VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-40072High· 7.2PoC
5mo ago

web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

▾ Midnightweb3 · web3EPSS 0.31%via OSV
CVE-2026-35187High· 7.7
5mo ago

pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter

pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter

▾ Twilightpyload-ng · pyload-ngEPSS 0.36%via OSV
CVE-2026-35464High· 7.5
5mo ago

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33…

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)

▾ Twilightpyload-ng · pyload-ngEPSS 0.61%via OSV
CVE-2026-0545Critical· 9.8PoC
5mo ago

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job e…

▾ Abyssallfprojects · mlflowEPSS 4.4%via NVD
CVE-2026-34543High
5mo ago

OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)

OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)

▾ Twilightopenexr · openexrEPSS 0.52%via OSV
CVE-2026-33175High· 8.8
5mo ago

Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims

Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims

▾ Twilightoauthenticator · oauthenticatorEPSS 0.64%via OSV
CVE-2026-33752High· 8.6PoC
5mo ago

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

▾ Midnightcurl-cffi · curl-cffiEPSS 0.45%via OSV
CVE-2026-34753Medium· 5.4PoC
5mo ago

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

▾ Twilightvllm · vllmEPSS 0.30%via OSV
CVE-2026-34544High
5mo ago

OpenEXR: integer overflow to OOB write in uncompress_b44_impl()

OpenEXR: integer overflow to OOB write in uncompress_b44_impl()

▾ Twilightopenexr · openexrEPSS 0.21%via OSV
CVE-2026-34052Medium· 5.9
5mo ago

LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)

LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)

▾ Sunlitjupyterhub-ltiauthenticator · jupyterhub-ltiauthenticatorEPSS 0.41%via OSV
CVE-2026-35175High
5mo ago

Ajenti has an authorization bypass during custom package installation

Ajenti has an authorization bypass during custom package installation

▾ Twilightajenti-panel · ajenti-panelEPSS 0.38%via OSV
CVE-2026-35029HighPoC
5mo ago

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

▾ Midnightlitellm · litellmEPSS 4.0%via OSV
CVE-2026-35052Medium
5mo ago

D-Tale: Remote Code Execution through redis/shelf storage

D-Tale: Remote Code Execution through redis/shelf storage

▾ Sunlitdtale · dtaleEPSS 0.86%via OSV
CVE-2026-33709Medium· 6.1
5mo ago

JupyterHub has an Open Redirect Vulnerability

JupyterHub has an Open Redirect Vulnerability

▾ Sunlitjupyterhub · jupyterhubEPSS 0.30%via OSV
CVE-2026-34824High· 7.5
5mo ago

Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service

Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service

▾ Twilightmesop · mesopEPSS 0.67%via OSV
CVE-2026-35536Medium· 5.4
5mo ago

tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injecti…

▾ SunlitRed Hat · Red Hat OpenShift AI 2.25EPSS 0.29%via CSAF
CVE-2026-34760High· 7.1
6mo ago

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults t…

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 sp…

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2026-32871Critical· 10.0
6mo ago

FastMCP is a Pythonic way to build MCP servers and clients

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for const…

▾ Midnightjlowin · fastmcpEPSS 1.4%via NVD
GHSA-qc22-xmq4-qg46Medium
6mo ago

c2cciutils affected by CVE-2022-40896

c2cciutils affected by CVE-2022-40896

▾ Sunlitc2cciutils · c2cciutilsvia OSV
CVE-2026-34447Medium· 5.5
6mo ago

ONNX: External Data Symlink Traversal

ONNX: External Data Symlink Traversal

▾ Sunlitonnx · onnxEPSS 0.19%via OSV
CVE-2026-74877Medium
6mo ago

openssl-encrypt has no owner verification on key revocation — any client can revoke any key

openssl-encrypt has no owner verification on key revocation — any client can revoke any key

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.45%via OSV
CVE-2026-74876Medium
6mo ago

openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys

openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.35%via OSV
CVE-2026-74880Medium
6mo ago

openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage

openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.56%via OSV
CVE-2026-74879Medium
6mo ago

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.44%via OSV
CVE-2026-35000None
6mo ago

ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows …

ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc(…

▾ Sunlitchangedetection-io · changedetection-ioEPSS 0.47%via OSV
CVE-2026-34936High· 7.7
6mo ago

PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback

PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback

▾ Twilightpraisonai · praisonaiEPSS 0.35%via OSV
CVE-2026-34452Medium· 5.3
6mo ago

Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape

Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape

▾ Sunlitanthropic · anthropicEPSS 0.14%via OSV
CVE-2026-34937High· 7.8
6mo ago

PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution

PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.63%via OSV
CVE-2026-22815Medium
6mo ago

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

▾ Sunlitaiohttp · aiohttpEPSS 0.44%via OSV
CVE-2026-34955High· 8.8
6mo ago

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

▾ Twilightpraisonai · praisonaiEPSS 0.39%via OSV
CVEs tagged “pip” — page 70 · VulnSea