VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-14590None
1mo ago

Malicious code in yamlformatter-utils (PyPI)

Malicious code in yamlformatter-utils (PyPI)

▾ Sunlityamlformatter-utils · yamlformatter-utilsvia OSV
MAL-2026-14589None
1mo ago

Malicious code in yamlformat-tools (PyPI)

Malicious code in yamlformat-tools (PyPI)

▾ Sunlityamlformat-tools · yamlformat-toolsvia OSV
MAL-2026-14588None
1mo ago

Malicious code in yaml-report-formatter (PyPI)

Malicious code in yaml-report-formatter (PyPI)

▾ Sunlityaml-report-formatter · yaml-report-formattervia OSV
MAL-2026-14587None
1mo ago

Malicious code in pygame-renderkit (PyPI)

Malicious code in pygame-renderkit (PyPI)

▾ Sunlitpygame-renderkit · pygame-renderkitvia OSV
CVE-2026-55248Critical· 9.1
1mo ago

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone.app.portlets vulnerable to denial of service via RSS feed portlet

▾ Midnightplone-app-portlets · plone-app-portletsEPSS 0.44%via OSV
CVE-2026-55520High
1mo ago

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

▾ Twilightprotego · protegoEPSS 0.51%via OSV
CVE-2026-55227Medium· 4.3
1mo ago

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2026-55228High· 8.1
1mo ago

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

▾ Twilightweblate · weblateEPSS 0.45%via OSV
CVE-2026-55247Critical· 9.1
1mo ago

plone.app.event vulnerable to denial of service via iCalendar import

plone.app.event vulnerable to denial of service via iCalendar import

▾ Midnightplone-app-event · plone-app-eventEPSS 0.44%via OSV
GHSA-73p9-6hrp-8qhrMedium
1mo ago

AIIR verification and policy gates could report success without enforcing the control (fail-open)

AIIR verification and policy gates could report success without enforcing the control (fail-open)

▾ Sunlitaiir · aiirvia GHSA
CVE-2026-55509High
1mo ago

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

▾ Twilightwsgidav · wsgidavEPSS 0.54%via OSV
CVE-2026-55485High· 8.8
1mo ago

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

▾ Twilightpiccolo-admin · piccolo-adminEPSS 0.56%via OSV
CVE-2026-54757High· 7.8
1mo ago

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.36%via OSV
CVE-2026-81702None
1mo ago

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers …

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with thei…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.19%via OSV
CVE-2026-81694None
1mo ago

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenti…

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filen…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.25%via OSV
CVE-2026-81689None
1mo ago

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allow…

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can pre…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.27%via OSV
CVE-2026-81680Medium· 5.3
1mo ago

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers …

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to …

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.20%via OSV
CVE-2026-37004Critical· 9.8
1mo ago

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

▾ Midnightlitellm · litellmEPSS 0.80%via OSV
CVE-2026-81721None
1mo ago

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to…

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitr…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.58%via OSV
CVE-2026-81719None
1mo ago

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to …

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process …

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.44%via OSV
CVE-2026-81717None
1mo ago

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model …

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._veri…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.12%via OSV
CVE-2026-81716None
1mo ago

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authoriz…

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permissio…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.26%via OSV
CVE-2026-81714None
1mo ago

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plug…

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unkn…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.20%via OSV
CVE-2026-81693None
1mo ago

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply cr…

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause d…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.49%via OSV
CVE-2026-81691None
1mo ago

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http…

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials i…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.27%via OSV
CVE-2026-81690None
1mo ago

openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enu…

openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and tre…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.71%via OSV
CVE-2026-81688None
1mo ago

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can…

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical …

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.27%via OSV
CVE-2026-81686Medium· 5.5
1mo ago

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs ne…

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call S…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.14%via OSV
CVE-2026-81685None
1mo ago

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control ch…

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft …

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.25%via OSV
CVE-2026-81683Medium· 5.5
1mo ago

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-rea…

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and …

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.07%via OSV
CVEs tagged “pip” — page 11 · VulnSea