PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-71361Highpicklescan: Picklescan has a missing detection when calling built-in python idlelib.calltip.CalltipGHSA-CJ3C-V495-4XQHMediumpicklescan: Picklescan has a missing detection when calling built-in python code.InteractiveInterpreterGHSA-7CQ8-MJ8X-J263Mediumpicklescan: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completionsCVE-2025-71358Highpicklescan: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entityCVE-2025-71354Highpicklescan: Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItemGHSA-F54Q-57X4-JG88Mediumpicklescan: Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loadsGHSA-6VQJ-C2Q5-J97WMediumpicklescan: Picklescan has a missing detection when calling built-in python profile.Profile.runctxGHSA-X696-VM39-CP64Mediumpicklescan: Picklescan has a missing detection when calling built-in python profile.Profile.runGHSA-G344-HCPH-8VGGMediumpicklescan: Picklescan has a missing detection when calling built-in python trace.Trace.runctxGHSA-5QWP-399C-MJWFMediumpicklescan: Picklescan has a missing detection when calling built-in python trace.Trace.runCVE-2025-11058Highxml2rfc: xml2rfc has an arbitrary file read vulnerabilityCVE-2025-5302Highllama-index-core: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderGHSA-63CX-G855-HVV4Mediummitmproxy: mitmproxy binaries embed a vulnerable python-hyper/h2 dependencyCVE-2025-57804Mediumh2: h2 allows HTTP Request Smuggling due to illegal characters in headersCVE-2025-57809Highxgrammar: XGrammar affected by Denial of Service by infinite recursion grammarsCVE-2025-57760Highlangflow: Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)GHSA-VV6J-3G6G-2PVJMediumpicklescan: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_configGHSA-VR7H-P6MM-WPMHMediumpicklescan: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapperGHSA-H3QP-7FH3-F8H4Mediumpicklescan: Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlersGHSA-F745-W6JP-HPXXMediumpicklescan: Picklescan missing detection when calling pytorch function torch.utils.collect_env.runGHSA-F4X7-RFWP-V3XWMediumpicklescan: Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expressionGHSA-86CJ-95QR-2P4FMediumpicklescan: Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.getGHSA-4R9R-CH6F-VXMXMediumpicklescan: Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofileCVE-2025-57751Highpyload-ng: Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljsCVE-2025-9141Highvllm: vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

Stop the waste.
Protect your environment with Kodem.