PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32634HighGlances: Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed ServersCVE-2026-32633CriticalGlances: Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`CVE-2026-32632MediumGlances: Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS RebindingCVE-2026-32611HighGlances: Glances has a SQL Injection in DuckDB Export via Unparameterized DDL StatementsCVE-2026-32610HighGlances: Glances's Default CORS Configuration Allows Cross-Origin Credential TheftCVE-2026-32609HighGlances: Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP CredentialsCVE-2026-32608HighGlances: Glances has a Command Injection via Process Names in Action Command TemplatesCVE-2026-32596HighGlances: Glances exposes the REST API without authenticationCVE-2026-28500Highonnx: ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain AttackCVE-2026-27459Highpyopenssl: pyOpenSSL DTLS cookie callback buffer overflowCVE-2026-28498Highauthlib: Authlib: Fail-Open Cryptographic Verification in OIDC Hash BindingCVE-2026-4229Mediumvanna: Vanna has a SQL injection in the remove_training_data functionCVE-2025-14287Highmlflow: MLflow has a command injection in mlflow/sagemaker/__init__.pyCVE-2026-28490Highauthlib: Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding OracleCVE-2026-27962Criticalauthlib: Authlib JWS JWK Header Injection: Signature Verification BypassCVE-2026-27448Lowpyopenssl: pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callbackCVE-2025-69196Highfastmcp: FastMCP OAuth Proxy token reuse across MCP serversGHSA-5CXW-W2XG-2M8HMediumfickling: fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE`GHSA-R48F-3986-4F9CMediumfickling: fickling modules linecache, difflib and gc are missing from the unsafe modules blocklistCVE-2026-32640Highsimpleeval: SimpleEval: Objects (including modules) can leak dangerous modules through to direct access inside the sandboxCVE-2026-32597HighPyJWT: PyJWT accepts unknown `crit` header extensionsGHSA-CWXJ-RR6W-M6W7HighScrapy: Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddlewareCVE-2026-31899HighCairoSVG: CairoSVG vulnerable to Exponential DoS via recursive <use> element amplificationCVE-2026-32116Highmagic-wormhole: Magic Wormhole: "wormhole receive" allows arbitrary local file overwriteCVE-2026-32274Highblack: Black: Arbitrary file writes from unsanitized user input in cache file name

Stop the waste.
Protect your environment with Kodem.