PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-28356Highmultipart: multipart vulnerable to ReDoS in `parse_options_header()`CVE-2026-32247Highgraphiti-core: Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filtersCVE-2026-32112Mediumha-mcp: ha-mcp has XSS via Unescaped HTML in OAuth Consent FormCVE-2026-32111Mediumha-mcp: ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracleCVE-2026-32109Lowcopyparty: Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`CVE-2026-32108Lowcopyparty: Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder accessCVE-2026-31958Hightornado: Tornado is vulnerable to DoS due to too many multipart partsCVE-2026-3060Criticalsglang: SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation moduleCVE-2026-3989Highsglang: SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserializationCVE-2026-3059Criticalsglang: SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ brokerGHSA-78CV-MQJ4-43F7Mediumtornado: Tornado has incomplete validation of cookie attributesCVE-2026-31826Mediumpypdf: pypdf: manipulated stream length values can exhaust RAMCVE-2026-31815Mediumdjango-unicorn: django-unicorn affected by component state manipulation via unvalidated attribute accessCVE-2026-27825Criticalmcp-atlassian: MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in…CVE-2026-27826Highmcp-atlassian: MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headersCVE-2026-26118HighAzure.Mcp: Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a networkCVE-2026-30974Mediumcopyparty: copyparty: volflag `nohtml` did not block javascript in svg filesCVE-2026-0846Highnltk: NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()CVE-2026-25960Mediumvllm: vLLM has SSRF Protection BypassCVE-2026-30930HighGlances: Glances has SQL Injection via Process Names in TimescaleDB ExportCVE-2026-30928Highglances: Glances Exposes Unauthenticated Configuration SecretsCVE-2025-69219Highapache-airflow-providers-http: Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperatorCVE-2026-25604Mediumapache-airflow-providers-amazon: Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication BypassGHSA-QR2G-P6Q7-W82MHigh@x402/svm: x402 SDK Security AdvisoryCVE-2026-33010Highmcp-memory-service: mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

Stop the waste.
Protect your environment with Kodem.