Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-2945NoneMalicious code in moonbit-locale-compat (PyPI)
Malicious code in moonbit-locale-compat (PyPI)
CVE-2026-32690Low· 3.7Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
CVE-2026-41490High· 8.3PoCDagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
CVE-2026-32228High· 7.5Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
CVE-2026-25917High· 7.2Apache Airflow allows code execution through crafted XCom payloads
Apache Airflow allows code execution through crafted XCom payloads
CVE-2026-40948Medium· 5.4apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
CVE-2026-40525Critical· 9.1OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
CVE-2026-35402LowNeo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures
Neo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures
CVE-2026-41496High· 8.1PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-41205High· 7.5Mako: Path traversal via double-slash URI prefix in TemplateLookup
Mako: Path traversal via double-slash URI prefix in TemplateLookup
CVE-2026-41425Medium· 5.4Authlib: Cross-site request forging when using cache
Authlib: Cross-site request forging when using cache
CVE-2026-41481Medium· 6.5LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-40474High· 7.6wger has Broken Access Control in Global Gym Configuration Update Endpoint
wger has Broken Access Control in Global Gym Configuration Update Endpoint
CVE-2026-41314Medium· 6.5pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVE-2026-41206MediumPySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_code
PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_code
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API
Weblate: Improper access control for pending tasks in API
CVE-2025-54550High· 8.1Apache Airflow: RCE by race condition in example_xcom dag
Apache Airflow: RCE by race condition in example_xcom dag
CVE-2026-31987High· 7.5Apache Airflow: JWT token appearing in logs
Apache Airflow: JWT token appearing in logs
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
Weblate: Arbitrary File Read via Symlink
CVE-2026-40256Medium· 5.0Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVE-2026-41312Medium· 6.5pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-40353Medium· 5.4wger has Stored XSS via Unescaped License Attribution Fields
wger has Stored XSS via Unescaped License Attribution Fields
CVE-2026-33440Medium· 5.0Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVE-2026-41313Medium· 6.5pypdf: Possible long runtimes for wrong size values in incremental mode
pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-40602Medium· 5.6Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
CVE-2026-6855High· 7.1instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…
CVE-2026-40347Medium· 5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
CVE-2026-41168Medium· 5.3pypdf has long runtimes for wrong size values in cross-reference and object streams
pypdf has long runtimes for wrong size values in cross-reference and object streams