VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-15827None
3w ago

Malicious code in company-sdk (PyPI)

Malicious code in company-sdk (PyPI)

▾ Sunlitcompany-sdk · company-sdkvia OSV
CVE-2026-53720Medium
3w ago

pymonocypher uses cython to wrap the Monocypher C library

pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, t…

▾ Sunlitpymonocypher · pymonocypherEPSS 0.18%via NVD
CVE-2026-84452High
3w ago

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…

▾ Twilightwinml-cli · winml-cliEPSS 1.6%via NVD
CVE-2026-84382High· 7.5
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…

▾ Twilighthttpx2 · httpx2EPSS 0.63%via NVD
CVE-2026-84380Medium· 5.6
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…

▾ Sunlithttpx2 · httpx2EPSS 0.36%via NVD
CVE-2026-84379Medium· 5.3
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…

▾ Sunlithttpx2 · httpx2EPSS 0.45%via NVD
CVE-2026-84378Medium· 5.9
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-contr…

▾ Sunlithttpx2 · httpx2EPSS 0.53%via NVD
CVE-2026-32773Medium· 6.1
3w ago

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encourag…

▾ Sunlitapache · sparkEPSS 0.68%via NVD
CVE-2026-84381High· 8.1
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a…

▾ Twilighthttpcore2 · httpcore2EPSS 0.11%via NVD
CVE-2026-12876Medium
3w ago

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

▾ Sunlitnltk · nltkvia OSV
CVE-2026-84366High· 7.4
3w ago

Scrapy is a high-level web crawling and scraping framework for Python

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to th…

▾ Twilightscrapy · scrapyEPSS 0.25%via NVD
MAL-2026-15811None
3w ago

Malicious code in syswatch (PyPI)

Malicious code in syswatch (PyPI)

▾ Sunlitsyswatch · syswatchvia OSV
MAL-2026-15810Critical⚠ Exploited
3w ago

Malicious code in gcphelpit (PyPI)

Malicious code in gcphelpit (PyPI)

▾ Abyssalgcphelpit · gcphelpitvia OSV
MAL-2026-15809None
3w ago

Malicious code in tallyboxlite (PyPI)

Malicious code in tallyboxlite (PyPI)

▾ Sunlittallyboxlite · tallyboxlitevia OSV
CVE-2026-84305Medium
3w ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/…

▾ Sunlitsqlparse · sqlparseEPSS 0.18%via NVD
CVE-2026-84309Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-84311Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-84310Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
GHSA-wwv5-g3v4-889xLow
3w ago

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_…

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

▾ Sunlittornado · tornadovia OSV
GHSA-8423-8fgw-73vqMedium
3w ago

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

▾ Sunlittornado · tornadovia OSV
GHSA-gqvg-gmmx-x4hmHigh· 8.8
3w ago

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

▾ Twilightmlflow · mlflowvia GHSA
CVE-2026-82398Medium· 5.3
4w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…

▾ Sunlitpypdf · pypdfEPSS 0.52%via NVD
CVE-2026-82397High· 7.5
4w ago

Tornado is a Python web framework and asynchronous networking library

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. Reques…

▾ Twilighttornado · tornadoEPSS 0.63%via NVD
MAL-2026-15603Critical⚠ Exploited
4w ago

Malicious code in pyservercheck (PyPI)

Malicious code in pyservercheck (PyPI)

▾ Abyssalpyservercheck · pyservercheckvia OSV
MAL-2026-15588None
4w ago

Malicious code in tronlinker (PyPI)

Malicious code in tronlinker (PyPI)

▾ Sunlittronlinker · tronlinkervia OSV
MAL-2026-15578None
4w ago

Malicious code in trongridor (PyPI)

Malicious code in trongridor (PyPI)

▾ Sunlittrongridor · trongridorvia OSV
MAL-2026-15577None
4w ago

Malicious code in auth-app-streamlit (PyPI)

Malicious code in auth-app-streamlit (PyPI)

▾ Sunlitauth-app-streamlit · auth-app-streamlitvia OSV
MAL-2026-15566None
1mo ago

Malicious code in flask-header-guard (PyPI)

Malicious code in flask-header-guard (PyPI)

▾ Sunlitflask-header-guard · flask-header-guardvia OSV
MAL-2026-15488None
1mo ago

Malicious code in calcboxlite (PyPI)

Malicious code in calcboxlite (PyPI)

▾ Sunlitcalcboxlite · calcboxlitevia OSV
CVE-2026-55830High· 8.3
1mo ago

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.40%via OSV
CVEs tagged “pip” — page 10 · VulnSea