VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-10618None
2mo ago

Malicious code in cosmos-gradio (PyPI)

Malicious code in cosmos-gradio (PyPI)

▾ Sunlitcosmos-gradio · cosmos-gradiovia OSV
MAL-2026-10617None
2mo ago

Malicious code in cosmos-cuda (PyPI)

Malicious code in cosmos-cuda (PyPI)

▾ Sunlitcosmos-cuda · cosmos-cudavia OSV
MAL-2026-10610None
2mo ago

Malicious code in proxy-check-ii (PyPI)

Malicious code in proxy-check-ii (PyPI)

▾ Sunlitproxy-check-ii · proxy-check-iivia OSV
MAL-2026-10576None
2mo ago

Malicious code in tennacity (PyPI)

Malicious code in tennacity (PyPI)

▾ Sunlittennacity · tennacityvia OSV
MAL-2026-10547None
2mo ago

Malicious code in pokee-data-utils (PyPI)

Malicious code in pokee-data-utils (PyPI)

▾ Sunlitpokee-data-utils · pokee-data-utilsvia OSV
CVE-2026-49477High· 7.5
2mo ago

soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings (CVE-2026-49477)

A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expressi…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-49855High· 7.5
2mo ago

tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)

A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.61%via CSAF
CVE-2026-49853High· 7.7
2mo ago

tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)

A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.45%via CSAF
CVE-2026-62240High· 7.4PoC
2mo ago

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…

▾ Midnightcrewai · crewaiEPSS 0.52%via NVD
CVE-2026-15685High· 7.50day
2mo ago

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…

▾ Abyssalollama · ollamaEPSS 0.71%via OSV
MAL-2026-10484None
2mo ago

Malicious code in browser-use-headless (PyPI)

Malicious code in browser-use-headless (PyPI)

▾ Sunlitbrowser-use-headless · browser-use-headlessvia OSV
GHSA-xf7x-x43h-rpqhHigh· 7.5
2mo ago

json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS

json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS

▾ Twilightjson-repair · json-repairvia GHSA
GHSA-8f6j-263m-g72xMedium
2mo ago

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

▾ Sunlitapp-store-server-library · app-store-server-libraryvia GHSA
GHSA-7xw9-549r-8jrcHigh· 8.5
2mo ago

DIRAC: SQL injection and lack of access control in PilotManager service

DIRAC: SQL injection and lack of access control in PilotManager service

▾ TwilightDIRAC · DIRACvia GHSA
MAL-2026-10441None
2mo ago

Malicious code in turbocalcng (PyPI)

Malicious code in turbocalcng (PyPI)

▾ Sunlitturbocalcng · turbocalcngvia OSV
CVE-2026-56074Medium· 5.5
2mo ago

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.17%via OSV
CVE-2024-27091Medium· 6.1
2mo ago

GeoNode: Stored XSS to full account takeover

GeoNode: Stored XSS to full account takeover

▾ Sunlitgeonode · geonodeEPSS 0.38%via GHSA
CVE-2026-15529Medium· 6.3
2mo ago

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…

▾ Sunlitpyod · pyodEPSS 0.44%via NVD
MAL-2026-10215None
2mo ago

Malicious code in fast-dotenv (PyPI)

Malicious code in fast-dotenv (PyPI)

▾ Sunlitfast-dotenv · fast-dotenvvia OSV
MAL-2026-10213None
2mo ago

Malicious code in pipspeed (PyPI)

Malicious code in pipspeed (PyPI)

▾ Sunlitpipspeed · pipspeedvia OSV
MAL-2026-10197None
2mo ago

Malicious code in metemask-sdk (PyPI)

Malicious code in metemask-sdk (PyPI)

▾ Sunlitmetemask-sdk · metemask-sdkvia OSV
MAL-2026-10196None
2mo ago

Malicious code in jupiter-sdk (PyPI)

Malicious code in jupiter-sdk (PyPI)

▾ Sunlitjupiter-sdk · jupiter-sdkvia OSV
MAL-2026-10195None
2mo ago

Malicious code in eth-agent (PyPI)

Malicious code in eth-agent (PyPI)

▾ Sunliteth-agent · eth-agentvia OSV
MAL-2026-10194None
2mo ago

Malicious code in solidity-dev (PyPI)

Malicious code in solidity-dev (PyPI)

▾ Sunlitsolidity-dev · solidity-devvia OSV
MAL-2026-10193None
2mo ago

Malicious code in py-base58 (PyPI)

Malicious code in py-base58 (PyPI)

▾ Sunlitpy-base58 · py-base58via OSV
MAL-2026-10192None
2mo ago

Malicious code in defi-tools (PyPI)

Malicious code in defi-tools (PyPI)

▾ Sunlitdefi-tools · defi-toolsvia OSV
MAL-2026-10191None
2mo ago

Malicious code in data-harvester (PyPI)

Malicious code in data-harvester (PyPI)

▾ Sunlitdata-harvester · data-harvestervia OSV
CVE-2026-56260Critical· 9.1
2mo ago

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supp…

▾ Midnightcrawl4ai · crawl4aiEPSS 0.65%via NVD
GHSA-h4g2-xfmw-q2c9High
2mo ago

Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset

Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset

▾ Twilightclauster · claustervia GHSA
GHSA-9mqm-qcwf-5qhgMedium· 5.5
2mo ago

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

▾ Sunlitcredsweeper · credsweepervia GHSA
CVEs tagged “pip” — page 33 · VulnSea