PyPI incidents
Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Malicious code in chroma-client (PyPI)
Malicious code in chroma-client (PyPI)
Malicious code in python-fork (PyPI)
Malicious code in python-fork (PyPI)
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
mysql-mcp-server: before 0.4.2
Malicious code in platform-telemetry-client (PyPI)
Malicious code in platform-telemetry-client (PyPI)
Malicious code in langgrap (PyPI)
Malicious code in langgrap (PyPI)
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
prowler-cloud: before 5.30.3
Malicious code in eth-account-web3 (PyPI)
Malicious code in eth-account-web3 (PyPI)
Malicious code in ollamaa (PyPI)
Malicious code in ollamaa (PyPI)
Malicious code in aitextutils-py (PyPI)
Malicious code in aitextutils-py (PyPI)
Malicious code in openaii (PyPI)
Malicious code in openaii (PyPI)
Malicious code in web3-eth-account (PyPI)
Malicious code in web3-eth-account (PyPI)
Malicious code in aitextkit-py (PyPI)
Malicious code in aitextkit-py (PyPI)
Malicious code in transfomers (PyPI)
Malicious code in transfomers (PyPI)
Malicious code in pymem-win (PyPI)
Malicious code in pymem-win (PyPI)
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
open-webui: 0.9.5 → 0.11.1
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
compliance-trestle: before 3.12.4
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython: before 3.1.59
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh: before 2.23.1
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
lightning: before 1.6.0
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
thrift: before 0.24.0
ChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
chromadb: ≥ 0.4.17
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
ironic: 17.0.0 → 29.0.6
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: before 0.6.0
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents: 1.5.128 → 1.6.58
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm: before 0.26.0
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
open-webui: 0.10.0 → 0.11.1
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
ONNX: TOCTOU arbitrary file read/write in save_external_dat
ONNX: TOCTOU arbitrary file read/write in save_external_dat
onnx: before 1.21.0
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
praisonai: before 4.6.58
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents: before 1.6.58
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
copier: 9.5.0 → 9.15.2
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
lightning: before 1.6.0
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2: before 2.12.0
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework: before 3.17.2
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
praisonai: before 4.6.58
Snowflake Connector for Python improperly verifies TLS hostnames
Snowflake Connector for Python improperly verifies TLS hostnames
snowflake-connector-python: before 3.18.1
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
chromadb: ≥ 0.5.0
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm: 0.21.0 → 0.26.0
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
praisonai: before 4.6.58
PyOD persistence.load deserializes untrusted artifacts before validation
PyOD persistence.load deserializes untrusted artifacts before validation
pyod: 3.5.0 → 3.6.2
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql: before 1.1.1
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
githacker: before 1.1.8
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui: 0.9.5 → 0.11.1
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
praisonai: before 4.6.58
MLflow AI Gateway permits SSRF through an unvalidated api_base
MLflow AI Gateway permits SSRF through an unvalidated api_base
mlflow: ≥ 3.13.0
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
keras: before 3.15.0
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler-cloud: before 5.37.0
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-websocket: before 1.1.1
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp: before 0.2.1
Malicious code in lucy-python-script-2030 (PyPI)
Malicious code in lucy-python-script-2030 (PyPI)
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: before 6.16.1
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
justhtml: before 1.10.0
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning: before 2.3.3
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
praisonai: before 4.6.58
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
nltk: before 3.10.1
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy-mini: before 1.8.2
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
praisonai: before 4.6.58
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: before 6.16.1
Windows ML CLI: CORS misconfig enables localhost RCE
Windows ML CLI: CORS misconfig enables localhost RCE
winml-cli: before 0.4.0
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
open-webui: 0.8.0 → 0.9.0
Cognee allows non-superusers to overwrite global LLM configuration
Cognee allows non-superusers to overwrite global LLM configuration
cognee: before 1.5.0
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui: 0.7.0 → 0.11.1
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
xinference: before 2.7.0
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
thrift: before 0.24.0
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: before 0.117.2
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui: 0.8.11 → 0.11.1
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
praisonai: 4.6.34 → 4.6.58
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonai: 3.9.26 → 4.6.58
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
praisonai: before 4.6.58
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
weblate: before 2026.7
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite-core: ≥ 2.0.0
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
praisonai: before 4.6.58
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit: 2.4.0rc0 → 2.12.0
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
open-webui: 0.5.0 → 0.11.1
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents: before 1.6.58
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
open-webui: 0.6.41 → 0.11.1
Malicious code in pylever (PyPI)
Malicious code in pylever (PyPI)
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
gitpython: before 3.1.58
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
transformers: before 5.10.0
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust: before 1.0.4
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
gitpython: before 3.1.58
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents: before 1.6.58
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk: before 3.10.3
kas Persistently Disables SSH Host Key Checking
kas Persistently Disables SSH Host Key Checking
kas: before 5.4
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2: before 2.10.0
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents: before 1.6.58
Material for MkDocs: DOM XSS in search suggestions via query parameter
Material for MkDocs: DOM XSS in search suggestions via query parameter
mkdocs-material: 7.2.0 → 9.7.7
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpx2: 2.6.0 → 2.10.0
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
esphome-device-builder: before 1.0.10
WsgiDAV MySQL provider has a blind SQL injection
WsgiDAV MySQL provider has a blind SQL injection
wsgidav: before 4.3.5
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2: 2.5.0 → 2.10.0
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm: before 0.26.0
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui: before 0.11.1
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
sqladmin: before 0.27.1
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2: before 2.11.0
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
nltk: before 3.10.3
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
thrift: before 0.24.0
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: before 6.16.0
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway: before 1.0.2
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
open-webui: 0.10.0 → 0.11.1
RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
restrictedpython: before 8.3
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython: before 3.1.51
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
gitpython: before 3.1.51
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui: 0.9.6 → 0.11.1
asteval has a Sandbox Escape via BaseException Subclasses
asteval has a Sandbox Escape via BaseException Subclasses
asteval: before 1.0.9
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone-app-portlets: before 5.0.8
icalendar has Algorithmic Complexity in Equality
