PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27905Highbentoml: BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar ExtractionCVE-2026-28518Highopenviking: OpenViking contains a Path Traversal vulnerabilityCVE-2026-25673HighDjango: Django vulnerable to Uncontrolled Resource ConsumptionCVE-2026-25674LowDjango: Django has a Race Condition vulnerabilityCVE-2026-28804Mediumpypdf: pypdf vulnerable to inefficient decoding of ASCIIHexDecode streamsCVE-2026-28795Highopenchatbi: OpenChatBI has a Path Traversal Vulnerability in save_report ToolCVE-2026-2256Mediumms-agent: MS-Agent vulnerable to Command InjectionCVE-2026-28438Highcocoindex: CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statementsCVE-2026-28413MediumProducts.isurlinportal: Products.isurlinportal has possible open redirect when using more than 2 forward slashesCVE-2026-28350Mediumlxml-html-clean: lxml-html-clean has <base> tag injection through default Cleaner configurationCVE-2026-28348Mediumlxml-html-clean: lxml-html-clean has CSS @import Filter Bypass via Unicode EscapesCVE-2026-27932Highjoserfc: joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)CVE-2026-27622HighOpenEXR: OpenEXR's CompositeDeepScanLine integer-overflow leads to heap OOB writeCVE-2026-28416Highgradio: Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config ProcessingCVE-2026-28415Mediumgradio: Gradio has an Open Redirect in its OAuth FlowCVE-2026-28414Highgradio: Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+CVE-2026-28352Mediumindico: Indico has a missing access check in the event series management APICVE-2026-27167Lowgradio: Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session SecretCVE-2026-28351Mediumpypdf: pypdf: Manipulated RunLengthDecode streams can exhaust RAMGHSA-747P-WMPV-9C78Mediumawscli: AWS CLI: cli_history database does not restrict file permissions on Unix systemsCVE-2026-27966Criticallangflow: Langflow has Remote Code Execution in CSV AgentCVE-2026-28370Criticalvitrage: OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval InjectionCVE-2026-27948Mediumcopyparty: Copyparty vulnerable to reflected XSS via setck parameterCVE-2026-27839Mediumwger: wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookupCVE-2026-27838Lowwger: wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

Stop the waste.
Protect your environment with Kodem.