VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-81681None
1mo ago

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with A…

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace direct…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.17%via OSV
CVE-2026-81706Medium· 6.8
1mo ago

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attacke…

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. Whe…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.18%via OSV
CVE-2026-81705None
1mo ago

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-o…

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.44%via OSV
CVE-2026-81703None
1mo ago

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attacker…

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing auth…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.22%via OSV
CVE-2026-81701None
1mo ago

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins…

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malic…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.43%via OSV
CVE-2026-81700None
1mo ago

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked a…

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exi…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.35%via OSV
CVE-2026-81698High· 8.8
1mo ago

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpol…

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name…

▾ Twilightopenssl-encrypt · openssl-encryptEPSS 0.43%via OSV
CVE-2026-81696None
1mo ago

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attacker…

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verific…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.25%via OSV
CVE-2026-81695None
1mo ago

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. A…

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint term…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.25%via OSV
CVE-2026-81725Medium· 5.9
1mo ago

nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)

A flaw was found in NLTK, specifically within the Pl196xCorpusReader component. A remote attacker can exploit this by supplying malformed Text Encoding Initiative (TEI) blocks containing numerous unmatched opening tags. This triggers a reg…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
CVE-2026-79720Medium· 5.0
1mo ago

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, …

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

▾ Sunlitnetron · netronEPSS 0.26%via OSV
CVE-2026-81724High· 7.5⚖ disputed
1mo ago

nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)

A flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structur…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.46%via CSAF
CVE-2026-81723Low· 3.7
1mo ago

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to caus…

▾ Sunlitnltk · nltkEPSS 0.28%via NVD
CVE-2026-81726High· 8.7
1mo ago

nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)

A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.34%via CSAF
CVE-2026-81727High· 7.1
1mo ago

nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)

A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installa…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.19%via CSAF
CVE-2026-81722High· 7.5
1mo ago

nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing (CVE-2026-81722)

A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.52%via CSAF
MAL-2026-14584None
1mo ago

Malicious code in flyteplugins-redis (PyPI)

Malicious code in flyteplugins-redis (PyPI)

▾ Sunlitflyteplugins-redis · flyteplugins-redisvia OSV
MAL-2026-14583None
1mo ago

Malicious code in flyteplugins-nsight (PyPI)

Malicious code in flyteplugins-nsight (PyPI)

▾ Sunlitflyteplugins-nsight · flyteplugins-nsightvia OSV
MAL-2026-14582None
1mo ago

Malicious code in flyteplugins-echo (PyPI)

Malicious code in flyteplugins-echo (PyPI)

▾ Sunlitflyteplugins-echo · flyteplugins-echovia OSV
MAL-2026-14581None
1mo ago

Malicious code in flyteplugins-agento11y (PyPI)

Malicious code in flyteplugins-agento11y (PyPI)

▾ Sunlitflyteplugins-agento11y · flyteplugins-agento11yvia OSV
MAL-2026-14556None
1mo ago

Malicious code in sap-quarterly-report (PyPI)

Malicious code in sap-quarterly-report (PyPI)

▾ Sunlitsap-quarterly-report · sap-quarterly-reportvia OSV
MAL-2026-14555None
1mo ago

Malicious code in ekx-report-utils (PyPI)

Malicious code in ekx-report-utils (PyPI)

▾ Sunlitekx-report-utils · ekx-report-utilsvia OSV
MAL-2026-14554None
1mo ago

Malicious code in decoris (PyPI)

Malicious code in decoris (PyPI)

▾ Sunlitdecoris · decorisvia OSV
MAL-2026-14552None
1mo ago

Malicious code in mathkitlite (PyPI)

Malicious code in mathkitlite (PyPI)

▾ Sunlitmathkitlite · mathkitlitevia OSV
CVE-2026-57171High· 7.7
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author comma…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.22%via NVD
GHSA-2rrw-hpqm-36pvHigh· 7.5
1mo ago

Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

▾ Twilightnltk · nltkvia GHSA
CVE-2026-80205High· 7.5
1mo ago

nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)

A flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions with…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.65%via CSAF
CVE-2026-57170High· 7.8
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-par…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.24%via NVD
MAL-2026-14545Critical⚠ Exploited
1mo ago

Malicious code in pybitjs (PyPI)

Malicious code in pybitjs (PyPI)

▾ Abyssalpybitjs · pybitjsvia OSV
MAL-2026-14542None
1mo ago

Malicious code in trongridet (PyPI)

Malicious code in trongridet (PyPI)

▾ Sunlittrongridet · trongridetvia OSV
CVEs tagged “pip” — page 12 · VulnSea