icalendar has Algorithmic Complexity in Equality
icalendar: 7.1.0 → 7.1.3
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
open-webui: 0.8.0 → 0.11.1
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools: before 1.15.1
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
nltk: before 3.10.3
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
open-webui: 0.9.0 → 0.11.1
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb: before 0.3.0
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
litellm: before 1.83.7
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: before 0.10.0
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
document-merge-service: before 9.1.0
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
mistune: 3.3.0 → 3.3.3
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
apache-airflow: before 3.3.0
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
open-webui: 0.9.0 → 0.11.1
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
praisonai: before 4.6.58
plone.app.event vulnerable to denial of service via iCalendar import
plone.app.event vulnerable to denial of service via iCalendar import
plone-app-event: before 5.2.4
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
lightning: all versions
PyTorch Lightning denial of service vulnerability
PyTorch Lightning denial of service vulnerability
lightning: all versions
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
snowflake-sqlalchemy: 1.1.6 → 1.11.0
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: before 6.15.0
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
scrapy: before 2.17.0
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed: before 5.1.2
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui: 0.10.0 → 0.11.1
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
gitpython: before 3.1.58
aiosmtplib: STARTTLS response injection
aiosmtplib: STARTTLS response injection
aiosmtplib: before 5.1.2
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh: before 2.23.1
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml-parser: before 3.0.2
PyTorch Lightning path traversal vulnerability
PyTorch Lightning path traversal vulnerability
lightning: before 2.4.0
OpenHarness remote project-context commands allow persistent prompt poisoning
OpenHarness remote project-context commands allow persistent prompt poisoning
openharness-ai: all versions
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm: before 0.26.0
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-store-mongodb: before 0.4.0
eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
eml-parser: before 3.0.2
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework: before 3.17.2
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
jupyterhub: before 5.5.0
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
chromadb: ≥ 0.4.17
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
open-webui: 0.10.0 → 0.11.1
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent: before 0.3.0
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent: before 0.3.0
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
open-webui: 0.9.0 → 0.11.1
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
tornado: before 6.5.8
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: before 1.6.58
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
nltk: 3.10.0 → 3.10.3
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
praisonai: before 4.6.58
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
protego: before 0.6.2
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
chainlit: 2.4.0rc0 → 2.12.0
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: 0.4.7 → 0.24.0
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
banks: before 2.4.5
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
hydra-core: before 1.3.4
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate: before 2026.7
Compromise of PyTorch Lightning PyPi Package Versions
Compromise of PyTorch Lightning PyPi Package Versions
lightning: 2.6.2 → 2.6.4
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: before 0.10.0
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml-parser: before 3.0.2
Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API
wagtail: before 7.0.9
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2: before 2.11.0
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler: before 5.37.0
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
omnigent: before 0.3.0
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
webob: before 1.8.11
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin: before 1.14.0
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
starlette-admin: before 0.16.1
Remote code execution in pytorch lightning
Remote code execution in pytorch lightning
pytorch-lightning: before 2.3.3
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
gitpython: before 3.1.58
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm: before 0.26.0
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent: before 0.3.0
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython: before 3.1.52
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents: 0.12.12 → 1.6.58
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
praisonai: before 4.6.58
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
accelerate: all versions
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
open-webui: 0.6.27 → 0.11.1
vLLM: Cross-User Data Leak Vulnerability
vLLM: Cross-User Data Leak Vulnerability
vllm: before 0.27.0
OpenHarness remote resume commands expose other users' saved session snapshots
OpenHarness remote resume commands expose other users' saved session snapshots
openharness-ai: all versions
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: before 1.6.58
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint: before 70.0
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
esphome-device-builder: before 1.0.10
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
sqladmin: before 0.27.1
Malicious code in websetup (PyPI)
Malicious code in websetup (PyPI)
Malicious code in bq-build-probe-vrp-2026 (PyPI)
Malicious code in bq-build-probe-vrp-2026 (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint: before 70.0
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
open-webui: 0.5.0 → 0.11.1
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
open-webui: 0.9.5 → 0.11.1
Malicious code in bq-sdist-probe-vrp (PyPI)
Malicious code in bq-sdist-probe-vrp (PyPI)
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
open-webui: 0.10.0 → 0.11.1
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
githacker: before 1.1.8
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
nltk: before 3.10.0
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
nltk: before 3.10.0
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
nltk: before 3.9.3
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2: before 2.11.0
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
nltk: before 3.9.4
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
gitpython: before 3.1.59
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
nltk: before 3.10.0
NLTK: Allowlisted pickle loaders still permit code execution in current source
NLTK: Allowlisted pickle loaders still permit code execution in current source
nltk: before 3.10.3
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
gitpython: before 3.1.59
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2: 2.5.0 → 2.10.0
NLTK: Corpus Reader Sandbox Bypass
NLTK: Corpus Reader Sandbox Bypass
nltk: before 3.10.3
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
gitpython: before 3.1.59
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
nltk: before 3.10.3
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
nltk: 3.10.0 → 3.10.2
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
nltk: before 3.10.0
NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
nltk: before 3.10.0
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
nltk: before 3.10.3
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
nltk: before 3.10.3
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython: before 3.1.59
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
nltk: before 3.10.3
vLLM: Cross-User Data Leak Vulnerability
vLLM: Cross-User Data Leak Vulnerability
vllm: before 0.27.0
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
gitpython: before 3.1.59
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm: before 0.26.0
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2: before 2.12.0
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
nltk: 3.10.0 → 3.10.2
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
nltk: before 3.10.3
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2: before 2.10.0
