Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-38743Medium· 4.3Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInst…
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
CVE-2026-41486HighRay: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVE-2026-42150Medium· 5.1wlc: print_html outputs API data without HTML escaping
wlc: print_html outputs API data without HTML escaping
CVE-2026-41140High· 8.7poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)
A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked int…
CVE-2026-3960Critical· 9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…
CVE-2026-6878Medium· 5.6verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
CVE-2026-6827Mediumjusthtml has sanitization bypass in custom policies and programmatic DOM
justhtml has sanitization bypass in custom policies and programmatic DOM
CVE-2026-6859High· 8.8InstructLab Includes Functionality from Untrusted Control Sphere
InstructLab Includes Functionality from Untrusted Control Sphere
CVE-2026-41066High· 7.5lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-28684Medium· 6.6python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
CVE-2026-35588Medium· 6.3Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
CVE-2026-34839Medium· 6.5Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVE-2026-35587High· 8.8Glances has SSRF in IP Plugin via public_api leading to credential leakage
Glances has SSRF in IP Plugin via public_api leading to credential leakage
CVE-2026-39378Medium· 6.5nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
CVE-2026-33626High· 7.5PoCLMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2026-39377Medium· 6.5nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
CVE-2026-6596High· 7.3Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
CVE-2026-6599Medium· 6.3Langflow vulnerable to injection
Langflow vulnerable to injection
CVE-2025-66335Medium· 5.3Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
CVE-2026-6608Medium· 5.3FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6606High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6603High· 7.3AgentScope Vulnerable to Remote Code Injection
AgentScope Vulnerable to Remote Code Injection
CVE-2026-6598Medium· 4.3Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6605High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6604High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6597Low· 2.7Langflow has an Information Leak through Incomplete API Key Redaction
Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-6607Medium· 5.3FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
CVE-2026-3219Mediumpip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
MAL-2026-2947NoneMalicious code in moonbit-schema-utils (PyPI)
Malicious code in moonbit-schema-utils (PyPI)
MAL-2026-2946NoneMalicious code in moonbit-metrics-validator (PyPI)
Malicious code in moonbit-metrics-validator (PyPI)