PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-PQHF-P39G-3X64Mediumuv: uv allows ZIP payload obfuscation through parsing differentialsCVE-2025-64100Mediumckan: CKAN vulnerable to fixed session IDsCVE-2025-11200Highmlflow: MLflow Weak Password Requirements Authentication Bypass VulnerabilityCVE-2025-11201Highmlflow: MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution VulnerabilityCVE-2025-62801Mediumfastmcp: FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_nameCVE-2025-62800Mediumfastmcp: FastMCP vulnerable to reflected XSS in client's callback pageGHSA-C2JP-C369-7PVXHighfastmcp: FastMCP Auth Integration Allows for Confused Deputy Account TakeoverCVE-2025-54384Mediumckan: CKAN vulnerable to stored XSS in resource descriptionCVE-2025-12058Mediumkeras: Keras is vulnerable to arbitrary local file loading and Server-Side Request ForgeryCVE-2025-62727Highstarlette: Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``CVE-2025-10282Mediumbbot: BBOT's gitlab.py exposes globally configured "gitlab" API keyCVE-2025-61385Highpg8000: pg8000 SQL injection vulnerability via a specially crafted Python list inputCVE-2025-8709Highlanggraph-checkpoint-sqlite: LangGraph's SQLite store implementation has a SQL Injection VulnerabilityCVE-2025-62708Mediumpypdf: pypdf can exhaust RAM via manipulated LZWDecode streamsCVE-2025-62707Mediumpypdf: pypdf possibly loops infinitely when reading DCT inline images without EOF markerCVE-2025-62611Highaiomysql: aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL serverGHSA-CQ46-M9X9-J8W2Mediumscapy: Scapy Session Loading Vulnerable to Arbitrary Code Execution via Untrusted Pickle DeserializationCVE-2025-11844Mediumsmolagents: Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f functionCVE-2025-62607Mediumnautobot-ssot: Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URLGHSA-W476-P2H3-79G9Lowuv: uv has differential in tar extraction with PAX headersCVE-2025-62528Mediumtaguette: Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document descriptionCVE-2025-62527Hightaguette: Taguette password reset link poisoningCVE-2025-49655Criticalkeras: Keras framework vulnerable to deserialization of untrusted dataCVE-2025-62515Criticalpyquokka: pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer CVE-2025-11849Mediummammoth: Mammoth is vulnerable to Directory Traversal

Stop the waste.
Protect your environment with Kodem.