VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-52869High· 7.1
2mo ago

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

▾ Twilightmcp · mcpEPSS 0.53%via OSV
CVE-2026-59950High
2mo ago

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

▾ Twilightmcp · mcpEPSS 0.23%via OSV
CVE-2026-52870High· 7.6
2mo ago

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

▾ Twilightmcp · mcpEPSS 0.39%via OSV
MAL-2026-10702None
2mo ago

Malicious code in discordia-telemetria (PyPI)

Malicious code in discordia-telemetria (PyPI)

▾ Sunlitdiscordia-telemetria · discordia-telemetriavia OSV
MAL-2026-10701None
2mo ago

Malicious code in discord-telemetry (PyPI)

Malicious code in discord-telemetry (PyPI)

▾ Sunlitdiscord-telemetry · discord-telemetryvia OSV
CVE-2026-58659High· 7.8
2mo ago

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.63%via NVD
MAL-2026-10690None
2mo ago

Malicious code in qwen-asr-pvt (PyPI)

Malicious code in qwen-asr-pvt (PyPI)

▾ Sunlitqwen-asr-pvt · qwen-asr-pvtvia OSV
MAL-2026-10689None
2mo ago

Malicious code in pylogora (PyPI)

Malicious code in pylogora (PyPI)

▾ Sunlitpylogora · pylogoravia OSV
MAL-2026-10688None
2mo ago

Malicious code in log-guru (PyPI)

Malicious code in log-guru (PyPI)

▾ Sunlitlog-guru · log-guruvia OSV
MAL-2026-10685None
2mo ago

Malicious code in trongridweb (PyPI)

Malicious code in trongridweb (PyPI)

▾ Sunlittrongridweb · trongridwebvia OSV
MAL-2026-10681None
2mo ago

Malicious code in xyq-drama-skill (PyPI)

Malicious code in xyq-drama-skill (PyPI)

▾ Sunlitxyq-drama-skill · xyq-drama-skillvia OSV
CVE-2026-50271High· 7.5
2mo ago

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightddtrace · ddtraceEPSS 0.79%via OSV
CVE-2026-53656Medium· 6.3
2mo ago

FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data

FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data

▾ Sunlitfiftyone · fiftyoneEPSS 0.12%via GHSA
GHSA-r3hx-x5rh-p9vvHigh
2mo ago

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

▾ Twilightdjango-haystack · django-haystackvia GHSA
MAL-2026-10672None
2mo ago

Malicious code in northstart-sdk (PyPI)

Malicious code in northstart-sdk (PyPI)

▾ Sunlitnorthstart-sdk · northstart-sdkvia OSV
MAL-2026-10643None
2mo ago

Malicious code in ethereum-input-decorder (PyPI)

Malicious code in ethereum-input-decorder (PyPI)

▾ Sunlitethereum-input-decorder · ethereum-input-decordervia OSV
MAL-2026-10642None
2mo ago

Malicious code in data-proxy-for-test (PyPI)

Malicious code in data-proxy-for-test (PyPI)

▾ Sunlitdata-proxy-for-test · data-proxy-for-testvia OSV
CVE-2026-45804High· 7.5
2mo ago

diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass (CVE-2026-45804)

A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit this vulnerability by crafting a malicious Hub repository with custom Python pipeline code. The `DiffusionPipeline.from_pretrained` f…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.37%via CSAF
CVE-2026-15736High· 8.3
2mo ago

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

▾ Twilightsnowflake-sqlalchemy · snowflake-sqlalchemyEPSS 0.38%via OSV
CVE-2026-12482Low· 3.1
2mo ago

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

▾ Sunlitkeras · kerasEPSS 0.33%via OSV
CVE-2026-59885High· 7.5
2mo ago

pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)

A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.62%via CSAF
CVE-2026-59886High· 7.5
2mo ago

pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)

A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.62%via CSAF
CVE-2026-59197High· 8.2
2mo ago

Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)

A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.58%via CSAF
CVE-2026-59200High· 7.5
2mo ago

Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59204High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-54058Critical· 9.1
2mo ago

Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)

A flaw was found in Pillow prior to 12.3.0. When an uncompressed McIdas AREA image is loaded from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width. Pixel a…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.68%via CSAF
CVE-2026-59205High· 7.5
2mo ago

Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)

A flaw was found in Pillow, a Python imaging library. This vulnerability allows an attacker to trigger controlled native heap corruption by supplying an output image whose mode does not match the transform's declared output mode when using…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59199High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via out-of-bounds write in image processing (CVE-2026-59199)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the library's image processing functions, specifically when handling image coordinates near certain limits. This flaw, a native heap o…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
MAL-2026-10644None
2mo ago

Malicious code in proxy-checker-j (PyPI)

Malicious code in proxy-checker-j (PyPI)

▾ Sunlitproxy-checker-j · proxy-checker-jvia OSV
MAL-2026-10624None
2mo ago

Malicious code in tronwe (PyPI)

Malicious code in tronwe (PyPI)

▾ Sunlittronwe · tronwevia OSV
CVEs tagged “pip” — page 32 · VulnSea