PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-M8J6-RC5X-WV36Mediumnono-py: nono-py's policy JSON accepts unknown security fieldsGHSA-9J7F-3R4P-PWH6Mediumnono-py: nono-py vulnerable to authorization bypass / policy confusionCVE-2026-48797Criticalbackpropagate: Backpropagate: backprop ui --auth and backprop ui --share do not enforce authenticationGHSA-72W7-MF9G-733PMediumnono-py: nono-py has proxy-only network fallback bypass on older Linux kernelsCVE-2026-48782Mediumpydantic-ai-slim: pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)CVE-2026-55166Criticallemur: Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromiseCVE-2026-55165Mediumlemur: Lemur: JWT verifier honors attacker-supplied alg, enabling ATOCVE-2026-55164Mediumlemur: Lemur user-update path stores plaintext passwordsCVE-2026-55163Mediumlemur: Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>CVE-2026-55162Mediumlemur: Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRFCVE-2026-48508Highlemur: Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermissionCVE-2026-9291Highamazon-braket-sdk: amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()CVE-2026-48776Mediumlanggraph-sdk: LangGraph SDK has unsafe URL path constructionCVE-2026-48775Mediumlanggraph-checkpoint: LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loadingGHSA-JF6W-2MVX-633JMediumjusthtml: justhtml: to_markdown() code-span blank-line breakout enables XSSGHSA-W2J7-F3C6-G8CWMediumFlask-Security: Flask-Security has an Open Redirect issueGHSA-PHV5-334H-MXCWCriticalmotioneye: motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path TraversalGHSA-QXVG-H7Q2-HCXHCriticalmotioneye: motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)CVE-2026-55863Mediummotioneye: motionEye's missing authentication on ActionHandler allows unauthenticated camera action executionCVE-2026-55488Highmotioneye: motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File ReadCVE-2026-54134HighOctoPrint: OctoPrint has possible file exfiltration via query parameters on upload endpointsCVE-2026-53925Highglances: Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configurationCVE-2026-35163MediumOctoPrint: OctoPrint has XSS in its Suppressed Command NotificationsCVE-2026-48487Mediumzeroconf: zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packetCVE-2026-46611Mediumglances: Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Stop the waste.
Protect your environment with Kodem.