streamlit vulnerabilities
CVEs whose affected-version data names the streamlit package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-10804Low· 3.6Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
▾ Sunlitstreamlit · streamlitEPSS 0.08%via OSV
CVE-2026-33682Medium· 4.7Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
▾ Sunlitstreamlit · streamlitEPSS 0.28%via OSV