PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-73228Mediumdjangorestframework: Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies…CVE-2026-73229Mediumdjangorestframework: Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requestsGHSA-GQVG-GMMX-X4HMHighmlflow: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifactCVE-2026-55830HighRestrictedPython: RestrictedPython guard hooks can be shadowed via positional-only argumentsGHSA-73P9-6HRP-8QHRMediumaiir: AIIR verification and policy gates could report success without enforcing the control (fail-open)CVE-2026-55247Criticalplone.app.event: plone.app.event vulnerable to denial of service via iCalendar importCVE-2026-55228HighWeblate: Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private projectCVE-2026-55227Mediumweblate: Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookupsCVE-2026-55520HighProtego: Protego has exponential backtracking ReDoS in robots.txt URL wildcard matchingCVE-2026-55248Criticalplone.app.portlets: plone.app.portlets vulnerable to denial of service via RSS feed portletCVE-2026-55485Highpiccolo-admin: piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.CVE-2026-55509HighWsgiDAV: WsgiDAV MySQL provider has a blind SQL injectionCVE-2026-54757Highcompliance-trestle: Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted DataCVE-2026-55558Mediumaiosmtplib: aiosmtplib: STARTTLS response injectionCVE-2026-54770Mediumwebob: WebOb: Open redirect in Location header normalization via leading C0 control / space charactersCVE-2026-37004Criticallitellm: LiteLLM vulnerable to server-side template injection in the /prompts/test endpointCVE-2026-54591Highasyncssh: asyncssh has SCP Path Traversal to Arbitrary File WriteCVE-2026-54590Mediumasyncssh: asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly…CVE-2026-54569Criticalsenaite.core: senaite.core Vulnerable to Eval Injection and Missing AuthorizationGHSA-X287-5C68-36WPMediumopenwisp-ipam: OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's…GHSA-93QJ-5Q5V-3C2HCriticalpantheon-agents: Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)CVE-2026-54548Lowkas: kas Persistently Disables SSH Host Key CheckingCVE-2026-54553Mediumstarlette-admin: Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoSCVE-2026-54338Mediumjupyterhub: JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed LoginCVE-2026-55099Highicalendar: icalendar has Algorithmic Complexity in Equality

Stop the waste.
Protect your environment with Kodem.