PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-53012MediumMaterialX: MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack ExhaustionCVE-2025-53009MediumMaterialX: MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit CVE-2025-48074MediumOpenEXR: OpenEXR Out-Of-Memory via Unbounded File Header ValuesCVE-2025-48073MediumOpenEXR: OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" ModeCVE-2025-48072MediumOpenEXR: OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_executeCVE-2025-48071HighOpenEXR: OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked SizeCVE-2025-53011LowMaterialX: MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutputCVE-2025-53010LowMaterialX: MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput returnGHSA-R54C-2XMF-2CF3Mediumms-swift: MS SWIFT Deserialization RCE VulnerabilityCVE-2025-41419Mediumms-swift: MS SWIFT WEB-UI RCE VulnerabilityCVE-2025-50460Lowms-swift: MS SWIFT Remote Code Execution via unsafe PyYAML deserializationCVE-2025-54589Mediumcopyparty: copyparty Reflected XSS via Filter ParameterGHSA-3WWM-HJV7-23R3Mediumpyload-ng: Pyload log Injection via API /json/add_package in add_name parameterCVE-2025-54433Highbugsink: Bugsink path traversal via event_id in ingestionCVE-2025-54381Criticalbentoml: BentoML SSRF Vulnerability in File Upload Processing CVE-2025-54423Mediumcopyparty: copyparty has DOM-Based XSS vulnerability when displaying multimedia metadataCVE-2025-5120Criticalsmolagents: smolagents has Sandbox Escape Vulnerability in the local_python_executor.py ModuleCVE-2025-54413Highskops: Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load timeCVE-2025-54412Highskops: Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods ExecutionCVE-2025-55013Mediumassemblyline-service-client: Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code CVE-2025-7404Mediumcalibreweb: Calibre Web and Autocaliweb have OS Command Injection vulnerabilityCVE-2025-6998Highcalibreweb: Calibre Web and Autocaliweb have a ReDoS vulnerabilityCVE-2025-50481MediumMezzanine: Mezzanine CMS vulnerable to Cross-site ScriptingCVE-2025-54365Highfastapi-guard: FastAPI Guard has a regex bypassCVE-2025-51464Mediumaim: Aim vulnerable to Cross-site Scripting

Stop the waste.
Protect your environment with Kodem.