Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-56078Medium· 6.5PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
CVE-2026-39981High· 8.8AGiXT Vulnerable to Path Traversal in safe_join()
AGiXT Vulnerable to Path Traversal in safe_join()
CVE-2026-33753Medium· 6.2rfc3161-client Has Improper Certificate Validation
rfc3161-client Has Improper Certificate Validation
CVE-2026-40035Critical· 9.1PoCUnfurl - Werkzeug Debugger Exposure via String Config Parsing
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-em…
CVE-2026-40036High· 7.5PoCUnfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/…
CVE-2026-39892Critical· 9.8⚖ disputedcryptography is a package designed to expose cryptographic primitives and recipes to Python developers
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …
CVE-2026-4292Low· 2.7Django vulnerable to privilege abuse in ModelAdmin.list_editable
Django vulnerable to privilege abuse in ModelAdmin.list_editable
CVE-2026-39373High· 7.5⚖ disputedJWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)
A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An unauthenticated attacker can exploit this vulnerability by sending specially crafted JWE toke…
CVE-2026-33034High· 7.5Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
CVE-2026-33033Medium· 6.5PoCDjango has potential DoS via MultiPartParser through crafted multipart uploads
Django has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-33866Medium· 4.3MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
GHSA-89gg-p5r5-q6r4High· 7.6MONAI: Unsafe functions lead to pickle deserialization rce
MONAI: Unsafe functions lead to pickle deserialization rce
CVE-2026-22680Medium· 5.3OpenViking contains a missing authorization vulnerability in the task polling endpoints
OpenViking contains a missing authorization vulnerability in the task polling endpoints
CVE-2026-1839Medium· 6.5HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
CVE-2026-34444Critical· 10.0PoCLupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
CVE-2026-1114Critical· 9.8LoLLMs is vulnerable to Improper Access Control through weak secret key
LoLLMs is vulnerable to Improper Access Control through weak secret key
CVE-2025-64182High· 7.8OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
CVE-2026-39308High· 7.1PraisonAI recipe registry publish path traversal allows out-of-root file write
PraisonAI recipe registry publish path traversal allows out-of-root file write
CVE-2026-26981Medium· 6.5OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
CVE-2026-35492Medium· 6.5PoCkedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
CVE-2026-34588High· 8.6OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working w…
CVE-2025-64183High· 7.5OpenEXR has use after free in PyObject_StealAttrString
OpenEXR has use after free in PyObject_StealAttrString
CVE-2026-39306High· 7.3PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
CVE-2026-39307High· 8.1PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
CVE-2025-64181High· 7.5OpenEXR Makes Use of Uninitialized Memory
OpenEXR Makes Use of Uninitialized Memory
CVE-2026-34756Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the…
CVE-2026-34755Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPE…
CVE-2026-5559Medium· 6.3PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py
PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py
CVE-2026-35463High· 8.8pyLoad: Improper Neutralization of Special Elements used in an OS Command
pyLoad: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-30762High· 7.5LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass