PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-VFGX-5Q85-58Q3Mediumopenssl-encrypt: openssl-encrypt has non-cryptographic PRNG used for steganography pixel selectionGHSA-H3M5-P59H-X88PMediumopenssl-encrypt: openssl-encrypt has visible password in process list via --password CLI argumentGHSA-H45M-MGCP-Q388Criticalopenssl-encrypt: openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restartGHSA-J48Q-4C78-RHF9Mediumopenssl-encrypt: openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verificationCVE-2026-34400Mediumalerta-server: alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) APICVE-2026-34203Lownautobot: Nautobot: Management of users via REST API does not apply configured password validatorsCVE-2026-32871Criticalfastmcp: FastMCP OpenAPI Provider has an SSRF & Path Traversal VulnerabilityCVE-2026-32727Highscitokens: SciTokens has an Authorization Bypass via Path Traversal in Scope ValidationCVE-2026-32716Highscitokens: SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix CheckingCVE-2026-32714Criticalscitokens: SciTokens is vulnerable to SQL Injection in KeyCacheCVE-2026-27489Highonnx: onnx Vulnerable to Path Traversal via SymlinkCVE-2026-27124Highfastmcp: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy VulnerabilitiesCVE-2025-64340Mediumfastmcp: FastMCP has a Command Injection vulnerability - Gemini CLICVE-2026-0596Criticalmlflow: Mlflow: Command Injection when serving models with enable_mlserver=TrueCVE-2026-34881Mediumglance: OpenStack Glance is affected by Server-Side Request Forgery (SSRF)CVE-2026-32794Mediumapache-airflow: Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token ExchangeGHSA-955R-262C-33JCCriticaltelnyx: Telnyx has malicious code in PyPI versions 4.87.1 and 4.87.2CVE-2026-34231Mediumslippers: Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template TagCVE-2026-33641HighGlances: Glances Vulnerable to Command Injection via Dynamic Configuration ValuesCVE-2026-33533HighGlances: Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS WildcardCVE-2025-15379Criticalmlflow: MLflow Command Injection vulnerabilityCVE-2025-15036Criticalmlflow: MLFlow path traversal vulnerabilityGHSA-7FQQ-Q52P-2JJGMediumopencc: OpenCC has an Out-of-bounds read when processing truncated UTF-8 inputCVE-2026-34172Highgiskard-agents: Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 EnvironmentCVE-2026-33045Lowhomeassistant: Home Assistant has stored XSS in history-graphs

Stop the waste.
Protect your environment with Kodem.