Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue
OpenStack Keystone has an Incorrect Authorization issue
CVE-2026-42998Medium· 6.0OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
CVE-2026-42999High· 8.3⚖ disputedopenstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection (CVE-2026-429…
A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perfo…
CVE-2026-48523Medium· 5.4PyJWT is a JSON Web Token implementation in Python
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked agains…
CVE-2026-48526High· 7.4PoCPyJWT is a JSON Web Token implementation in Python
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorith…
CVE-2026-47104Medium· 5.5libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attack…
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size…
CVE-2026-23679Medium· 5.5libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a…
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero bu…
CVE-2026-49017Medium· 6.5In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-s…
CVE-2026-45309MediumAsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
CVE-2026-44660High· 7.5python-ujson: UltraJSON: Memory leak leading to Denial of Service (CVE-2026-44660)
A flaw was found in UltraJSON, a fast JSON encoder and decoder. When the `ujson.dump()` function attempts to write data to a file-like object and an error occurs during this operation, the memory allocated for the serialized JSON string is…
CVE-2026-49014High· 7.4GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow
GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow
CVE-2026-25879Critical· 9.8Langroid has Prompt to SQL Injection, Leading to RCE
Langroid has Prompt to SQL Injection, Leading to RCE
CVE-2026-48545Medium· 6.8Gradio contains a cookie injection vulnerability
Gradio contains a cookie injection vulnerability
CVE-2026-9712Lowpretix vulnerable to Authorization Bypass Through User-Controlled Key
pretix vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2026-48544High· 7.5Taipy contains a path traversal vulnerability
Taipy contains a path traversal vulnerability
CVE-2026-9368High· 7.3hermes-agent has a sandbox issue
hermes-agent has a sandbox issue
CVE-2026-9366High· 7.3hermes-agent has an Injection issue
hermes-agent has an Injection issue
CVE-2026-46745Medium· 5.3Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
CVE-2026-3515High· 8.5Prefect has an Argument Injection issue
Prefect has an Argument Injection issue
CVE-2026-9369Medium· 5.3hermes-agent has an Incorrect Comparison
hermes-agent has an Incorrect Comparison
CVE-2026-9540Medium· 5.3vllm has Improper Resource Shutdown or Release
vllm has Improper Resource Shutdown or Release
CVE-2026-2651Critical· 9.0MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
CVE-2026-9353High· 7.3hermes-agent has an Injection issue
hermes-agent has an Injection issue
CVE-2026-4372High· 7.8HuggingFace transformers vulnerable to remote code execution
HuggingFace transformers vulnerable to remote code execution
CVE-2026-48710Medium· 6.5CISA KEVPoCStarlette is a lightweight ASGI framework/toolkit
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…
CVE-2026-45361High· 8.1Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the s…
CVE-2026-47157Medium· 6.5aiograpi: Unsafe signup challenge path handling
aiograpi: Unsafe signup challenge path handling
CVE-2026-46715MediumFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
CVE-2026-46695Critical· 10.0BoxLite: Permission Bypass Allows Modification of Read-Only Files
BoxLite: Permission Bypass Allows Modification of Read-Only Files