Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-5768NoneMalicious code in bash8 (PyPI)
Malicious code in bash8 (PyPI)
CVE-2026-45831High· 8.8ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
CVE-2026-45833CriticalPoCChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
CVE-2026-45830High· 8.8ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
MAL-2026-5698NoneMalicious code in nagios-xi (PyPI)
Malicious code in nagios-xi (PyPI)
CVE-2026-48155Mediumpypdf: Possible large memory usage for large offsets for layout mode text
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156Low· 3.3pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference …
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-49854Low· 3.7Tornado has out-of-bounds memory access via C extension
Tornado has out-of-bounds memory access via C extension
CVE-2026-11816High· 8.1Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/f…
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive …
MAL-2026-5545NoneMalicious code in acme-widget-layout-utils (PyPI)
Malicious code in acme-widget-layout-utils (PyPI)
CVE-2026-48045Medium· 6.5python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
CVE-2026-10143High· 7.5kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count (CVE-2026-10143)
A flaw was found in kafka-python. A malicious or machine-in-the-middle broker could exploit a denial-of-service vulnerability during SCRAM authentication. By providing an excessively large iteration count, the broker can cause the client's…
CVE-2026-10142High· 7.5kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-i…
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length…
CVE-2026-42563High· 8.0dulwich: Dulwich: Arbitrary code execution via malicious Git file paths during merge (CVE-2026-42563)
A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the …
CVE-2026-42305High· 8.8dulwich: Dulwich: Remote Code Execution via Malicious Git Repository (CVE-2026-42305)
A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious …
MAL-2026-5531NoneMalicious code in telegramlite (PyPI)
Malicious code in telegramlite (PyPI)
MAL-2026-5518NoneMalicious code in hello-dynamic (PyPI)
Malicious code in hello-dynamic (PyPI)
MAL-2026-5519NoneMalicious code in requests-toolbelt-plus (PyPI)
Malicious code in requests-toolbelt-plus (PyPI)
CVE-2026-48060High· 8.1PoCLitestar has HTML Injection Through its CSRF Token
Litestar has HTML Injection Through its CSRF Token
CVE-2026-52726Medium· 5.4⚖ disputeddulwich: Dulwich: Arbitrary code execution via crafted Git submodules (CVE-2026-52726)
A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updat…
CVE-2026-52902Medium· 4.7awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
CVE-2026-49818Medium· 6.5Apache Airflow has a Path Traversal issue
Apache Airflow has a Path Traversal issue
MAL-2026-5345NoneMalicious code in dstill (PyPI)
Malicious code in dstill (PyPI)
CVE-2026-11466Medium· 5.4zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
MAL-2026-5334NoneMalicious code in spaysrbx (PyPI)
Malicious code in spaysrbx (PyPI)
MAL-2026-5329NoneMalicious code in spaysdatarbx (PyPI)
Malicious code in spaysdatarbx (PyPI)
CVE-2026-11529Medium· 6.3MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MAL-2026-5330NoneMalicious code in bittensor-burn-alert (PyPI)
Malicious code in bittensor-burn-alert (PyPI)
MAL-2026-5335NoneMalicious code in xfoobar (PyPI)
Malicious code in xfoobar (PyPI)
MAL-2026-5332NoneMalicious code in xforpy (PyPI)
Malicious code in xforpy (PyPI)