Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-23528MediumDask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
CVE-2026-23535High· 8.0Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
CVE-2026-23490High· 7.5PoCpyasn1 is a generic ASN.1 library for Python
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
CVE-2025-68492Medium· 4.2Chainlit contains an authorization bypass vulnerability
Chainlit contains an authorization bypass vulnerability
CVE-2026-22779MediumBlackSheep's ClientSession is vulnerable to CRLF injection
BlackSheep's ClientSession is vulnerable to CRLF injection
CVE-2026-21889LowWeblate leaks information via screenshots
Weblate leaks information via screenshots
CVE-2026-22871HighGuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE
GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE
CVE-2026-21226High· 7.5Azure Core is vulnerable to deserialization of untrusted data
Azure Core is vulnerable to deserialization of untrusted data
CVE-2026-22798Medium· 5.9hermes's raw options logging may disclose secrets passed in via subcommand options argument
hermes's raw options logging may disclose secrets passed in via subcommand options argument
CVE-2026-22870HighGuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
CVE-2026-22702Medium· 4.5virtualenv Has TOCTOU Vulnerabilities in Directory Creation
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
CVE-2026-23949High· 8.6jaraco.context Has a Path Traversal Vulnerability
jaraco.context Has a Path Traversal Vulnerability
CVE-2026-22777High· 7.5ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
MAL-2026-237NoneMalicious code in formater (PyPI)
Malicious code in formater (PyPI)
MAL-2026-236NoneMalicious code in graponater (PyPI)
Malicious code in graponater (PyPI)
CVE-2025-14279High· 8.1MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
CVE-2026-22251Medium· 5.3Weblate wlc has insecure API key configuration
Weblate wlc has insecure API key configuration
CVE-2026-22033HighLabel Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
CVE-2026-22250Low· 2.5Weblate command-line client susceptible to SSL verification skip
Weblate command-line client susceptible to SSL verification skip
CVE-2025-15506Low· 3.3AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
CVE-2026-22701Medium· 5.3filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)
A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…
CVE-2025-15504Low· 3.3LIEF is vulnerable to segmentation fault
LIEF is vulnerable to segmentation fault
CVE-2026-22606HighFickling has a bypass via runpy.run_path() and runpy.run_module()
Fickling has a bypass via runpy.run_path() and runpy.run_module()
CVE-2026-22609HighFickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22607HighFickling Blocklist Bypass: cProfile.run()
Fickling Blocklist Bypass: cProfile.run()
CVE-2026-22612HighFickling vulnerable to detection bypass due to "builtins" blindness
Fickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22608HighFickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2026-22690Lowpypdf has possible long runtimes for missing /Root object with large /Size values
pypdf has possible long runtimes for missing /Root object with large /Size values
CVE-2026-22691Lowpypdf has possible long runtimes for malformed startxref
pypdf has possible long runtimes for malformed startxref
CVE-2023-7333Medium· 5.3records-mover Injection vulnerability
records-mover Injection vulnerability