Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-21874Medium· 5.3NiceGUI has Redis connection leak via tab storage causes service degradation
NiceGUI has Redis connection leak via tab storage causes service degradation
CVE-2026-21873High· 7.2NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
CVE-2026-21872Medium· 6.1NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
CVE-2025-68158Medium· 5.7Authlib has 1-click Account Takeover vulnerability
Authlib has 1-click Account Takeover vulnerability
CVE-2026-53872High· 7.5picklescan has Arbitrary file read using `io.FileIO`
picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-21860Medium· 5.3Werkzeug safe_join() allows Windows special device names with compound extensions
Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2026-21871Medium· 6.1NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
CVE-2025-61782Medium· 6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callbac…
CVE-2026-22041Lowloggingredactor converts non-string types to string types in logs
loggingredactor converts non-string types to string types in logs
CVE-2026-21441High· 7.5urllib3 is an HTTP client library for Python
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urll…
MAL-2026-96NoneMalicious code in pycolorom (PyPI)
Malicious code in pycolorom (PyPI)
CVE-2025-69230Medium· 5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an a…
CVE-2026-21892Medium· 5.3Parsl Monitoring Visualization Vulnerable to SQL Injection
Parsl Monitoring Visualization Vulnerable to SQL Injection
CVE-2026-21851Medium· 5.3MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
CVE-2026-21883MediumBokeh server applications have Incomplete Origin Validation in WebSockets
Bokeh server applications have Incomplete Origin Validation in WebSockets
MAL-2026-42NoneMalicious code in pyrogrom (PyPI)
Malicious code in pyrogrom (PyPI)
CVE-2026-21439Lowbadkeys vulnerable to ASCII control character injection on console via malformed input
badkeys vulnerable to ASCII control character injection on console via malformed input
CVE-2025-69225LowAIOHTTP has unicode match groups in regexes for ASCII protocol elements
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
CVE-2025-69227High· 7.5aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)
A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provide…
CVE-2025-69229MediumAIOHTTP vulnerable to DoS through chunked messages
AIOHTTP vulnerable to DoS through chunked messages
CVE-2025-69228Medium· 6.8aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)
A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Servi…
CVE-2025-69224LowAIOHTTP's unicode processing of header values could cause parsing discrepancies
AIOHTTP's unicode processing of header values could cause parsing discrepancies
CVE-2025-69226LowAIOHTTP vulnerable to brute-force leak of internal static file path components
AIOHTTP vulnerable to brute-force leak of internal static file path components
CVE-2025-69223High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that …
CVE-2026-21445HighPoCLangflow Missing Authentication on Critical API Endpoints
Langflow Missing Authentication on Critical API Endpoints
CVE-2025-68131MediumCBORDecoder reuse can leak shareable values across decode calls
CBORDecoder reuse can leak shareable values across decode calls
MAL-2025-193011NoneMalicious code in requeses (PyPI)
Malicious code in requeses (PyPI)
MAL-2025-193010NoneMalicious code in pyrogrqm (PyPI)
Malicious code in pyrogrqm (PyPI)
MAL-2025-193008NoneMalicious code in telegreph (PyPI)
Malicious code in telegreph (PyPI)
MAL-2025-193007NoneMalicious code in aiogrem (PyPI)
Malicious code in aiogrem (PyPI)