Windows ML CLI: CORS misconfig enables localhost RCE
Windows ML CLI: CORS misconfig enables localhost RCE
winml-cli: before 0.4.0
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler: before 5.37.0
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2: before 2.11.0
Malicious code in cv-train (PyPI)
Malicious code in cv-train (PyPI)
Malicious code in telegram-helper (PyPI)
Malicious code in telegram-helper (PyPI)
Malicious code in dac-tools (PyPI)
Malicious code in dac-tools (PyPI)
Malicious code in minecraftmodes (PyPI)
Malicious code in minecraftmodes (PyPI)
Malicious code in dbt-sa-cli (PyPI)
Malicious code in dbt-sa-cli (PyPI)
Malicious code in proxycer (PyPI)
Malicious code in proxycer (PyPI)
Malicious code in trongridew (PyPI)
Malicious code in trongridew (PyPI)
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm: before 0.26.0
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm: before 0.26.0
Malicious code in astlsi (PyPI)
Malicious code in astlsi (PyPI)
Malicious code in houdus (PyPI)
Malicious code in houdus (PyPI)
Malicious code in tsshare (PyPI)
Malicious code in tsshare (PyPI)
tsshare: all versions
Malicious code in tpu-raiden-jax (PyPI)
Malicious code in tpu-raiden-jax (PyPI)
Malicious code in pymaas (PyPI)
Malicious code in pymaas (PyPI)
Malicious code in metricboxlite (PyPI)
Malicious code in metricboxlite (PyPI)
Malicious code in chartkit-core (PyPI)
Malicious code in chartkit-core (PyPI)
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm: 0.21.0 → 0.26.0
Malicious code in timeweave (PyPI)
Malicious code in timeweave (PyPI)
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm: before 0.26.0
Malicious code in olympuslib (PyPI)
Malicious code in olympuslib (PyPI)
Malicious code in qoeoe (PyPI)
Malicious code in qoeoe (PyPI)
Malicious code in 0requests (PyPI)
Malicious code in 0requests (PyPI)
Malicious code in py-1requests (PyPI)
Malicious code in py-1requests (PyPI)
Material for MkDocs: DOM XSS in search suggestions via query parameter
Material for MkDocs: DOM XSS in search suggestions via query parameter
mkdocs-material: 7.2.0 → 9.7.7
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: 0.4.7 → 0.24.0
Malicious code in company-sdk (PyPI)
Malicious code in company-sdk (PyPI)
Malicious code in py-0requests (PyPI)
Malicious code in py-0requests (PyPI)
Malicious code in uvhttp-custom (PyPI)
Malicious code in uvhttp-custom (PyPI)
Malicious code in asti (PyPI)
Malicious code in asti (PyPI)
Malicious code in env-validator-tool (PyPI)
Malicious code in env-validator-tool (PyPI)
Malicious code in telemetry-helper (PyPI)
Malicious code in telemetry-helper (PyPI)
Malicious code in py-2equests (PyPI)
Malicious code in py-2equests (PyPI)
Malicious code in trongridi (PyPI)
Malicious code in trongridi (PyPI)
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
nltk: before 3.10.3
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
mistune: 3.3.0 → 3.3.3
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent: before 0.3.0
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
nltk: all versions
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
nltk: before 3.10.3
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent: before 0.3.0
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk: before 3.10.3
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: before 6.15.0
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
nltk: before 3.10.3
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent: before 0.3.0
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
tornado: before 6.5.8
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
scrapy: before 2.17
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
nltk: before 3.10.0
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
nltk: before 3.10.0
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
omnigent: before 0.3.0
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
nltk: before 3.10.3
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generat
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web
pyspark: 3.0.0 → 3.5.8
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
banks: before 2.4.5
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: before 6.16.0
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
nltk: before 3.10.3
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
mlflow: 2.1.0 → 3.15.0
Malicious code in gcphelpit (PyPI)
Malicious code in gcphelpit (PyPI)
Malicious code in syswatch (PyPI)
Malicious code in syswatch (PyPI)
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
tornado: 6.5.5 → 6.5.8
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
nltk: before 3.10.3
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework: before 3.17.2
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: before 6.16.1
Malicious code in tallyboxlite (PyPI)
Malicious code in tallyboxlite (PyPI)
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
tornado: before 6.5.8
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: before 0.6.0
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: before 6.16.1
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework: before 3.17.2
Malicious code in pyservercheck (PyPI)
Malicious code in pyservercheck (PyPI)
Malicious code in trongridor (PyPI)
Malicious code in trongridor (PyPI)
Malicious code in tronlinker (PyPI)
Malicious code in tronlinker (PyPI)
Malicious code in auth-app-streamlit (PyPI)
Malicious code in auth-app-streamlit (PyPI)
Malicious code in flask-header-guard (PyPI)
Malicious code in flask-header-guard (PyPI)
RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
restrictedpython: before 8.3
Malicious code in yaml-report-formatter (PyPI)
Malicious code in yaml-report-formatter (PyPI)
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
compliance-trestle: before 3.12.4
plone.app.event vulnerable to denial of service via iCalendar import
plone.app.event vulnerable to denial of service via iCalendar import
plone-app-event: before 5.2.4
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
protego: before 0.6.2
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin: before 1.14.0
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate: before 2026.7
Malicious code in calcboxlite (PyPI)
Malicious code in calcboxlite (PyPI)
AIIR verification and policy gates could report success without enforcing the control (fail-open)
AIIR verification and policy gates could report success without enforcing the control (fail-open)
aiir: before 1.7.0
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
weblate: before 2026.7
WsgiDAV MySQL provider has a blind SQL injection
WsgiDAV MySQL provider has a blind SQL injection
wsgidav: before 4.3.5
Malicious code in yamlformatter-utils (PyPI)
Malicious code in yamlformatter-utils (PyPI)
Malicious code in yamlformat-tools (PyPI)
Malicious code in yamlformat-tools (PyPI)
Malicious code in pygame-renderkit (PyPI)
Malicious code in pygame-renderkit (PyPI)
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone-app-portlets: 7.0.0 → 7.0.2
Malicious code in mathkitlite (PyPI)
Malicious code in mathkitlite (PyPI)
Malicious code in flyteplugins-echo (PyPI)
Malicious code in flyteplugins-echo (PyPI)
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.
openssl-encrypt: before 1.4.9
Malicious code in flyteplugins-agento11y (PyPI)
Malicious code in flyteplugins-agento11y (PyPI)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names, --option=value forms, and tokens starting with -p, so these spellings bypass the redaction chokepoint and the cleartext password is written to stderr. Anyone with access to that output (terminal scrollback, merged 2>&1 output,
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
openssl-encrypt: before 1.4.9
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.
openssl-encrypt: before 1.4.9
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host process.
openssl-encrypt: before 1.4.9
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
netron: before 9.1.3
Malicious code in ekx-report-utils (PyPI)
Malicious code in ekx-report-utils (PyPI)
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.
openssl-encrypt: before 1.4.9
aiosmtplib: STARTTLS response injection
aiosmtplib: STARTTLS response injection
aiosmtplib: before 5.1.2
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offline password guessing at hardware speed to recover user passwords.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.
openssl-encrypt: before 1.4.9
Malicious code in flyteplugins-nsight (PyPI)
Malicious code in flyteplugins-nsight (PyPI)
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.
openssl-encrypt: before 1.4.9
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4.9 by routing drive-derived names through sanitize_for_display().
