Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-33155HighDeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
CVE-2026-33140MediumStored XSS in PySpector HTML Report Generation leads to Javascript Code Execution
Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution
CVE-2026-27459Critical· 9.8⚖ disputedpyOpenSSL is a Python wrapper around the OpenSSL library
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL wou…
CVE-2026-9769HighUncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
CVE-2026-4269High· 7.5Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
CVE-2026-28500High· 8.6ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVE-2025-14287High· 7.5MLflow has a command injection in mlflow/sagemaker/__init__.py
MLflow has a command injection in mlflow/sagemaker/__init__.py
CVE-2026-32596HighPoCGlances exposes the REST API without authentication
Glances exposes the REST API without authentication
CVE-2026-32634High· 8.1Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
CVE-2026-27448LowpyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
CVE-2026-32608High· 7.0Glances has a Command Injection via Process Names in Action Command Templates
Glances has a Command Injection via Process Names in Action Command Templates
CVE-2026-32722Low· 3.6PoCStored XSS in Memray-generated HTML reports via unescaped command-line metadata
Stored XSS in Memray-generated HTML reports via unescaped command-line metadata
CVE-2026-32632Medium· 5.9Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
CVE-2026-32609High· 7.5Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
CVE-2026-32610High· 8.1Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
CVE-2026-28490HighAuthlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVE-2026-4229High· 7.3Vanna has a SQL injection in the remove_training_data function
Vanna has a SQL injection in the remove_training_data function
CVE-2026-32611High· 7.0Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
CVE-2026-31899High· 7.5PoCCairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
CVE-2026-32116HighMagic Wormhole: "wormhole receive" allows arbitrary local file overwrite
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
CVE-2026-32597High· 7.5PoCPyJWT is a JSON Web Token implementation in Python
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …
CVE-2026-32112Medium· 6.8ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
CVE-2026-3989High· 7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-32247High· 8.1PoCGraphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
CVE-2026-32111Medium· 5.3ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
CVE-2026-32274High· 7.5Black: Arbitrary file writes from unsanitized user input in cache file name
Black: Arbitrary file writes from unsanitized user input in cache file name
CVE-2026-28356High· 7.5multipart is a fast multipart/form-data parser for python
multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential back…
CVE-2026-31900Critical· 9.8PoCBlack is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…
CVE-2026-31826Mediumpypdf: manipulated stream length values can exhaust RAM
pypdf: manipulated stream length values can exhaust RAM
CVE-2026-31815Medium· 5.3django-unicorn affected by component state manipulation via unvalidated attribute access
django-unicorn affected by component state manipulation via unvalidated attribute access