PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-3044Mediumllama-index-readers-papers: LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisionsCVE-2025-3262Mediumtransformers: Transformers vulnerable to ReDoS attack through its SETTING_RE variableCVE-2025-3108Mediumllama-index-core: LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer componentCVE-2025-53366Highmcp: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoSCVE-2025-53365Highmcp: MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of ServiceCVE-2025-48379Highpillow: Pillow vulnerability can cause write buffer overflow on BCn encodingCVE-2025-6855Lowlangchain-chatchat: Langchain-Chatchat vulnerable to path traversalCVE-2025-6854Lowlangchain-chatchat: Langchain-Chatchat vulnerable to path traversalCVE-2025-6853Lowlangchain-chatchat: Langchain-Chatchat has a Path Traversal vulnerabilityCVE-2025-6773Mediumlightrag-hku: HKUDS LightRAG allows Path Traversal via function upload_to_input_dirCVE-2024-54000Highmobsf: MobSF vulnerability allows SSRF due to the allow_redirects=True parameterCVE-2025-53002Highllamafactory: LLaMA-Factory allows Code Injection through improper vhead_file safeguardsCVE-2025-50213Criticalapache-airflow-providers-snowflake: Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperatorCVE-2025-6518Lowpyspur: pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode functionCVE-2025-2828Highlangchain-community: LangChain Community SSRF vulnerability exists in RequestsToolkit component CVE-2025-52558Highchangedetection.io: ChangeDetection.io XSS in watch overviewCVE-2025-52967Mediummlflow: MLFlow SSRF via gateway_proxy_handlerCVE-2025-52556Criticalrfc3161-client: rfc3161-client has insufficient verification for timestamp response signaturesCVE-2025-6279Lowupsonic: Upsonic has vulnerability in Pickle Handler component that can lead to deserializationCVE-2025-6278Lowupsonic: Upsonic is vulnerable to Path Traversal attack through its os.path.join functionCVE-2025-6272Lowpywasm3: pywasm3 has Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2025-50182Mediumurllib3: urllib3 does not control redirects in browsers and Node.jsCVE-2025-50181Mediumurllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiationCVE-2025-3248Criticallangflow: Langflow Unauth RCECVE-2025-6050MediumMezzanine: Mezzanine CMS has a Stored Cross-Site Scripting (XSS) vulnerability in the displayable_links_js function

Stop the waste.
Protect your environment with Kodem.