PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-23877Mediumswingmusic: Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin userCVE-2026-23842Highchatterbot: ChatterBot Vulnerable to Denial of Service via Database Connection Pool ExhaustionCVE-2025-68616Highweasyprint: WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP RedirectCVE-2026-22219Highchainlit: Chainlit contain a server-side request forgery (SSRF) vulnerabilityCVE-2026-26216CriticalCrawl4AI: Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks ParameterCVE-2026-26217Criticalcrawl4ai: Crawl4AI Has Local File Inclusion in Docker API via file:// URLsCVE-2026-23490Highpyasn1: pyasn1 has a DoS vulnerability in decoderCVE-2026-23535Highwlc: Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command CVE-2026-23528Mediumdistributed: Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and DashboardCVE-2025-68675Highapache-airflow: Apache Airflow proxy credentials for various providers might leak in task logsCVE-2025-68438Highapache-airflow: Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncatedCVE-2026-22779Mediumblacksheep: BlackSheep's ClientSession is vulnerable to CRLF injectionCVE-2026-21889Lowweblate: Weblate leaks information via screenshotsCVE-2025-68492Lowchainlit: Chainlit contains an authorization bypass vulnerabilityCVE-2026-22871Highguarddog: GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCECVE-2026-22870Highguarddog: GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoSCVE-2026-23949Highjaraco.context: jaraco.context Has a Path Traversal VulnerabilityCVE-2026-21226Highazure-core: Azure Core is vulnerable to deserialization of untrusted dataCVE-2026-22798Mediumhermes: hermes's raw options logging may disclose secrets passed in via subcommand options argumentCVE-2026-22777Highcomfy-cli: ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration HandlerCVE-2026-22702Mediumvirtualenv: virtualenv Has TOCTOU Vulnerabilities in Directory CreationCVE-2026-22701Mediumfilelock: filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLockCVE-2026-22773Mediumvllm: vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsCVE-2026-22251Mediumwlc: Weblate wlc has insecure API key configurationCVE-2026-22250Lowwlc: Weblate command-line client susceptible to SSL verification skip

Stop the waste.
Protect your environment with Kodem.