pypi
OSS Librariespackage-ecosystem
Latest CVEs
The 15 most recently published vulnerabilities affecting pypi.
- GHSA-39wr-7q6h-cf68LMDeploy has an SSRF bypass
- GHSA-xjw9-38cr-6372djust: A template binding inherits a context safety grant it never earned (XSS)
- GHSA-9395-2g46-rj3fdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
- GHSA-8423-8fgw-73vqtornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
- GHSA-wwv5-g3v4-889xTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
- GHSA-gqvg-gmmx-x4hmMLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
- GHSA-73p9-6hrp-8qhrAIIR verification and policy gates could report success without enforcing the control (fail-open)
- GHSA-x287-5c68-36wpOpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
- GHSA-93qj-5q5v-3c2hTrojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
- GHSA-vwf3-4xxj-qg6hmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
- GHSA-8cp3-qxj6-px34utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
- GHSA-ppx3-28rw-8fpfutcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
- GHSA-9qhg-99ww-9mqcutcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
- GHSA-jm5p-837g-rv8gWagtail: Improper restriction handling on Page translation API endpoint
- GHSA-x5cx-w6p2-mxf2Wagtail: Improper permission handling when copying snippets