part content type header constructionCVE-2026-34513Lowaiohttp: AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnectorCVE-2026-34452Mediumanthropic: Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox EscapeCVE-2026-34450Mediumanthropic: Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory ToolCVE-2026-34447Mediumonnx: ONNX: External Data Symlink TraversalCVE-2026-34446Mediumonnx: ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX loadGHSA-C65F-X25W-62JVMediumopenssl-encrypt: openssl-encrypt has CORS wildcard with allow_credentials=True in standalone serversGHSA-4RH7-JWG9-M28MMediumopenssl-encrypt: openssl-encrypt accepts refresh tokens as URL query parameters causing token leakageGHSA-2VHW-Q7VH-7XV2Mediumopenssl-encrypt: openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callersGHSA-HVC7-763R-4F3HMediumopenssl-encrypt: openssl-encrypt has no owner verification on key revocation — any client can revoke any keyGHSA-8H88-GXP3-J7PGMediumopenssl-encrypt: openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keysCVE-2026-34445Highonnx: ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.GHSA-5QVP-PR9F-2G2VMediumpoetry-plugin-tweak-dependencies-version: poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645GHSA-QC22-XMQ4-QG46Mediumc2cciutils: c2cciutils affected by CVE-2022-40896 CVE-2026-34222Highopen-webui: Open WebUI has Broken Access Control in Tool ValvesCVE-2026-22815Mediumaiohttp: aiohttp allows unlimited trailer headers, leading to possible uncapped memory usageCVE-2024-49048Hightorchgeo: TorchGeo Remote Code Execution VulnerabilityCVE-2026-34531MediumFlask-HTTPAuth: Flask-HTTPAuth invokes token verification callback when missing or empty token was given by clientGHSA-425G-FJHQ-5H92Mediumopenssl-encrypt: openssl-encrypt silently skips schema validation when jsonschema library is not installed

Stop the waste.
Protect your environment with Kodem.