Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-46447Medium· 5.8OpenStack Ironic allows Boot Script Injection
OpenStack Ironic allows Boot Script Injection
CVE-2026-48681Medium· 5.9OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
CVE-2026-41283Critical· 9.9OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
CVE-2026-10783Low· 2.5Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-47706Medium· 5.3Strawberry GraphQL has a Circular Fragment Reference DOS
Strawberry GraphQL has a Circular Fragment Reference DOS
CVE-2026-47707Medium· 5.3Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
CVE-2026-35193Low· 3.1Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
CVE-2026-6873Low· 3.1Django: signed cookies are vulnerable to salt namespace collisions
Django: signed cookies are vulnerable to salt namespace collisions
CVE-2026-48587Low· 3.1Django: has_vary_header may expose cached responses when Vary values contain whitespace
Django: has_vary_header may expose cached responses when Vary values contain whitespace
CVE-2026-8404Low· 3.1Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
MAL-2026-5173NoneMalicious code in spadata (PyPI)
Malicious code in spadata (PyPI)
CVE-2026-44020High· 7.5Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-10766Low· 3.6mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
CVE-2026-44018Medium· 5.5Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-44016High· 8.2Docling: Unsafe Playwright-based HTML Rendering
Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-7666Low· 3.1Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-44023High· 8.6Docling Core: Unsafe remote filename resolution
Docling Core: Unsafe remote filename resolution
CVE-2026-44019High· 8.1Docling Core: Insufficient validation of image reference URIs
Docling Core: Insufficient validation of image reference URIs
CVE-2026-47265MediumAIOHTTP is vulnerable to cross-origin redirect with per-request cookies
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
CVE-2026-5241High· 7.7python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting (CVE-2026-5241)
A flaw was found in python-transformers. An attacker can exploit this vulnerability by providing a malicious model repository. During model initialization, the `trust_remote_code` parameter, intended to prevent remote code execution, is ov…
CVE-2026-44017High· 7.5Docling: Unsafe Zip Extraction in EasyOCR Model Download
Docling: Unsafe Zip Extraction in EasyOCR Model Download
CVE-2026-44022Medium· 5.5Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
CVE-2026-44546Low· 3.7daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
CVE-2026-44545Medium· 5.3daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames
daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames
CVE-2026-4035Critical· 9.1MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
CVE-2026-10692Medium· 4.3Code Index MCP is vulnerable to Uncontrolled Resource Consumption
Code Index MCP is vulnerable to Uncontrolled Resource Consumption
MAL-2026-5171NoneMalicious code in spaysdata (PyPI)
Malicious code in spaysdata (PyPI)
MAL-2026-5170NoneMalicious code in spaysrbdata (PyPI)
Malicious code in spaysrbdata (PyPI)
CVE-2026-47117Critical· 9.8PoCOpenMed vulnerable to remote code injection through privacy-filter model loading path
OpenMed vulnerable to remote code injection through privacy-filter model loading path
CVE-2026-34993High· 7.2aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993)
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. An attacker could exploit this vulnerability by providing untrusted input to the `CookieJar.load()` function. This could potentially lead to …