Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-44264Medium· 4.3Weblate vulnerable to XSS via crafted Markdown
Weblate vulnerable to XSS via crafted Markdown
CVE-2026-44661Medium· 4.7utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
MAL-2026-3370NoneMalicious code in sufiagent (PyPI)
Malicious code in sufiagent (PyPI)
CVE-2026-44334High· 8.4PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
CVE-2026-42544High· 7.5Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
CVE-2026-44305Medium· 6.8Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
CVE-2026-44405Low· 3.4Paramiko rsakey.py allows the SHA-1 algorithm
Paramiko rsakey.py allows the SHA-1 algorithm
CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass
PraisonAI has an SSRF bypass
CVE-2026-42561High· 7.5python-multipart has Denial of Service via unbounded multipart part headers
python-multipart has Denial of Service via unbounded multipart part headers
CVE-2026-42557Critical· 9.6JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
CVE-2026-44363Mediummisp-modules has nsafe remote resource fetching in expansion
misp-modules has nsafe remote resource fetching in expansion
CVE-2026-42545Medium· 5.9Granian vulnerable to DoS via WSGI response header panic
Granian vulnerable to DoS via WSGI response header panic
CVE-2026-42448Low· 3.5Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
CVE-2026-44226Medium· 5.3PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
CVE-2026-44368Mediumpyquorum: Timing side‑channel in mul_mod
pyquorum: Timing side‑channel in mul_mod
CVE-2026-44243High· 7.1GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
CVE-2026-44439High· 7.5Playwright Capture permits access to local files and internal network resources during page capture
Playwright Capture permits access to local files and internal network resources during page capture
CVE-2026-44304High· 8.1Lemur: LDAP Filter Injection enables post-authentication privilege escalation
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
CVE-2026-44307HighMako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
CVE-2026-33079High· 7.5In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service
In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular ex…
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
Django has an Improper Handling of Length Parameter Inconsistency
CVE-2025-61669MediumJupyter Server has an open redirection vulnerability in `next` query parameter
Jupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2026-42304High· 7.5Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVE-2026-40934Medium· 6.8Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
CVE-2026-6907Medium· 4.3Django Uses Cache Containing Sensitive Information
Django Uses Cache Containing Sensitive Information
CVE-2026-35397High· 8.8PoCJupyter Server is the backend for Jupyter web applications
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…
CVE-2026-44219Low· 3.7ciguard: SCA HTTP client reads response body without size cap
ciguard: SCA HTTP client reads response body without size cap
CVE-2026-7846Low· 2.6Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
CVE-2026-7845Low· 2.6Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
CVE-2026-43002Medium· 5.3An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…