VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-44394Medium· 6.0
4mo ago

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

▾ Sunlitkeystone · keystoneEPSS 0.32%via OSV
CVE-2026-43000Medium· 6.0
4mo ago

OpenStack Keystone has an Incorrect Authorization issue

OpenStack Keystone has an Incorrect Authorization issue

▾ Sunlitkeystone · keystoneEPSS 0.43%via OSV
CVE-2026-42998Medium· 6.0
4mo ago

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

▾ Sunlitkeystone · keystoneEPSS 0.40%via OSV
CVE-2026-42999High· 8.3⚖ disputed
4mo ago

openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection (CVE-2026-429…

A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perfo…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.42%via CSAF
CVE-2026-48523Medium· 5.4
4mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked agains…

▾ Sunlitpyjwt_project · pyjwtEPSS 0.17%via NVD
CVE-2026-48526High· 7.4PoC
4mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorith…

▾ Midnightpyjwt_project · pyjwtEPSS 0.43%via NVD
CVE-2026-47104Medium· 5.5
4mo ago

libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attack…

libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size…

▾ Sunlitlibusb · libusbEPSS 0.19%via OSV
CVE-2026-23679Medium· 5.5
4mo ago

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a…

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero bu…

▾ Sunlitlibusb · libusbEPSS 0.18%via OSV
CVE-2026-49017Medium· 6.5
4mo ago

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-s…

▾ Sunlitopenstack · swiftEPSS 0.36%via NVD
CVE-2026-45309Medium
4mo ago

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

▾ Sunlitasyncssh · asyncsshEPSS 0.59%via OSV
CVE-2026-44660High· 7.5
4mo ago

python-ujson: UltraJSON: Memory leak leading to Denial of Service (CVE-2026-44660)

A flaw was found in UltraJSON, a fast JSON encoder and decoder. When the `ujson.dump()` function attempts to write data to a file-like object and an error occurs during this operation, the memory allocated for the serialized JSON string is…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-49014High· 7.4
4mo ago

GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow

GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow

▾ Twilightgdal · gdalEPSS 0.15%via OSV
CVE-2026-25879Critical· 9.8
4mo ago

Langroid has Prompt to SQL Injection, Leading to RCE

Langroid has Prompt to SQL Injection, Leading to RCE

▾ Midnightlangroid · langroidEPSS 0.69%via OSV
CVE-2026-48545Medium· 6.8
4mo ago

Gradio contains a cookie injection vulnerability

Gradio contains a cookie injection vulnerability

▾ Sunlitgradio · gradioEPSS 0.47%via OSV
CVE-2026-9712Low
4mo ago

pretix vulnerable to Authorization Bypass Through User-Controlled Key

pretix vulnerable to Authorization Bypass Through User-Controlled Key

▾ Sunlitpretix · pretixEPSS 0.35%via OSV
CVE-2026-48544High· 7.5
4mo ago

Taipy contains a path traversal vulnerability

Taipy contains a path traversal vulnerability

▾ Twilighttaipy · taipyEPSS 0.60%via OSV
CVE-2026-9368High· 7.3
4mo ago

hermes-agent has a sandbox issue

hermes-agent has a sandbox issue

▾ Twilighthermes-agent · hermes-agentEPSS 0.64%via OSV
CVE-2026-9366High· 7.3
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Twilighthermes-agent · hermes-agentEPSS 0.52%via OSV
CVE-2026-46745Medium· 5.3
4mo ago

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

▾ Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.76%via OSV
CVE-2026-3515High· 8.5
4mo ago

Prefect has an Argument Injection issue

Prefect has an Argument Injection issue

▾ Twilightprefect · prefectEPSS 0.48%via OSV
CVE-2026-9369Medium· 5.3
4mo ago

hermes-agent has an Incorrect Comparison

hermes-agent has an Incorrect Comparison

▾ Sunlithermes-agent · hermes-agentEPSS 0.32%via OSV
CVE-2026-9540Medium· 5.3
4mo ago

vllm has Improper Resource Shutdown or Release

vllm has Improper Resource Shutdown or Release

▾ Sunlitvllm · vllmEPSS 0.72%via OSV
CVE-2026-2651Critical· 9.0
4mo ago

MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled

MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled

▾ Midnightmlflow · mlflowEPSS 0.54%via OSV
CVE-2026-9353High· 7.3
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Twilighthermes-agent · hermes-agentEPSS 0.52%via OSV
CVE-2026-4372High· 7.8
4mo ago

HuggingFace transformers vulnerable to remote code execution

HuggingFace transformers vulnerable to remote code execution

▾ Twilighttransformers · transformersEPSS 0.60%via OSV
CVE-2026-48710Medium· 6.5CISA KEVPoC
4mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

▾ Midnightstarlette · starletteEPSS 7.1%via NVD
CVE-2026-45361High· 8.1
4mo ago

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the s…

▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 0.80%via OSV
CVE-2026-47157Medium· 6.5
4mo ago

aiograpi: Unsafe signup challenge path handling

aiograpi: Unsafe signup challenge path handling

▾ Sunlitaiograpi · aiograpiEPSS 0.30%via OSV
CVE-2026-46715Medium
4mo ago

Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance

Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance

▾ Sunlitflask-security-too · flask-security-tooEPSS 0.49%via OSV
CVE-2026-46695Critical· 10.0
4mo ago

BoxLite: Permission Bypass Allows Modification of Read-Only Files

BoxLite: Permission Bypass Allows Modification of Read-Only Files

▾ Midnightboxlite · boxliteEPSS 0.48%via OSV
CVEs tagged “pip” — page 55 · VulnSea