Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-13731NoneMalicious code in morpho-sdk (PyPI)
Malicious code in morpho-sdk (PyPI)
MAL-2026-13730NoneMalicious code in euler-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
MAL-2026-13729NoneMalicious code in dlmm-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI)
MAL-2026-13728NoneMalicious code in dlmm (PyPI)
Malicious code in dlmm (PyPI)
CVE-2026-48809High· 7.5python-engineio is a Python implementation of the Engine.IO realtime client and server
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before …
CVE-2026-48802High· 7.5python-engineio is a Python implementation of the Engine.IO realtime client and server
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbe…
CVE-2026-48804High· 7.5python-socketio is a Python implementation of the Socket.IO realtime client and server
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attach…
CVE-2026-48813LowPoCFlawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Inj…
CVE-2026-69112High· 7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…
CVE-2026-68871Medium· 6.5The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with thi…
CVE-2026-68872Medium· 6.5The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deploymen…
MAL-2026-13712NoneMalicious code in bigtime (PyPI)
Malicious code in bigtime (PyPI)
MAL-2026-13711NoneMalicious code in plp-contract (PyPI)
Malicious code in plp-contract (PyPI)
MAL-2026-13710NoneMalicious code in neutrl-core (PyPI)
Malicious code in neutrl-core (PyPI)
MAL-2026-13709NoneMalicious code in neutrl-contracts (PyPI)
Malicious code in neutrl-contracts (PyPI)
MAL-2026-13686NoneMalicious code in chaintest (PyPI)
Malicious code in chaintest (PyPI)
MAL-2026-13685NoneMalicious code in pytablute (PyPI)
Malicious code in pytablute (PyPI)
MAL-2026-13683NoneMalicious code in kotoraka (PyPI)
Malicious code in kotoraka (PyPI)
MAL-2026-13682NoneMalicious code in btcflx (PyPI)
Malicious code in btcflx (PyPI)
MAL-2026-13681NoneMalicious code in btcflip (PyPI)
Malicious code in btcflip (PyPI)
CVE-2026-12570Medium· 5.5A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…
MAL-2026-13667NoneMalicious code in kotanku (PyPI)
Malicious code in kotanku (PyPI)
CVE-2026-12372Low· 3.7A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, f…
MAL-2026-13666NoneMalicious code in cubesat-upstream-driver (PyPI)
Malicious code in cubesat-upstream-driver (PyPI)
MAL-2026-13665NoneMalicious code in riakcs (PyPI)
Malicious code in riakcs (PyPI)
CVE-2026-76217Medium· 6.5GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
CVE-2026-71870Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…
MAL-2026-13619NoneMalicious code in atlas-internal (PyPI)
Malicious code in atlas-internal (PyPI)
MAL-2026-13607NoneMalicious code in speed-hashes (PyPI)
Malicious code in speed-hashes (PyPI)
MAL-2026-13606NoneMalicious code in cdktn-provider-azurerm (PyPI)
Malicious code in cdktn-provider-azurerm (PyPI)