py-rattler vulnerabilities
CVEs whose affected-version data names the py-rattler package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53956Medium· 5.4Rattler vulnerable to package cache path traversal via conda package build string
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…
▾ Sunlitconda · rattler_cacheEPSS 0.24%via CVEORG
CVE-2026-47425Mediumrattler has an entry-point path traversal in noarch:python install (arbitrary file write)
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
▾ Sunlitrattler · rattlerEPSS 0.20%via OSV