PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-22033Highlabel-studio: Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys fieldCVE-2025-68472HighMindsDB: MindsDB has improper sanitation of filepath that leads to information disclosure and DOSCVE-2025-14279Highmlflow: MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validationCVE-2025-15506Lowopencolorio: AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerabilityCVE-2025-15504Lowlief: LIEF is vulnerable to segmentation faultCVE-2026-22584Criticaluni2ts: Salesforce Uni2TS has a Code Injection vulnerabilityCVE-2026-22612Highfickling: Fickling vulnerable to detection bypass due to "builtins" blindnessCVE-2026-22609Highfickling: Fickling has Static Analysis Bypass via Incomplete Dangerous Module BlocklistCVE-2026-22608Highfickling: Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detectionCVE-2026-22607Highfickling: Fickling Blocklist Bypass: cProfile.run()CVE-2026-22606Highfickling: Fickling has a bypass via runpy.run_path() and runpy.run_module()CVE-2026-22691Lowpypdf: pypdf has possible long runtimes for malformed startxrefCVE-2026-22690Lowpypdf: pypdf has possible long runtimes for missing /Root object with large /Size valuesCVE-2025-68158Mediumauthlib: Authlib has 1-click Account Takeover vulnerabilityGHSA-MCMC-2M55-J8JJHighvllm: vLLM introduced enhanced protection for CVE-2025-62164CVE-2026-21874Mediumnicegui: NiceGUI has Redis connection leak via tab storage causes service degradationCVE-2026-21873Highnicegui: NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSSCVE-2026-21872Mediumnicegui: NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided linksCVE-2026-21871Mediumnicegui: NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()CVE-2026-21860MediumWerkzeug: Werkzeug safe_join() allows Windows special device names with compound extensionsCVE-2026-53872Highpicklescan: picklescan has Arbitrary file read using `io.FileIO` CVE-2025-15346Criticalwolfssl: wolfSSL Python module vulnerable to Improper AuthenticationCVE-2023-7333Mediumrecords-mover: records-mover Injection vulnerabilityCVE-2026-22041Lowloggingredactor: loggingredactor converts non-string types to string types in logsCVE-2026-21441Highurllib3: Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

Stop the waste.
Protect your environment with Kodem.