VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

GHSA-7cx2-g3h9-382pHigh· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

▾ Twilightcrawl4ai · crawl4aivia GHSA
CVE-2026-53755High· 8.6PoC
3mo ago

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

▾ Midnightcrawl4ai · crawl4aiEPSS 1.6%via GHSA
CVE-2026-50574High· 8.3
3mo ago

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

▾ Twilightyt-dlp · yt-dlpEPSS 0.46%via GHSA
GHSA-x7cf-6gp3-q5f8Medium· 7.1
3mo ago

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-9fr2-p65v-gqxqHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-46448Medium· 5.4
3mo ago

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

▾ Sunlitnova · novaEPSS 0.46%via OSV
GHSA-69qj-pvh9-c5wgHigh· 7.5
3mo ago

yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp

yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp

▾ Twilightyt-dlp · yt-dlpvia GHSA
CVE-2026-49468Critical· 9.8PoC
3mo ago

LiteLLM: Authentication Bypass via Host Header Injection

LiteLLM: Authentication Bypass via Host Header Injection

▾ Abyssallitellm · litellmEPSS 0.82%via OSV
MAL-2026-5824None
3mo ago

Malicious code in testpgagent (PyPI)

Malicious code in testpgagent (PyPI)

▾ Sunlittestpgagent · testpgagentvia OSV
MAL-2026-5812None
3mo ago

Malicious code in hello-test-s1 (PyPI)

Malicious code in hello-test-s1 (PyPI)

▾ Sunlithello-test-s1 · hello-test-s1via OSV
CVE-2026-48524Low· 3.7
3mo ago

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

▾ Sunlitpyjwt · pyjwtEPSS 0.32%via OSV
CVE-2026-48522Medium· 4.2
3mo ago

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

▾ Sunlitpyjwt · pyjwtEPSS 0.22%via OSV
CVE-2026-48525Medium· 5.3
3mo ago

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

▾ Sunlitpyjwt · pyjwtEPSS 0.41%via OSV
CVE-2026-50269Low
3mo ago

aiohttp: CRLF injection in multipart headers

aiohttp: CRLF injection in multipart headers

▾ Sunlitaiohttp · aiohttpEPSS 0.53%via OSV
CVE-2026-54279Low
3mo ago

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54277Medium
3mo ago

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

▾ Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2026-54278Medium
3mo ago

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54273Medium
3mo ago

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54275Low
3mo ago

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

▾ Sunlitaiohttp · aiohttpEPSS 0.47%via OSV
CVE-2026-54274Medium
3mo ago

aiohttp: Incomplete websocket frame payloads bypass memory limits

aiohttp: Incomplete websocket frame payloads bypass memory limits

▾ Sunlitaiohttp · aiohttpEPSS 0.54%via OSV
GHSA-537c-gmf6-5ccfHigh· 7.5
3mo ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Twilightcryptography · cryptographyvia OSV
CVE-2026-48817Medium· 5.3
3mo ago

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

▾ Sunlitstarlette · starletteEPSS 0.35%via OSV
CVE-2026-48818High· 7.5
3mo ago

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

▾ Twilightstarlette · starletteEPSS 0.65%via OSV
CVE-2026-53537Low· 3.7
3mo ago

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

▾ Sunlitpython-multipart · python-multipartEPSS 0.29%via OSV
CVE-2026-53538Low· 3.7
3mo ago

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

▾ Sunlitpython-multipart · python-multipartEPSS 0.26%via OSV
CVE-2026-53540Low· 3.7
3mo ago

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

▾ Sunlitpython-multipart · python-multipartEPSS 0.34%via OSV
CVE-2026-53539High· 7.5
3mo ago

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

▾ Twilightpython-multipart · python-multipartEPSS 0.46%via OSV
GHSA-pw6j-qg29-8w7fMedium· 5.9
3mo ago

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

▾ Sunlittornado · tornadovia OSV
CVE-2026-54282Low· 3.7
3mo ago

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

▾ Sunlitstarlette · starletteEPSS 0.27%via OSV
CVE-2026-54421Medium· 6.8
3mo ago

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

▾ Sunlitironic · ironicEPSS 0.47%via OSV
CVEs tagged “pip” — page 48 · VulnSea