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.
openssl-encrypt: before 1.4.9
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main password. Any local user can read the steganography password from /proc/<pid>/cmdline for the lifetime of the subprocess. Fixed in 1.4.9.
openssl-encrypt: before 1.4.9
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
nltk: before 3.10.3
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
litellm: before 1.83.7
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification.
openssl-encrypt: before 1.4.9
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize it. As a result the token is printed in cleartext to stderr under --debug (even without --unsafe-show-secrets), persisting the credential in logs and terminal history. Fixed in 1.4.9.
openssl-encrypt: before 1.4.9
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.
nltk: before 3.10.3
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.
nltk: before 3.10.3
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causin
nltk: before 3.10.3
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.
openssl-encrypt: before 1.4.9
Malicious code in sap-quarterly-report (PyPI)
Malicious code in sap-quarterly-report (PyPI)
Malicious code in flyteplugins-redis (PyPI)
Malicious code in flyteplugins-redis (PyPI)
Malicious code in decoris (PyPI)
Malicious code in decoris (PyPI)
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
nltk: before 3.10.3
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
webob: before 1.8.11
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.
nltk: before 3.10.0
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
starlette-admin: before 0.16.1
Malicious code in pybitjs (PyPI)
Malicious code in pybitjs (PyPI)
Malicious code in trongridet (PyPI)
Malicious code in trongridet (PyPI)
Malicious code in syntaxerror-package-12345 (PyPI)
Malicious code in syntaxerror-package-12345 (PyPI)
Malicious code in 0xfighter3 (PyPI)
Malicious code in 0xfighter3 (PyPI)
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing i
nltk: before 3.10.3
kas Persistently Disables SSH Host Key Checking
kas Persistently Disables SSH Host Key Checking
kas: before 5.4
Malicious code in bigquery-agent-analytics-tracing (PyPI)
Malicious code in bigquery-agent-analytics-tracing (PyPI)
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
pantheon-agents: 0.6.1 → 0.6.4
Malicious code in rce-test (PyPI)
Malicious code in rce-test (PyPI)
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
openwisp-ipam: before 1.2.1
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh: before 2.23.1
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite-core: ≥ 2.0.0
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh: before 2.23.1
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy-mini: before 1.8.2
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents: before 1.6.58
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql: before 1.1.1
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.
nltk: before 3.10.3
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
praisonai: before 4.6.58
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
praisonai: before 4.6.58
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http: before 1.1.4
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp: before 0.2.1
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.
nltk: before 3.10.3
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http: before 1.1.4
Malicious code in minecraft-ytreceiver (PyPI)
Malicious code in minecraft-ytreceiver (PyPI)
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
praisonai: 4.6.34 → 4.6.58
Malicious code in python-walletlibr-v (PyPI)
Malicious code in python-walletlibr-v (PyPI)
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway: before 1.0.0
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attack
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.
nltk: before 3.10.3
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
praisonai: before 4.6.58
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().
nltk: before 3.10.3
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: before 1.6.58
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml-parser: before 3.0.2
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
uff: all versions
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit: 2.4.0rc0 → 2.12.0
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
praisonai: before 4.6.58
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
chainlit: 2.4.0rc0 → 2.12.0
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents: before 1.6.58
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
praisonai: before 4.6.58
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents: before 1.6.58
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.
nltk: before 3.10.3
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents: 1.5.128 → 1.6.58
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: before 1.6.58
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
praisonai: before 4.6.58
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed: before 5.1.2
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents: before 1.6.58
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
praisonai: before 4.6.58
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
praisonai: before 4.6.58
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml-parser: before 3.0.2
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
praisonai: before 4.6.58
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
praisonai: before 4.6.58
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust: before 1.0.4
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents: 0.12.12 → 1.6.58
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code wit
nltk: before 3.10.0
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
jupyterhub: before 5.5.0
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an
nltk: before 3.10.3
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
praisonai: before 4.6.58
eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
eml-parser: before 3.0.2
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: before 0.117.2
icalendar has Algorithmic Complexity in Equality
icalendar has Algorithmic Complexity in Equality
icalendar: 7.1.0 → 7.1.3
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway: before 1.0.2
Malicious code in multyproccess (PyPI)
Malicious code in multyproccess (PyPI)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
Malicious code in msrcpoc (PyPI)
Malicious code in msrcpoc (PyPI)
Malicious code in py-devoli-common (PyPI)
Malicious code in py-devoli-common (PyPI)
Malicious code in envprovision (PyPI)
Malicious code in envprovision (PyPI)
Malicious code in cryptgraphy (PyPI)
Malicious code in cryptgraphy (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.
nltk: before 3.9.4
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.
nltk: before 3.10.0
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
nltk: before 3.9.3
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary.
nltk: before 3.9.4
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.
nltk: before 3.10.0
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
nltk: 3.10.0 → 3.10.2
NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c
NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who contro
nltk: 3.9.4 → 3.10.3
Malicious code in scrambleeeer (PyPI)
Malicious code in scrambleeeer (PyPI)
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
nltk: 3.9.4 → 3.10.3
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
nltk: 3.10.0 → 3.10.3
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
nltk: before 3.10.0
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebin
nltk: before 3.10.0
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.
