PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-69147Mediumvllm: vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationCVE-2026-77401MediumAccessControl: Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functionsCVE-2026-76825HighRestrictedPython: RestrictedPython vulnerable to sandbox escape via string.Formatter field resolutionCVE-2026-85078Mediumsanic: sanic chunked trailer request smuggling allows hidden second request executionCVE-2026-62949Mediumasyncssh: AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATIONCVE-2026-59823Mediumlitellm: LiteLLM Proxy has server-side request forgery via the `user_config` request parameterCVE-2026-57173Mediumvllm: vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completionsCVE-2026-61599Highdjust: djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount pathCVE-2026-61589Mediumdjust: djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on…CVE-2026-61596Highdjust: djust has broken object-level access control (IDOR)CVE-2026-61588Mediumdjust: djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute…CVE-2026-61594Criticaldjust: djust has an authorization bypass on the WebSocket/SSE mount pathCVE-2026-61591Highdjust: djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)CVE-2026-61592Highdjust: djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session…CVE-2026-61597Mediumdjust: djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tagsCVE-2026-61593Highdjust: djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE sessionCVE-2025-59953Criticallmdeploy: LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeployCVE-2026-61595Highdjust: djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' dataCVE-2026-61598Highdjust: djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handlerCVE-2026-61590Highdjust: djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only…CVE-2026-59178Criticalesphome-device-builder: ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgradeCVE-2026-59151Criticalprowler-cloud: Prowler: SAML Domain Claiming Enables Cross-Tenant Account TakeoverCVE-2026-59971Criticalmysql-mcp-server: MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)CVE-2026-88006Mediumopen-webui: Open WebUI: Users denied by the OAuth role policy can still sign in via token exchangeCVE-2026-87011Highopen-webui: Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

Stop the waste.
Protect your environment with Kodem.