pypa has 2 CVEs on record between 2021 and 2026. The median CVSS is 5.6 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.6
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2021-3572Medium· 5.7A flaw was found in python-pip in the way it handled Unicode separators in git references44CVE-2026-8643Medium· 5.5pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.30
pypa vulnerabilities
CVEs affecting pypa, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-8643Medium· 5.5⚖ disputedpip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
▾ Sunlitpypa · pipEPSS 0.32%via NVD
CVE-2021-3572Medium· 5.7PoCA flaw was found in python-pip in the way it handled Unicode separators in git references
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to …
▾ Twilightpypa · pipEPSS 1.8%via NVD