PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24747Highpytorch: PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint FilesCVE-2026-23892MediumOctoPrint: OctoPrint has Timing Side-Channel Vulnerability in API Key AuthenticationCVE-2026-1213Mediumaskbot: askbot inexhaustive permissions check allows any user to modify a different user's profile pictureCVE-2026-24688Mediumpypdf: pypdf has possible Infinite Loop when processing outlines/bookmarksCVE-2026-24490Highmobsf: MobSF has Stored XSS via Manifest Analysis - Dialer Code Host FieldCVE-2026-24489Mediumgakido: Gakido vulnerable to HTTP Header Injection (CRLF Injection) CVE-2026-24486Highpython-multipart: Python-Multipart has Arbitrary File Write via Non-Default ConfigurationCVE-2026-24408Lowsigstore: sigstore CSRF possibility in OIDC authentication during signingCVE-2025-11687Mediumgi-docgen: GI-DocGen vulnerable to Reflected XSS via unescaped query stringsCVE-2026-24123Highbentoml: BentoML has a Path Traversal via Bentofile ConfigurationCVE-2026-22696Criticaldcap-qvl: dcap-qvl has Missing Verification for QE IdentityCVE-2026-0994Highprotobuf: protobuf affected by a JSON recursion depth bypassCVE-2026-0770Highlangflow: Langflow affected by Remote Code Execution via validate_code() exec()CVE-2026-1260Highsentencepiece: Sentencepiece has a a heap overflow issueCVE-2025-67221Highorjson: orjson does not limit recursion for deeply nested JSON documentsCVE-2026-24130Lowmoonraker: Moonraker affected by LDAP search filter injectionCVE-2026-24049Highwheel: Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpackCVE-2026-24009Highdocling-core: docling-core vulnerable to Remote Code Execution via unsafe PyYAML usageCVE-2025-71176Mediumpytest: pytest has vulnerable tmpdir handlingCVE-2026-23996Lowfastapi-api-key: FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detectionCVE-2026-23986Mediumcopier: Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true CVE-2026-23968Mediumcopier: Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: falseCVE-2026-23946Mediumtendenci: Tendenci Affected by Authenticated Remote Code Execution via Pickle DeserializationCVE-2026-22807Highvllm: vLLM affected by RCE via auto_map dynamic module loading during model initializationCVE-2026-23833Mediumesphome: ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

Stop the waste.
Protect your environment with Kodem.