nltk: before 3.10.0
Malicious code in scrambleeer (PyPI)
Malicious code in scrambleeer (PyPI)
Malicious code in requests-crypt (PyPI)
Malicious code in requests-crypt (PyPI)
Malicious code in boto4 (PyPI)
Malicious code in boto4 (PyPI)
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
xinference: before 2.7.0
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
nltk: before 3.10.1
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
hydra-core: before 1.3.4
Malicious code in reqcrypts (PyPI)
Malicious code in reqcrypts (PyPI)
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API
wagtail: before 7.0.9
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval: before 1.0.9
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node: before 0.9.0a11
Wagtail: Improper permission handling in image preview
Wagtail: Improper permission handling in image preview
wagtail: before 7.0.8
Wagtail: Reflected XSS in dynamic image URL generator view
Wagtail: Reflected XSS in dynamic image URL generator view
wagtail: 7.3 → 7.3.3
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
zoo-kcl: before 0.3.153
Wagtail: Improper restriction handling on Page translation API endpoint
Wagtail: Improper restriction handling on Page translation API endpoint
wagtail: before 7.0.9
Wagtail: Denial of service via unbounded filter specs in the image preview
Wagtail: Denial of service via unbounded filter specs in the image preview
wagtail: before 7.0.8
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
zoo-kcl: before 0.3.129
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
wagtail: before 7.0.8
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
wagtail: before 7.0.9
Wagtail: Improper permission handling when copying snippets
Wagtail: Improper permission handling when copying snippets
wagtail: before 7.0.9
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
Wagtail: Identification of documents by SHA1 hash
Wagtail: Identification of documents by SHA1 hash
wagtail: before 7.0.9
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb: before 0.3.0
asteval has a Sandbox Escape via BaseException Subclasses
asteval has a Sandbox Escape via BaseException Subclasses
asteval: before 1.0.9
Wagtail: Pages translations can be created without page permissions when using simple_translation
Wagtail: Pages translations can be created without page permissions when using simple_translation
wagtail: before 7.0.8
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
geolens-cli: before 1.2.3
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: before 0.10.0
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: before 0.10.0
devpi-server may leak database contents
devpi-server may leak database contents
devpi-server: before 6.20.2
Malicious code in reqcrypt-dev (PyPI)
Malicious code in reqcrypt-dev (PyPI)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow: before 3.15.0
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
lemur: before 1.9.3
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
ansible-jailexec: before 2.0.0
surfio has an out-of-bounds read
surfio has an out-of-bounds read
surfio: before 0.0.19
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
stata-mcp: before 1.19.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle: before 4.1.0
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
homeassistant: before 2026.6.0
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata: before 6.2.9
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes: before 3.9.0
Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion
copyparty: before 1.20.17
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
lemur: before 1.9.3
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
lemur: 0.5.0 → 1.9.3
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: before 0.6.0
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: all versions
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
lemur: before 1.9.3
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: before 0.6.0
SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
sglang: all versions
vLLM: Completion prompt lists fan out into unbounded engine requests
vLLM: Completion prompt lists fan out into unbounded engine requests
vllm: 0.19.0 → 0.26.0
libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
libp2p: all versions
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
lemur: before 1.9.3
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: before 0.6.0
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
lemur: before 1.9.3
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: before 0.22.0
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: before 0.6.0
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
lemur: before 1.9.3
MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check
mobsf: before 4.5.1
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
mcp-contextforge-gateway: before 1.0.3
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
mobsf: before 4.5.1
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
glances: before 4.5.6
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
jupyterlab: 3.3.0 → 4.5.10
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
lemur: before 1.9.3
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
mobsf: before 4.5.1
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
jupyterlab: before 4.5.10
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
geolens: before 1.2.3
MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
mlflow: 2.14.0rc0 → 3.13.0rc0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai-slim: 1.65.0 → 1.106.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai: 1.65.0 → 1.106.0
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
glances: before 4.5.6
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: before 6.1.0
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
jupyterlab: 4.5.0 → 4.5.10
Malicious code in rc4-secure (PyPI)
Malicious code in rc4-secure (PyPI)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
document-merge-service: before 9.1.0
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: before 3.10.0
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
geolens: before 1.2.4
Malicious code in libasync (PyPI)
Malicious code in libasync (PyPI)
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
glances: 4.5.2 → 4.5.6
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
glances: before 4.5.6
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
copier: 9.5.0 → 9.15.2
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
glances: before 4.5.6
MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check
mobsf: before 4.5.1
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata: before 6.2.9
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
lemur: before 1.9.3
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
surfio has an out-of-bounds read
surfio has an out-of-bounds read
surfio: before 0.0.19
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
mobsf: before 4.5.1
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
lemur: before 1.9.3
devpi-server may leak database contents
devpi-server may leak database contents
devpi-server: before 6.20.2
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
lemur: before 1.9.3
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
lemur: 0.5.0 → 1.9.3
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
lemur: before 1.9.3
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
lemur: before 1.9.3
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: before 6.1.0
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
lemur: before 1.9.3
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
mobsf: before 4.5.1
Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion
copyparty: before 1.20.17
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
lemur: before 1.9.3
MONAI vulnerable to OS command injection
MONAI vulnerable to OS command injection
monai: before 1.6.0
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
monai: before 1.6.0
Malicious code in deepface-weight (PyPI)
Malicious code in deepface-weight (PyPI)
Malicious code in reqcrypt (PyPI)
Malicious code in reqcrypt (PyPI)
Malicious code in deepface-weights (PyPI)
Malicious code in deepface-weights (PyPI)
Malicious code in httpz-requests (PyPI)
Malicious code in httpz-requests (PyPI)
Malicious code in infogram-bot (PyPI)
Malicious code in infogram-bot (PyPI)
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
monai: before 1.6.0
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings access
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMA
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call i
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles fr
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugi
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256 speed instead of the configured KDF cost.
openssl-encrypt: before 1.4.6
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: before 0.6.0
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation ch
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.
openssl-encrypt: before 1.4.0
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: before 0.6.0
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
openssl-encrypt: before 1.4.0
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hs
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal scrollback, session recordings, or CI logs. Impact is limited because the pepper is derived from a random per-invocation test salt and is salt-bound, so the leaked value cannot be used to
openssl-encrypt: before 1.4.7
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
openssl-encrypt: before 1.4.0
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: before 0.6.0
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recover
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
openssl-encrypt: before 1.4.0
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow: before 3.15.0
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method th
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
openssl-encrypt: before 1.4.0
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
glances: before 4.5.6
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
glances: before 4.5.6
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
glances: before 4.5.6
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
glances: 4.5.2 → 4.5.6
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
glances: before 4.5.6
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.
