conda-forge
OSS Librariesoss-project
Latest CVEs
The 9 most recently published vulnerabilities affecting conda-forge.
- CVE-2026-46699conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository7.6
- CVE-2025-49824conda-smithy Insecure Encryption Vulnerable to Oracle Padding Attack
- CVE-2025-49843conda-smithy Has Incorrect Default File Permissions
- CVE-2025-49842conda-forge-webservices Privilege Escalation Risk via Default Docker Root User
- CVE-2025-49598conda-forge-ci-setup Allows Arbitrary Code Execution via Insecure Version Parsing
- CVE-2025-35471conda-forge openssl-feedstock writable OPENSSLDIR7.3
- CVE-2025-32784conda-forge-webservices has an Unauthorized Artifact Modification Race Condition
- CVE-2025-31484conda-forge infrastructure uses a bad token for Azure's cf-staging access
- CVE-2025-27510RCE in the package conda-forge-metadata