poetry vulnerabilities
CVEs whose affected-version data names the poetry package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-41140LowPoetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
▾ Sunlitpoetry · poetryEPSS 0.29%via OSV
CVE-2026-34591Medium· 6.5Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
▾ Sunlitpoetry · poetryEPSS 0.47%via OSV