openssl-encrypt: before 1.4.0
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: before 0.6.0
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silent
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.
openssl-encrypt: before 1.4.0
Malicious code in kb-ai (PyPI)
Malicious code in kb-ai (PyPI)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
mcp-contextforge-gateway: before 1.0.3
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.
gitpython: before 3.1.55
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing 'git rev-list --output=<path>' to open and truncate the target file to zero bytes before revision parsing.
gitpython: before 3.1.56
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.
gitpython: before 3.1.57
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.
gitpython: before 3.1.54
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
gitpython: before 3.1.57
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.
gitpython: before 3.1.54
vLLM: Completion prompt lists fan out into unbounded engine requests
vLLM: Completion prompt lists fan out into unbounded engine requests
vllm: 0.19.0 → 0.26.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai-slim: 1.65.0 → 1.106.0
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: before 1.1.0
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
nltk: before 3.10.0
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: before 3.10.0
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
stata-mcp: before 1.19.0
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configurat
apache-airflow: before 3.3.1
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m
apache-airflow: before 3.3.1
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
ansible-jailexec: before 2.0.0
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unus
apache-airflow-providers-google: before 22.3.0
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore
apache-airflow: before 3.3.1
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler proce
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
apache-airflow: before 3.3.1
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does n
apache-airflow: before 3.3.1
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those se
apache-airflow: before 3.3.1
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle: before 4.1.0
Malicious code in dlmm (PyPI)
Malicious code in dlmm (PyPI)
Malicious code in telebot-pro (PyPI)
Malicious code in telebot-pro (PyPI)
Malicious code in morpho-sdk (PyPI)
Malicious code in morpho-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
Malicious code in joule-btp-extension (PyPI)
Malicious code in joule-btp-extension (PyPI)
Malicious code in joule-sbx-poc (PyPI)
Malicious code in joule-sbx-poc (PyPI)
Malicious code in dlmm-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI)
Malicious code in kotoraka (PyPI)
Malicious code in kotoraka (PyPI)
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
keras: before 3.15.0
Malicious code in neutrl-core (PyPI)
Malicious code in neutrl-core (PyPI)
Malicious code in btcflx (PyPI)
Malicious code in btcflx (PyPI)
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
accelerate: all versions
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backe
apache-airflow-providers-yandex: before 4.5.1
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling
apache-airflow-providers-amazon: before 9.34.0
Malicious code in neutrl-contracts (PyPI)
Malicious code in neutrl-contracts (PyPI)
Malicious code in bigtime (PyPI)
Malicious code in bigtime (PyPI)
Malicious code in chaintest (PyPI)
Malicious code in chaintest (PyPI)
Malicious code in pytablute (PyPI)
Malicious code in pytablute (PyPI)
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
aiosend: before 3.0.7
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
open-webui: 0.7.0 → 0.11.0
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
open-webui: 0.9.0 → 0.11.0
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
open-webui: 0.8.8 → 0.11.0
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
open-webui: 0.9.0 → 0.11.0
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
open-webui: 0.10.0 → 0.11.0
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
open-webui: 0.5.0 → 0.11.0
Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
keras: before 3.12.3
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
open-webui: 0.9.6 → 0.11.0
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
open-webui: 0.6.34 → 0.11.0
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
open-webui: 0.8.8 → 0.11.0
Open WebUI: DNS Rebinding SSRF Bypass
Open WebUI: DNS Rebinding SSRF Bypass
open-webui: before 0.11.0
Keras: HDF5 links can disclose local file contents
Keras: HDF5 links can disclose local file contents
keras: before 3.12.3
Keras: DiskIOStore permits path traversal through crafted layer names
Keras: DiskIOStore permits path traversal through crafted layer names
keras: before 3.12.3
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
open-webui: 0.8.0 → 0.11.0
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: before 6.15.0
Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
keras: before 3.12.3
h2: Duplicate Host header could facilitate request smuggling
h2: Duplicate Host header could facilitate request smuggling
h2: before 4.4.1
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
open-webui: 0.9.6 → 0.11.0
Keras: Lambda deserialization can bypass safe mode and execute code
Keras: Lambda deserialization can bypass safe mode and execute code
keras: before 3.12.3
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
open-webui: 0.10.0 → 0.11.0
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: before 6.15.0
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
open-webui: 0.9.6 → 0.11.0
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
open-webui: 0.9.6 → 0.11.0
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
open-webui: before 0.11.0
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: before 11.0.1
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
awscli: before 1.45.28
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
keras: before 3.12.3
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
open-webui: 0.9.0 → 0.11.0
Malicious code in btcflip (PyPI)
Malicious code in btcflip (PyPI)
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-sqlite: before 3.1.1
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-postgres: before 3.1.1
Malicious code in plp-contract (PyPI)
Malicious code in plp-contract (PyPI)
Malicious code in kotanku (PyPI)
Malicious code in kotanku (PyPI)
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Python's `ipaddress` module does not classify such addresses as `is_private` or `is_global`, and the current guard only checks `is_private` and a few explicit categorie
nltk: all versions
Malicious code in cubesat-upstream-driver (PyPI)
Malicious code in cubesat-upstream-driver (PyPI)
Malicious code in riakcs (PyPI)
Malicious code in riakcs (PyPI)
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: before 6.15.0
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active throug
nltk: before 3.10.0
Malicious code in fastapii (PyPI)
Malicious code in fastapii (PyPI)
Malicious code in pydanticc (PyPI)
Malicious code in pydanticc (PyPI)
Malicious code in flasq (PyPI)
Malicious code in flasq (PyPI)
Malicious code in speed-hashes (PyPI)
Malicious code in speed-hashes (PyPI)
Malicious code in cdktn-provider-azurerm (PyPI)
Malicious code in cdktn-provider-azurerm (PyPI)
Malicious code in atlas-internal (PyPI)
Malicious code in atlas-internal (PyPI)
Malicious code in fast-hashes (PyPI)
Malicious code in fast-hashes (PyPI)
Malicious code in idnna (PyPI)
Malicious code in idnna (PyPI)
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
gitpython: before 3.1.58
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
gitpython: before 3.1.58
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: before 11.0.1
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
gitpython: before 3.1.58
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: before 6.15.0
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
gitpython: before 3.1.58
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
gitpython: before 3.1.58
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
gitpython: before 3.1.58
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside
apache-polaris: before 1.7.0
Malicious code in xayoub-xctxteam (PyPI)
Malicious code in xayoub-xctxteam (PyPI)
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
awscli: before 1.45.28
Malicious code in decapod-common (PyPI)
Malicious code in decapod-common (PyPI)
Malicious code in alphalend-layouts (PyPI)
Malicious code in alphalend-layouts (PyPI)
Malicious code in alphalend-abi (PyPI)
Malicious code in alphalend-abi (PyPI)
h2: Duplicate Host header could facilitate request smuggling
h2: Duplicate Host header could facilitate request smuggling
h2: before 4.4.1
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-postgres: before 3.1.1
MLflow AI Gateway permits SSRF through an unvalidated api_base
MLflow AI Gateway permits SSRF through an unvalidated api_base
mlflow: ≥ 3.13.0
Malicious code in uncrypt (PyPI)
Malicious code in uncrypt (PyPI)
Malicious code in eth-account-wallet (PyPI)
Malicious code in eth-account-wallet (PyPI)
Malicious code in mnemonic-py (PyPI)
