conda has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.1 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
conda vulnerabilities
CVEs affecting conda, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-53940High· 8.8PoCConda is a system-level binary package and environment manager that runs on major operating systems and platforms
Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…
▾ Midnightconda · condavia NVD
CVE-2026-53956Medium· 5.4Rattler vulnerable to package cache path traversal via conda package build string
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…
▾ Sunlitconda · rattler_cacheEPSS 0.24%via CVEORG