PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24708HighNova: OpenStack Nova calls qemu-img without format restrictions for resize CVE-2025-14009Criticalnltk: NLTK has a Zip Slip VulnerabilityCVE-2026-53875Highpicklescan: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBERCVE-2026-2654Lowsmolagents: Hugging Face Smolagents has a Server-Side Request Forgery issueCVE-2025-33253Highnemo-toolkit: NVIDIA NeMo Framework Deserializes Untrusted DataCVE-2025-33245Highnemo-toolkit: NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code executionCVE-2026-26057Mediumcisco-ai-skill-scanner: Skill-scanner Unsecured Network Binding VulnerabilityCVE-2026-25739Mediumindico: Indico Affected by Cross-Site-Scripting via material uploadsCVE-2026-25738Mediumindico: Indico has Server-Side Request Forgery (SSRF) in multiple placesCVE-2026-24126MediumWeblate: Weblate has an argument injection in management consoleCVE-2026-25087Highpyarrow: Apache Arrow: Potential use-after-free when reading IPC file with pre-bufferingCVE-2026-2415Highpretix: pretix unsafely evaluates variables in emailsCVE-2026-2531LowMindsDB: MindsDB affected by a SSRF vulnerabilityGHSA-27JP-WM6Q-GP25Mediumsqlparse: sqlparse: formatting list of tuples leads to denial of serviceCVE-2025-69872Mediumdiskcache: DiskCache has unsafe pickle deserializationCVE-2026-26013Lowlangchain-core: LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messagesCVE-2026-25990Highpillow: Pillow affected by out-of-bounds write when loading PSD imagesCVE-2026-26007Highcryptography: cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT CurvesCVE-2026-21531Criticalazure-ai-language-conversations-authoring: Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCECVE-2026-25577Highemmett-core: Emmett-Core: Unhandled CookieError Exception Causing Denial of ServiceCVE-2026-25528Mediumlangsmith: LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header InjectionCVE-2026-25480Mediumlitestar: Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)CVE-2026-25479Mediumlitestar: Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patternsCVE-2026-25478Highlitestar: Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed originsCVE-2026-22922Mediumapache-airflow: Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

Stop the waste.
Protect your environment with Kodem.