Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-24486High· 8.6PoCPython-Multipart is a streaming multipart parser for Python
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …
CVE-2026-24408None· 0.0sigstore CSRF possibility in OIDC authentication during signing
sigstore CSRF possibility in OIDC authentication during signing
CVE-2026-24489Medium· 5.3Gakido vulnerable to HTTP Header Injection (CRLF Injection)
Gakido vulnerable to HTTP Header Injection (CRLF Injection)
CVE-2026-24490High· 8.1MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
CVE-2026-24123High· 7.4BentoML has a Path Traversal via Bentofile Configuration
BentoML has a Path Traversal via Bentofile Configuration
CVE-2025-11687Medium· 6.1GI-DocGen vulnerable to Reflected XSS via unescaped query strings
GI-DocGen vulnerable to Reflected XSS via unescaped query strings
CVE-2026-24688MediumPoCpypdf has possible Infinite Loop when processing outlines/bookmarks
pypdf has possible Infinite Loop when processing outlines/bookmarks
CVE-2026-0770HighCISA KEV0dayPoCLangflow affected by Remote Code Execution via validate_code() exec()
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-0994High· 7.5PoCA denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…
CVE-2025-67221HighPoCorjson does not limit recursion for deeply nested JSON documents
orjson does not limit recursion for deeply nested JSON documents
MAL-2026-470NoneMalicious code in urlsssser (PyPI)
Malicious code in urlsssser (PyPI)
MAL-2026-468NoneMalicious code in urlsser (PyPI)
Malicious code in urlsser (PyPI)
CVE-2026-24009High· 8.1PoCdocling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
CVE-2025-71176Medium· 6.8pytest has vulnerable tmpdir handling
pytest has vulnerable tmpdir handling
CVE-2026-24130LowMoonraker affected by LDAP search filter injection
Moonraker affected by LDAP search filter injection
CVE-2026-1260High· 7.8Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
CVE-2026-24049High· 7.1PoCwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after e…
CVE-2026-23968Medium· 5.5Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
CVE-2026-23877MediumSwing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user
Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user
CVE-2026-23996Low· 3.7FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
CVE-2026-23833MediumESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
CVE-2026-23986High· 7.1Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
CVE-2026-23946Medium· 6.8Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
CVE-2026-22807High· 8.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…
CVE-2026-23842High· 7.5PoCChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion
ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion
CVE-2026-22219High· 7.7Chainlit contain a server-side request forgery (SSRF) vulnerability
Chainlit contain a server-side request forgery (SSRF) vulnerability
MAL-2026-326NoneMalicious code in urlssser (PyPI)
Malicious code in urlssser (PyPI)
MAL-2026-325NoneMalicious code in marshel (PyPI)
Malicious code in marshel (PyPI)
CVE-2025-68675High· 7.5Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
CVE-2025-68438High· 7.5Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated