Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
GHSA-7cx2-g3h9-382pHigh· 8.1Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
CVE-2026-53755High· 8.6PoCCrawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
CVE-2026-50574High· 8.3yt-dlp: Arbitrary code execution via manifest downloads with aria2c
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
GHSA-x7cf-6gp3-q5f8Medium· 7.1Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin
Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin
GHSA-9fr2-p65v-gqxqHigh· 7.1Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-46448Medium· 5.4OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
GHSA-69qj-pvh9-c5wgHigh· 7.5yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
CVE-2026-49468Critical· 9.8PoCLiteLLM: Authentication Bypass via Host Header Injection
LiteLLM: Authentication Bypass via Host Header Injection
MAL-2026-5824NoneMalicious code in testpgagent (PyPI)
Malicious code in testpgagent (PyPI)
MAL-2026-5812NoneMalicious code in hello-test-s1 (PyPI)
Malicious code in hello-test-s1 (PyPI)
CVE-2026-48524Low· 3.7PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2026-48522Medium· 4.2PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-48525Medium· 5.3PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-50269Lowaiohttp: CRLF injection in multipart headers
aiohttp: CRLF injection in multipart headers
CVE-2026-54279Lowaiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
CVE-2026-54277Mediumaiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
CVE-2026-54278Mediumaiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
CVE-2026-54273Mediumaiohttp: HTTP/1 Pipelined Requests Queue Without Limit
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
CVE-2026-54275Lowaiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
CVE-2026-54274Mediumaiohttp: Incomplete websocket frame payloads bypass memory limits
aiohttp: Incomplete websocket frame payloads bypass memory limits
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2026-48817Medium· 5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
CVE-2026-48818High· 7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVE-2026-53537Low· 3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVE-2026-53538Low· 3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVE-2026-53540Low· 3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
CVE-2026-53539High· 7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
GHSA-pw6j-qg29-8w7fMedium· 5.9Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
CVE-2026-54282Low· 3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-54421Medium· 6.8OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties