PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-3RCM-VJRC-P45JMediumjusthtml: JustHTML has a Sanitizer Bypass (in Markdown)GHSA-QVC2-MG72-JJHXMediumjusthtml: JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)GHSA-RF74-V2FM-23PWMediumnltk: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoSCVE-2026-33155Highdeepdiff: DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORTCVE-2026-33154Highdynaconf: dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja ResolverCVE-2026-33057Criticalmesop: Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-pyCVE-2026-33054Criticalmesop: Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/DeletionCVE-2026-33140Mediumpyspector: Stored XSS in PySpector HTML Report Generation leads to Javascript Code ExecutionCVE-2026-33139Highpyspector: PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code ExecutionCVE-2026-33123Mediumpypdf: pypdf has inefficient decoding of array-based streamsCVE-2026-33125Highfrigate: Frigte has broken access control viewer user can delete admin and other users accountCVE-2026-32875Highujson: UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loopCVE-2026-32874Highujson: UltraJSON has a Memory Leak parsing large integers allows DoS CVE-2026-33053Highlangflow: Langflow is Missing Ownership Verification in API Key Deletion (IDOR)CVE-2026-32981Highray: Ray Dashboard is vulnerable to path traversal through its static file handling mechanismCVE-2026-4269Mediumbedrock-agentcore-starter-toolkit: Improper S3 ownership verification in Bedrock AgentCore Starter ToolkitCVE-2026-4270Mediumawslabs.aws-api-mcp-server: AWS API MCP File Access Restriction BypassCVE-2026-33017Criticallangflow: Unauthenticated Remote Code Execution in Langflow via Public Flow Build EndpointCVE-2026-30922Highpyasn1: Denial of Service in pyasn1 via Unbounded RecursionGHSA-V7CF-C9RM-WM3JHighjusthtml: Uncontrolled recursion DoS in JustHTML() via deeply nested HTMLCVE-2026-30911Highapache-airflow: Apache Airflow: Execution API HITL Endpoints Missing Per-Task AuthorizationCVE-2026-28779Highapache-airflow: Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applicationsCVE-2026-28563Mediumapache-airflow: Apache Airflow: DAG authorization bypassCVE-2026-26929Highapache-airflow: Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks MetadataCVE-2026-32722Lowmemray: Stored XSS in Memray-generated HTML reports via unescaped command-line metadata

Stop the waste.
Protect your environment with Kodem.