Malicious code in mnemonic-py (PyPI)
Malicious code in numpyp (PyPI)
Malicious code in numpyp (PyPI)
Malicious code in gcli-control (PyPI)
Malicious code in gcli-control (PyPI)
Malicious code in solana-sniper-bot (PyPI)
Malicious code in solana-sniper-bot (PyPI)
Malicious code in defi-sdk-py (PyPI)
Malicious code in defi-sdk-py (PyPI)
Malicious code in bitcoinlib-py (PyPI)
Malicious code in bitcoinlib-py (PyPI)
Malicious code in crypto-trading-toolkit (PyPI)
Malicious code in crypto-trading-toolkit (PyPI)
Malicious code in bip39-py (PyPI)
Malicious code in bip39-py (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
flyto-core: before 2.26.7
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator: 0.59.0 → 0.62.0
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: before 6.14.0
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
datamodel-code-generator: 0.17.0 → 0.60.2
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
open-webui: before 0.10.0
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
flyto-core: before 2.26.7
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge: 1.0.0 → 1.3.1
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
proot-distro: before 5.1.5
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: before 6.0.0
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
deepsearcher: all versions
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: all versions
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
thumbor: before 7.8.0
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
thumbor: before 7.8.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: before 6.14.2
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
pymdown-extensions: before 11.0.0
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi: 2.0.0 → 2.2.1
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
open-webui: 0.9.6 → 0.10.0
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
open-webui: 0.9.0 → 0.10.0
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
open-webui: 0.7.0 → 0.10.0
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: before 0.15.0
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: before 49.0.0
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
thumbor: before 7.8.0
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
mysql-mcp-server: before 0.3.0
AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
awscli: before 1.44.78
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
flyto-core: before 2.26.7
Malicious code in psbt-utils (PyPI)
Malicious code in psbt-utils (PyPI)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator: 0.14.1 → 0.60.2
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
cryptography: before 49.0.0
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: before 0.63.0
Malicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code in launchdarkly-ai-server-sdk (PyPI)
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
nanobot-ai: before 0.2.1
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator: 0.11.6 → 0.64.0
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
nltk: before 3.10.0
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
nltk: before 3.10.0
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
onnx: 1.3.0 → 1.22.0
Malicious code in coldcard-helpers (PyPI)
Malicious code in coldcard-helpers (PyPI)
OnionShare Receive mode writes uploaded files even when file uploads are disabled
OnionShare Receive mode writes uploaded files even when file uploads are disabled
onionshare-cli: before 2.6.4
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro: before 5.1.6
Malicious code in psbt-helpers (PyPI)
Malicious code in psbt-helpers (PyPI)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
flyto-core: before 2.26.7
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Ea
django: before 5.2.17
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
open-webui: 0.6.27 → 0.10.0
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
open-webui: 0.6.16 → 0.10.0
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
open-webui: before 0.10.0
Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
open-webui: 0.8.12 → 0.10.0
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
open-webui: 0.9.2 → 0.10.0
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
open-webui: before 0.10.0
Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
open-webui: before 0.10.0
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator: 0.9.1 → 0.61.0
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
thumbor: before 7.8.0
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
open-webui: 0.9.0 → 0.11.0
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
open-webui: 0.9.5 → 0.10.0
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
open-webui: 0.9.0 → 0.11.0
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
open-webui: before 0.10.0
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
open-webui: 0.8.11 → 0.10.0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: before 2026.7.4
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
open-webui: before 0.11.0
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: HTTP request smuggling via WebSocket upgrade
aiohttp: before 3.14.2
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
open-webui: before 0.10.0
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
flyto-core: before 2.26.7
Open WebUI: DNS Rebinding SSRF Bypass
Open WebUI: DNS Rebinding SSRF Bypass
open-webui: before 0.11.0
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
thumbor: before 7.8.0
pypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
pypdf: before 6.14.0
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui: 0.9.6 → 0.10.0
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
open-webui: 0.6.34 → 0.11.0
pypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
pypdf: before 6.14.1
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
open-webui: before 0.10.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
datamodel-code-generator: 0.25.0 → 0.60.1
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent: all versions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
open-webui: 0.7.0 → 0.11.0
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
datamodel-code-generator: 0.52.1 → 0.60.2
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
open-webui: 0.9.0 → 0.10.0
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
datamodel-code-generator: 0.51.0 → 0.60.2
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
open-webui: 0.9.6 → 0.11.0
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
open-webui: 0.9.6 → 0.11.0
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
aiohttp: before 3.14.3
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
penelope-shell-handler: before 0.20.0
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
open-webui: 0.10.0 → 0.11.0
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
open-webui: 0.10.0 → 0.11.0
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
aiohttp: before 3.14.2
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
open-webui: 0.8.0 → 0.11.0
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
thumbor: before 7.8.0
awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
awxkit: all versions
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
open-webui: 0.8.8 → 0.11.0
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
open-webui: 0.5.0 → 0.11.0
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
open-webui: 0.9.6 → 0.11.0
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: 44.0.0 → 50.0.0
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
open-webui: 0.8.8 → 0.11.0
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator: before 0.62.0
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
open-webui: 0.9.0 → 0.11.0
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
open-webui: 0.9.6 → 0.11.0
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
bedrock-agentcore: before 1.18.1
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator: 0.9.1 → 0.61.0
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator: before 0.63.0
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
flyto-core: before 2.26.7
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
aiohttp: before 3.14.2
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
gitpython: before 3.1.57
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
aiohttp: before 3.14.3
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: 44.0.0 → 50.0.0
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: 42.0.0 → 49.0.0
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: HTTP request smuggling via WebSocket upgrade
aiohttp: before 3.14.2
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
gitpython: before 3.1.57
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
cryptography: 45.0.0 → 49.0.0
Malicious code in instalogin1234 (PyPI)
Malicious code in instalogin1234 (PyPI)
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
gitpython: before 3.1.56
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
transformers: before 5.10.0
Malicious code in trongriden (PyPI)
Malicious code in trongriden (PyPI)
Malicious code in wacve-utils (PyPI)
Malicious code in wacve-utils (PyPI)
Keras: HDF5 links can disclose local file contents
Keras: HDF5 links can disclose local file contents
keras: before 3.12.3
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.
