VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4536 CVEsRSS

CVE-2026-61599High· 8.8
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …

Twilightdjust-org · djustEPSS 0.38%via NVD
CVE-2026-61589Medium· 6.3
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

Sunlitdjust-org · djustEPSS 0.16%via NVD
CVE-2026-61597Medium· 5.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/use…

Sunlitdjust-org · djustEPSS 0.30%via NVD
CVE-2026-61592High· 7.4
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

Twilightdjust-org · djustEPSS 0.29%via NVD
CVE-2026-61594Critical· 9.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

Midnightdjust-org · djustEPSS 0.43%via NVD
CVE-2026-61591High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was res…

Twilightdjust-org · djustEPSS 0.17%via NVD
CVE-2026-61588Medium· 6.5
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

Sunlitdjust-org · djustEPSS 0.30%via NVD
CVE-2026-61596High· 7.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

Twilightdjust-org · djustEPSS 0.24%via NVD
CVE-2026-62949Medium· 6.5
5d ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

Sunlitronf · asyncsshEPSS 0.39%via NVD
CVE-2026-59823Medium· 5.3
5d ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…

SunlitBerriAI · litellmEPSS 0.44%via NVD
CVE-2026-69147Medium· 6.5PoC
5d ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

Twilightvllm-project · vllmEPSS 0.46%via NVD
CVE-2026-57173Medium· 6.5
5d ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURA…

Sunlitvllm-project · vllmEPSS 0.66%via NVD
MAL-2026-16219Critical⚠ Exploited
5d ago

Malicious code in licloud (PyPI)

Malicious code in licloud (PyPI)

Abyssallicloud · licloudvia OSV
MAL-2026-16212Critical⚠ Exploited
5d ago

Malicious code in cli-anything-ai-market (PyPI)

Malicious code in cli-anything-ai-market (PyPI)

Abyssalcli-anything-ai-market · cli-anything-ai-marketvia OSV
CVE-2026-61595High· 7.7
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

Twilightdjust · djustEPSS 0.38%via NVD
CVE-2025-59953Critical· 9.8PoC
5d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

AbyssalInternLM · lmdeployEPSS 0.68%via NVD
CVE-2026-61593High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

Twilightdjust · djustEPSS 0.18%via NVD
CVE-2026-76825High· 8.4
5d ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

Twilightzopefoundation · RestrictedPythonEPSS 0.57%via NVD
CVE-2026-77401Medium· 6.8
5d ago

Zope AccessControl provides a general security framework for use in Zope

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …

Sunlitzopefoundation · AccessControlEPSS 0.37%via NVD
CVE-2026-61590High· 7.4
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface …

Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-61598High· 7.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is …

Twilightdjust · djustEPSS 0.41%via NVD
CVE-2026-86792High· 8.8
5d ago

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka …

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka …

Twilightapache · apache-airflow-providers-apache-kafkaEPSS 1.2%via NVD
CVE-2024-58384Medium· 5.4
6d ago

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitr…

Sunlittornadoweb · tornadoEPSS 0.24%via NVD
CVE-2024-14029High· 7.5PoC⚖ disputed
6d ago

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deploye…

Midnighttornadoweb · tornadoEPSS 0.35%via NVD
CVE-2023-54397High· 7.5
6d ago

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy val…

Twilighttornadoweb · tornadoEPSS 0.37%via NVD
CVE-2026-91990High· 7.5PoC
6d ago

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create lar…

Midnighttornadoweb · tornadoEPSS 0.41%via NVD
CVE-2026-91987Medium· 6.5
6d ago

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers…

Sunlitdep0we · atomic-agents-stackEPSS 0.37%via NVD
CVE-2026-91989High· 7.5
6d ago

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass …

Twilightdep0we · atomic-agents-stackEPSS 1.3%via NVD
CVE-2026-91988High· 8.1
6d ago

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…

Twilightdep0we · atomic-agents-stackEPSS 0.25%via NVD
CVE-2026-91992Medium· 5.9PoC
6d ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

Twilighttornadoweb · tornadoEPSS 0.21%via NVD
CVEs tagged “pip” — page 2 · VulnSea