PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-1777Highsagemaker: SageMaker Python SDK has Exposed HMACCVE-2026-1778Highsagemaker: SageMaker Python SDK has Insecure TLS ConfigurationCVE-2026-25505Criticalbambuddy: Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require AuthenticationGHSA-M7J5-R2P5-C39RMediumpicklescan: picklescan vulnerable to arbitrary file create using logging.FileHandlerCVE-2026-53874Highpicklescan: picklescan missing detection by simple obfuscation of a `builtins.eval` callCVE-2026-25481Criticallangroid: Langroid has WAF Bypass Leading to RCE in TableChatAgentCVE-2026-22778Criticalvllm: vLLM has RCE In Video ProcessingCVE-2025-69207Mediumkhoj: Khoj has an IDOR in Notion OAuth Flow that Enables Index PoisoningCVE-2026-1703Lowpip: pip Path Traversal vulnerabilityCVE-2024-5986Criticalai.h2o:h2o-core: H2O has an External Control of File Name or Path vulnerabilityCVE-2026-0599Hightext-generation: Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource ConsumptionCVE-2025-6208Mediumllama-index-core: llama-index-core vulnerable to Uncontrolled Resource ConsumptionCVE-2026-1117Highlollms: Lollms has an Improper Access Control vulnerabilityCVE-2025-10279Highmlflow: mlflow Creates of Temporary File in Directory with Insecure PermissionsCVE-2025-62349Highsalt: Salt Authentication Protocol Version Downgrade Allows Minion ImpersonationCVE-2025-62348Highsalt: Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML PayloadCVE-2025-69662Highgeopandas: geopandas SQL Injection Vulnerability in to_postgis() Allows Information DisclosureCVE-2026-25130Criticalcai-framework: CAI find_file Agent Tool has Command Injection Vulnerability Through Argument InjectionCVE-2026-25211Lowllama-stack: Llama Stack exposes secret in initialization logGHSA-VG9H-JX4V-CWX2Criticaldfir-unfurl: Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)CVE-2026-40036Highdfir-unfurl: Unfurl's unbounded zlib decompression allows decompression bomb DoSCVE-2026-24780Highagpt: AutoGPT is Vulnerable to RCE via Disabled Block ExecutionCVE-2020-36962Mediumtendenci: Tendenci is Vulnerable to CSV Formula Injection through its Contact Form Message Field CVE-2026-24779Highvllm: vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnectorGHSA-GPX9-96J6-PP87Mediumagentos-taskweaver: TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF)

Stop the waste.
Protect your environment with Kodem.