PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-5R2P-PJR8-7FH7Highsagemaker: SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionalityCVE-2026-30244Highplane: Plane is Vulnerable to Unauthenticated Workspace Member Information DisclosureCVE-2026-30242Highplane: Plane has SSRF via Incomplete IP Validation in Webhook URL SerializerCVE-2026-29787Mediummcp-memory-service: mcp-memory-service Vulnerable to System Information Disclosure via Health EndpointCVE-2025-45691Highragas: RAGAS has an Arbitrary File Read vulnerabilityCVE-2026-28277Mediumlanggraph: LangGraph checkpoint loading has unsafe msgpack deserializationCVE-2026-25048Highxgrammar: xgrammar vulnerable to DoS via multi-layer nestingCVE-2025-69534MediumMarkdown: Python-Markdown has an Uncaught ExceptionCVE-2026-27982Mediumdjango-allauth: django-allauth has an open redirect vulnerabilityCVE-2026-29790Lowdbt-common: dbt-common's commonprefix() doesn't protect against path traversalCVE-2026-29778Highpyload-ng: pyLoad has an Arbitrary File Write via Path Traversal in edit_package()CVE-2026-29780Mediumeml-parser: eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File WriteCVE-2026-0847Highnltk: NLTK has a Path Traversal issueGHSA-5HWF-RC88-82XMHighfickling: Fickling missing RCE-capable modules in UNSAFE_IMPORTSGHSA-WCCX-J62J-R448Highfickling: Fickling has `always_check_safety()` bypass: pickle.loads and _pickle.loads remain unhookedCVE-2026-29065Highchangedetection.io: changedetection.io has Zip Slip vulnerability in the backup restore functionalityCVE-2026-29039Highchangedetection.io: changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()CVE-2026-29038Mediumchangedetection.io: changedetection.io has Reflected XSS in its RSS Tag Error ResponseCVE-2026-28802Highauthlib: Authlib: Setting `alg: none` and a blank signature appears to bypass signature verificationCVE-2026-28681Highirrd: IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email linksGHSA-G38G-8GR9-H9XPCriticalpicklescan: PickleScan has multiple stdlib modules with direct RCE not in blocklistCVE-2026-3490Criticalpicklescan: PickleScan's pkgutil.resolve_name has a universal blocklist bypassCVE-2026-53873Criticalpicklescan: PickleScan's profile.run blocklist mismatch allows exec() bypassCVE-2026-28223Mediumwagtail: Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interfaceCVE-2026-28222Mediumwagtail: Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes

Stop the waste.
Protect your environment with Kodem.