Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-52869High· 7.1MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-59950HighMCP Python SDK: WebSocket server transport does not support Host/Origin validation
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-52870High· 7.6MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MAL-2026-10702NoneMalicious code in discordia-telemetria (PyPI)
Malicious code in discordia-telemetria (PyPI)
MAL-2026-10701NoneMalicious code in discord-telemetry (PyPI)
Malicious code in discord-telemetry (PyPI)
CVE-2026-58659High· 7.8PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…
MAL-2026-10690NoneMalicious code in qwen-asr-pvt (PyPI)
Malicious code in qwen-asr-pvt (PyPI)
MAL-2026-10689NoneMalicious code in pylogora (PyPI)
Malicious code in pylogora (PyPI)
MAL-2026-10688NoneMalicious code in log-guru (PyPI)
Malicious code in log-guru (PyPI)
MAL-2026-10685NoneMalicious code in trongridweb (PyPI)
Malicious code in trongridweb (PyPI)
MAL-2026-10681NoneMalicious code in xyq-drama-skill (PyPI)
Malicious code in xyq-drama-skill (PyPI)
CVE-2026-50271High· 7.5dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-53656Medium· 6.3FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data
FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data
GHSA-r3hx-x5rh-p9vvHighdjango-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
MAL-2026-10672NoneMalicious code in northstart-sdk (PyPI)
Malicious code in northstart-sdk (PyPI)
MAL-2026-10643NoneMalicious code in ethereum-input-decorder (PyPI)
Malicious code in ethereum-input-decorder (PyPI)
MAL-2026-10642NoneMalicious code in data-proxy-for-test (PyPI)
Malicious code in data-proxy-for-test (PyPI)
CVE-2026-45804High· 7.5diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass (CVE-2026-45804)
A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit this vulnerability by crafting a malicious Hub repository with custom Python pipeline code. The `DiffusionPipeline.from_pretrained` f…
CVE-2026-15736High· 8.3Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
CVE-2026-12482Low· 3.1Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…
CVE-2026-59886High· 7.5pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)
A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…
CVE-2026-59197High· 8.2Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…
CVE-2026-59204High· 7.5Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …
CVE-2026-54058Critical· 9.1Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)
A flaw was found in Pillow prior to 12.3.0. When an uncompressed McIdas AREA image is loaded from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width. Pixel a…
CVE-2026-59205High· 7.5Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)
A flaw was found in Pillow, a Python imaging library. This vulnerability allows an attacker to trigger controlled native heap corruption by supplying an output image whose mode does not match the transform's declared output mode when using…
CVE-2026-59199High· 7.5Pillow: Pillow: Denial of Service via out-of-bounds write in image processing (CVE-2026-59199)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the library's image processing functions, specifically when handling image coordinates near certain limits. This flaw, a native heap o…
MAL-2026-10644NoneMalicious code in proxy-checker-j (PyPI)
Malicious code in proxy-checker-j (PyPI)
MAL-2026-10624NoneMalicious code in tronwe (PyPI)
Malicious code in tronwe (PyPI)