Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-15827NoneMalicious code in company-sdk (PyPI)
Malicious code in company-sdk (PyPI)
CVE-2026-53720Mediumpymonocypher uses cython to wrap the Monocypher C library
pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, t…
CVE-2026-84452HighWindows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML
Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…
CVE-2026-84382High· 7.5HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…
CVE-2026-84380Medium· 5.6HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…
CVE-2026-84379Medium· 5.3HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…
CVE-2026-84378Medium· 5.9HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-contr…
CVE-2026-32773Medium· 6.1There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encourag…
CVE-2026-84381High· 8.1HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a…
CVE-2026-12876MediumNLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
CVE-2026-84366High· 7.4Scrapy is a high-level web crawling and scraping framework for Python
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to th…
MAL-2026-15811NoneMalicious code in syswatch (PyPI)
Malicious code in syswatch (PyPI)
MAL-2026-15810Critical⚠ ExploitedMalicious code in gcphelpit (PyPI)
Malicious code in gcphelpit (PyPI)
MAL-2026-15809NoneMalicious code in tallyboxlite (PyPI)
Malicious code in tallyboxlite (PyPI)
CVE-2026-84305Mediumsqlparse is a non-validating SQL parser module for Python
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/…
CVE-2026-84309Medium· 5.5pypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …
CVE-2026-84311Medium· 5.5pypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…
CVE-2026-84310Medium· 5.5pypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…
GHSA-wwv5-g3v4-889xLowTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_…
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
GHSA-8423-8fgw-73vqMediumtornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
GHSA-gqvg-gmmx-x4hmHigh· 8.8MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
CVE-2026-82398Medium· 5.3pypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…
CVE-2026-82397High· 7.5Tornado is a Python web framework and asynchronous networking library
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. Reques…
MAL-2026-15603Critical⚠ ExploitedMalicious code in pyservercheck (PyPI)
Malicious code in pyservercheck (PyPI)
MAL-2026-15588NoneMalicious code in tronlinker (PyPI)
Malicious code in tronlinker (PyPI)
MAL-2026-15578NoneMalicious code in trongridor (PyPI)
Malicious code in trongridor (PyPI)
MAL-2026-15577NoneMalicious code in auth-app-streamlit (PyPI)
Malicious code in auth-app-streamlit (PyPI)
MAL-2026-15566NoneMalicious code in flask-header-guard (PyPI)
Malicious code in flask-header-guard (PyPI)
MAL-2026-15488NoneMalicious code in calcboxlite (PyPI)
Malicious code in calcboxlite (PyPI)
CVE-2026-55830High· 8.3RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments