PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-61492Criticalterminal-controller: terminal-controller-mcp vulnerable to Command InjectionCVE-2026-21892Mediumparsl: Parsl Monitoring Visualization Vulnerable to SQL InjectionCVE-2026-21883Mediumbokeh: Bokeh server applications have Incomplete Origin Validation in WebSocketsCVE-2026-21851Mediummonai: MONAI has Path Traversal (Zip Slip) in NGC Private Bundle DownloadCVE-2025-69230Lowaiohttp: AIOHTTP Vulnerable to Cookie Parser Warning StormCVE-2025-69229Mediumaiohttp: AIOHTTP vulnerable to DoS through chunked messagesCVE-2025-69228Mediumaiohttp: AIOHTTP vulnerable to denial of service through large payloadsCVE-2025-69227Mediumaiohttp: AIOHTTP vulnerable to DoS when bypassing assertsCVE-2025-69226Lowaiohttp: AIOHTTP vulnerable to brute-force leak of internal static file path componentsCVE-2025-69225Lowaiohttp: AIOHTTP has unicode match groups in regexes for ASCII protocol elementsCVE-2025-69224Lowaiohttp: AIOHTTP's unicode processing of header values could cause parsing discrepanciesCVE-2025-69223Highaiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombCVE-2026-21439Lowbadkeys: badkeys vulnerable to ASCII control character injection on console via malformed inputCVE-2026-21445Highlangflow-base: Langflow Missing Authentication on Critical API EndpointsCVE-2025-11157Highfeast: Feast vulnerable to Deserialization of Untrusted DataCVE-2025-68131Mediumcbor2: CBORDecoder reuse can leak shareable values across decode callsCVE-2025-69277Mediumparagonie/sodium_compat: libsodium has Incomplete List of Disallowed InputsGHSA-46H3-79WF-XR6CHighpicklescan: Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetterGHSA-955R-X9J8-7RHHHighpicklescan: Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcallerCVE-2025-71339Mediumpicklescan: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_lengthGHSA-RRXM-2PVV-M66XHighpicklescan: Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoefGHSA-CFFC-MXRF-MHH4Mediumpicklescan: Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_evalGHSA-3329-GHMP-JMV5Highpicklescan: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myevalGHSA-X843-G5MX-G377Highpicklescan: Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcallerGHSA-R8G5-CGF2-4M4MHighpicklescan: Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef

Stop the waste.
Protect your environment with Kodem.