VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-5768None
3mo ago

Malicious code in bash8 (PyPI)

Malicious code in bash8 (PyPI)

▾ Sunlitbash8 · bash8via OSV
CVE-2026-45831High· 8.8
3mo ago

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

▾ Twilightchromadb · chromadbEPSS 0.42%via OSV
CVE-2026-45833CriticalPoC
3mo ago

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

▾ Abyssalchromadb · chromadbEPSS 0.63%via OSV
CVE-2026-45830High· 8.8
3mo ago

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

▾ Twilightchromadb · chromadbEPSS 0.50%via OSV
MAL-2026-5698None
3mo ago

Malicious code in nagios-xi (PyPI)

Malicious code in nagios-xi (PyPI)

▾ Sunlitnagios-xi · nagios-xivia OSV
CVE-2026-48155Medium
3mo ago

pypdf: Possible large memory usage for large offsets for layout mode text

pypdf: Possible large memory usage for large offsets for layout mode text

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-48156Low· 3.3
3mo ago

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference …

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-49854Low· 3.7
3mo ago

Tornado has out-of-bounds memory access via C extension

Tornado has out-of-bounds memory access via C extension

▾ Sunlittornado · tornadoEPSS 0.42%via OSV
CVE-2026-11816High· 8.1
3mo ago

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/f…

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive …

▾ Twilightkeras · kerasEPSS 0.56%via OSV
MAL-2026-5545None
3mo ago

Malicious code in acme-widget-layout-utils (PyPI)

Malicious code in acme-widget-layout-utils (PyPI)

▾ Sunlitacme-widget-layout-utils · acme-widget-layout-utilsvia OSV
CVE-2026-48045Medium· 6.5
3mo ago

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

▾ Sunlitzeroconf · zeroconfEPSS 0.37%via GHSA
CVE-2026-10143High· 7.5
3mo ago

kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count (CVE-2026-10143)

A flaw was found in kafka-python. A malicious or machine-in-the-middle broker could exploit a denial-of-service vulnerability during SCRAM authentication. By providing an excessively large iteration count, the broker can cause the client's…

▾ TwilightRed Hat · Red Hat Quay 3.12EPSS 0.52%via CSAF
CVE-2026-10142High· 7.5
3mo ago

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-i…

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length…

▾ Twilightkafka-python · kafka-pythonEPSS 0.35%via OSV
CVE-2026-42563High· 8.0
3mo ago

dulwich: Dulwich: Arbitrary code execution via malicious Git file paths during merge (CVE-2026-42563)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the …

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.80%via CSAF
CVE-2026-42305High· 8.8
3mo ago

dulwich: Dulwich: Remote Code Execution via Malicious Git Repository (CVE-2026-42305)

A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.85%via CSAF
MAL-2026-5531None
3mo ago

Malicious code in telegramlite (PyPI)

Malicious code in telegramlite (PyPI)

▾ Sunlittelegramlite · telegramlitevia OSV
MAL-2026-5518None
3mo ago

Malicious code in hello-dynamic (PyPI)

Malicious code in hello-dynamic (PyPI)

▾ Sunlithello-dynamic · hello-dynamicvia OSV
MAL-2026-5519None
3mo ago

Malicious code in requests-toolbelt-plus (PyPI)

Malicious code in requests-toolbelt-plus (PyPI)

▾ Sunlitrequests-toolbelt-plus · requests-toolbelt-plusvia OSV
CVE-2026-48060High· 8.1PoC
3mo ago

Litestar has HTML Injection Through its CSRF Token

Litestar has HTML Injection Through its CSRF Token

▾ Midnightlitestar · litestarEPSS 0.40%via GHSA
CVE-2026-52726Medium· 5.4⚖ disputed
3mo ago

dulwich: Dulwich: Arbitrary code execution via crafted Git submodules (CVE-2026-52726)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updat…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.68%via CSAF
CVE-2026-52902Medium· 4.7
3mo ago

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

▾ Sunlitawxkit · awxkitEPSS 0.16%via OSV
CVE-2026-49818Medium· 6.5
3mo ago

Apache Airflow has a Path Traversal issue

Apache Airflow has a Path Traversal issue

▾ Sunlitapache-airflow-providers-samba · apache-airflow-providers-sambaEPSS 0.97%via OSV
MAL-2026-5345None
3mo ago

Malicious code in dstill (PyPI)

Malicious code in dstill (PyPI)

▾ Sunlitdstill · dstillvia OSV
CVE-2026-11466Medium· 5.4
3mo ago

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

▾ Sunlitdeepsearcher · deepsearcherEPSS 0.25%via OSV
MAL-2026-5334None
3mo ago

Malicious code in spaysrbx (PyPI)

Malicious code in spaysrbx (PyPI)

▾ Sunlitspaysrbx · spaysrbxvia OSV
MAL-2026-5329None
3mo ago

Malicious code in spaysdatarbx (PyPI)

Malicious code in spaysdatarbx (PyPI)

▾ Sunlitspaysdatarbx · spaysdatarbxvia OSV
CVE-2026-11529Medium· 6.3
3mo ago

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

▾ Sunlitmysql-mcp-server · mysql-mcp-serverEPSS 0.21%via OSV
MAL-2026-5330None
3mo ago

Malicious code in bittensor-burn-alert (PyPI)

Malicious code in bittensor-burn-alert (PyPI)

▾ Sunlitbittensor-burn-alert · bittensor-burn-alertvia OSV
MAL-2026-5335None
3mo ago

Malicious code in xfoobar (PyPI)

Malicious code in xfoobar (PyPI)

▾ Sunlitxfoobar · xfoobarvia OSV
MAL-2026-5332None
3mo ago

Malicious code in xforpy (PyPI)

Malicious code in xforpy (PyPI)

▾ Sunlitxforpy · xforpyvia OSV
CVEs tagged “pip” — page 49 · VulnSea