Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-5299NoneMalicious code in pantheon-agents (PyPI)
Malicious code in pantheon-agents (PyPI)
MAL-2026-5285NoneMalicious code in ufish (PyPI)
Malicious code in ufish (PyPI)
MAL-2026-5284NoneMalicious code in synago (PyPI)
Malicious code in synago (PyPI)
MAL-2026-5283NoneMalicious code in okite (PyPI)
Malicious code in okite (PyPI)
MAL-2026-5279NoneMalicious code in uprobe (PyPI)
Malicious code in uprobe (PyPI)
MAL-2026-5277NoneMalicious code in pantheon-toolsets (PyPI)
Malicious code in pantheon-toolsets (PyPI)
MAL-2026-5276NoneMalicious code in nucbox (PyPI)
Malicious code in nucbox (PyPI)
MAL-2026-5275NoneMalicious code in napari-ufish (PyPI)
Malicious code in napari-ufish (PyPI)
CVE-2026-37737Medium· 6.5sanic-cors contains an improper regular expression in the try_match() function
sanic-cors contains an improper regular expression in the try_match() function
CVE-2026-50589Medium· 5.3OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
CVE-2026-11312Low· 3.3bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map
CVE-2026-47715Low· 3.1Bugsink: Issue event views can show an event from another project if its UUID is known
Bugsink: Issue event views can show an event from another project if its UUID is known
CVE-2026-47716Low· 3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
CVE-2026-47419High· 8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2024-24769LowVantage6: No limit on emails sent for password/MFA reset
Vantage6: No limit on emails sent for password/MFA reset
CVE-2026-47728Medium· 4.3Bugsink: Project scoping missing in sourcemap and debug-file lookup
Bugsink: Project scoping missing in sourcemap and debug-file lookup
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
Vantage6: 2FA can be circumvented with hacked email access
CVE-2026-54533Mediumvantage6 node has an Improper Access Control issue
vantage6 node has an Improper Access Control issue
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
Vantage6: Set admin user and password from environment or configuration
MAL-2026-5273NoneMalicious code in anthropy (PyPI)
Malicious code in anthropy (PyPI)
CVE-2026-45409Medium· 5.3python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)
A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding f…
CVE-2026-10775Low· 3.6SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-44889Medium· 6.1WebOb: Location header normalization during redirect leads to open redirect - again
WebOb: Location header normalization during redirect leads to open redirect - again
CVE-2026-10812Low· 3.6GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix
GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix
CVE-2026-10804Low· 3.6Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-44393High· 7.4OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
CVE-2026-10803Low· 2.5mlflow: MLflow: Use of weak hash in Dataset Digest Computation (CVE-2026-10803)
A flaw was found in MLflow. This vulnerability stems from the use of a weak hash algorithm within the Dataset Digest Computation component. A local attacker could potentially exploit this weakness, which may impact the integrity or authent…
CVE-2026-10813Low· 3.6LMCache: 16-bit multimodal hash collision can poison KV cache entries
LMCache: 16-bit multimodal hash collision can poison KV cache entries
CVE-2026-10801Low· 3.6ms-swift: Image Cache Hash Collision via Missing Dimension Metadata
ms-swift: Image Cache Hash Collision via Missing Dimension Metadata