Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-10618NoneMalicious code in cosmos-gradio (PyPI)
Malicious code in cosmos-gradio (PyPI)
MAL-2026-10617NoneMalicious code in cosmos-cuda (PyPI)
Malicious code in cosmos-cuda (PyPI)
MAL-2026-10610NoneMalicious code in proxy-check-ii (PyPI)
Malicious code in proxy-check-ii (PyPI)
MAL-2026-10576NoneMalicious code in tennacity (PyPI)
Malicious code in tennacity (PyPI)
MAL-2026-10547NoneMalicious code in pokee-data-utils (PyPI)
Malicious code in pokee-data-utils (PyPI)
CVE-2026-49477High· 7.5soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings (CVE-2026-49477)
A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expressi…
CVE-2026-49855High· 7.5tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)
A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…
CVE-2026-49853High· 7.7tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…
CVE-2026-62240High· 7.4PoCCrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…
CVE-2026-15685High· 7.50dayOllama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not require…
MAL-2026-10484NoneMalicious code in browser-use-headless (PyPI)
Malicious code in browser-use-headless (PyPI)
GHSA-xf7x-x43h-rpqhHigh· 7.5json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
GHSA-8f6j-263m-g72xMediumApple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
GHSA-7xw9-549r-8jrcHigh· 8.5DIRAC: SQL injection and lack of access control in PilotManager service
DIRAC: SQL injection and lack of access control in PilotManager service
MAL-2026-10441NoneMalicious code in turbocalcng (PyPI)
Malicious code in turbocalcng (PyPI)
CVE-2026-56074Medium· 5.5PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2024-27091Medium· 6.1GeoNode: Stored XSS to full account takeover
GeoNode: Stored XSS to full account takeover
CVE-2026-15529Medium· 6.3A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…
MAL-2026-10215NoneMalicious code in fast-dotenv (PyPI)
Malicious code in fast-dotenv (PyPI)
MAL-2026-10213NoneMalicious code in pipspeed (PyPI)
Malicious code in pipspeed (PyPI)
MAL-2026-10197NoneMalicious code in metemask-sdk (PyPI)
Malicious code in metemask-sdk (PyPI)
MAL-2026-10196NoneMalicious code in jupiter-sdk (PyPI)
Malicious code in jupiter-sdk (PyPI)
MAL-2026-10195NoneMalicious code in eth-agent (PyPI)
Malicious code in eth-agent (PyPI)
MAL-2026-10194NoneMalicious code in solidity-dev (PyPI)
Malicious code in solidity-dev (PyPI)
MAL-2026-10193NoneMalicious code in py-base58 (PyPI)
Malicious code in py-base58 (PyPI)
MAL-2026-10192NoneMalicious code in defi-tools (PyPI)
Malicious code in defi-tools (PyPI)
MAL-2026-10191NoneMalicious code in data-harvester (PyPI)
Malicious code in data-harvester (PyPI)
CVE-2026-56260Critical· 9.1Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supp…
GHSA-h4g2-xfmw-q2c9HighClauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
GHSA-9mqm-qcwf-5qhgMedium· 5.5CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources