Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-7025NoneMalicious code in tronsev (PyPI)
Malicious code in tronsev (PyPI)
MAL-2026-7023NoneMalicious code in dbzy-tools (PyPI)
Malicious code in dbzy-tools (PyPI)
MAL-2026-6961NoneMalicious code in waymo-waymax (PyPI)
Malicious code in waymo-waymax (PyPI)
MAL-2026-6960NoneMalicious code in pyqt6darktheme (PyPI)
Malicious code in pyqt6darktheme (PyPI)
CVE-2026-49471High· 8.3Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
GHSA-mxwc-wh95-pw4gMedium· 5.3Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
MAL-2026-7015NoneMalicious code in turbom (PyPI)
Malicious code in turbom (PyPI)
MAL-2026-7007NoneMalicious code in manom (PyPI)
Malicious code in manom (PyPI)
MAL-2026-7006NoneMalicious code in manik (PyPI)
Malicious code in manik (PyPI)
MAL-2026-6983NoneMalicious code in tronpak (PyPI)
Malicious code in tronpak (PyPI)
MAL-2026-6979NoneMalicious code in turbod (PyPI)
Malicious code in turbod (PyPI)
MAL-2026-6978NoneMalicious code in manin (PyPI)
Malicious code in manin (PyPI)
MAL-2026-6977NoneMalicious code in rarcore (PyPI)
Malicious code in rarcore (PyPI)
MAL-2026-6976NoneMalicious code in py-slugify (PyPI)
Malicious code in py-slugify (PyPI)
MAL-2026-6975NoneMalicious code in oxntime (PyPI)
Malicious code in oxntime (PyPI)
MAL-2026-6974NoneMalicious code in tronhapy (PyPI)
Malicious code in tronhapy (PyPI)
MAL-2026-6971NoneMalicious code in tronhap (PyPI)
Malicious code in tronhap (PyPI)
MAL-2026-6970NoneMalicious code in jsonschemavalid (PyPI)
Malicious code in jsonschemavalid (PyPI)
CVE-2026-48828Medium· 6.5The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
CVE-2026-58473Critical· 9.1Cognee allows non-superusers to overwrite global LLM configuration
Cognee allows non-superusers to overwrite global LLM configuration
CVE-2026-53878Medium· 6.1Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
CVE-2026-53877Medium· 4.8Django: GDALRaster may over-read heap memory when constructed from bytes
Django: GDALRaster may over-read heap memory when constructed from bytes
CVE-2026-48588Low· 3.1Django: cache middleware may expose private responses when unrelated request cookies are present
Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-49487Medium· 6.5In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, a…
CVE-2026-48892Medium· 6.5The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…
CVE-2026-48891Medium· 4.3A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …
A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …
CVE-2026-49296Medium· 6.5Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the en…
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…
MAL-2026-7467NoneMalicious code in scanvia (PyPI)
Malicious code in scanvia (PyPI)
MAL-2026-7466NoneMalicious code in scan-checker (PyPI)
Malicious code in scan-checker (PyPI)