gitpython: 3.1.50 → 3.1.51
Malicious code in nvtorch-oot-nightly (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
thumbor: before 7.8.0
Malicious code in catalogai (PyPI)
Malicious code in catalogai (PyPI)
Malicious code in telerape (PyPI)
Malicious code in telerape (PyPI)
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
thumbor: before 7.8.0
Malicious code in asdk-plugin-ai-platform (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
thumbor: before 7.8.0
Malicious code in aiprepkit (PyPI)
Malicious code in aiprepkit (PyPI)
Malicious code in ailaunchkit (PyPI)
Malicious code in ailaunchkit (PyPI)
Malicious code in walmart-genai-trace (PyPI)
Malicious code in walmart-genai-trace (PyPI)
Malicious code in reguestsc (PyPI)
Malicious code in reguestsc (PyPI)
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
onionshare-cli: before 2.6.4
Malicious code in aichannel (PyPI)
Malicious code in aichannel (PyPI)
Malicious code in cognikit (PyPI)
Malicious code in cognikit (PyPI)
Malicious code in aiassistcore (PyPI)
Malicious code in aiassistcore (PyPI)
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge: 1.0.0 → 1.3.1
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-legacy (PyPI)
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
thumbor: before 7.8.0
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
nltk: before 3.10.0
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
thumbor: before 7.8.0
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
thumbor: before 7.8.0
OnionShare Receive mode writes uploaded files even when file uploads are disabled
OnionShare Receive mode writes uploaded files even when file uploads are disabled
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
nltk: before 3.10.0
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
flyto-core: before 2.26.7
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
flyto-core: before 2.26.7
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
flyto-core: before 2.26.7
Malicious code in ml-data-shared (PyPI)
Malicious code in ml-data-shared (PyPI)
Malicious code in mcp-search-server (PyPI)
Malicious code in mcp-search-server (PyPI)
Malicious code in ml-shared (PyPI)
Malicious code in ml-shared (PyPI)
Malicious code in phabricator-client (PyPI)
Malicious code in phabricator-client (PyPI)
Malicious code in ai-perf-toolkit (PyPI)
Malicious code in ai-perf-toolkit (PyPI)
Malicious code in ml-fdbk-shared (PyPI)
Malicious code in ml-fdbk-shared (PyPI)
Malicious code in ml-nps-shared (PyPI)
Malicious code in ml-nps-shared (PyPI)
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: before 6.0.0
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
flyto-core: before 2.26.7
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
flyto-core: before 2.26.7
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
flyto-core: 2.26.6 → 2.26.7
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from a
pip: before 26.2
pip would incorrectly handle doubly-encoded package URLs from indexes
pip would incorrectly handle doubly-encoded package URLs from indexes
pip: before 26.2.0
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
penelope-shell-handler: before 0.20.0
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
matrix-commander: all versions
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro: before 5.1.6
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
proot-distro: before 5.1.5
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
datamodel-code-generator: 0.52.1 → 0.60.2
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
datamodel-code-generator: 0.51.0 → 0.60.2
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
datamodel-code-generator: 0.25.0 → 0.60.1
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator: 0.11.6 → 0.64.0
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator: before 0.62.0
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator: 0.9.1 → 0.61.0
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi: 2.0.0 → 2.2.1
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator: 0.14.1 → 0.60.2
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
datamodel-code-generator: 0.17.0 → 0.60.2
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator: 0.9.1 → 0.61.0
Malicious code in vtranalytic (PyPI)
Malicious code in vtranalytic (PyPI)
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator: 0.59.0 → 0.62.0
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator: before 0.63.0
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: before 0.63.0
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
thrift: before 0.24.0
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
thrift: before 0.24.0
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
thrift: before 0.24.0
Malicious code in cfgzen (PyPI)
Malicious code in cfgzen (PyPI)
NLTK vulnerable to Eval Injection via collocations CLI arguments
NLTK vulnerable to Eval Injection via collocations CLI arguments
nltk: before 3.9.3
Malicious code in blessclient (PyPI)
Malicious code in blessclient (PyPI)
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
open-webui: 0.9.0 → 0.10.0
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
open-webui: 0.8.11 → 0.10.0
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
gitpython: before 3.1.55
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
open-webui: 0.9.0 → 0.10.0
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
httplib2: before 0.32.0
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
gitpython: before 3.1.54
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
onnx: 1.3.0 → 1.22.0
Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
open-webui: 0.8.12 → 0.10.0
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
open-webui: before 0.10.0
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
open-webui: 0.6.27 → 0.10.0
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lo
nltk: before 3.9.3
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
open-webui: before 0.10.0
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
open-webui: before 0.10.0
Malicious code in discordnv (PyPI)
Malicious code in discordnv (PyPI)
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.
datasets: before 5.0.1
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
open-webui: before 0.10.0
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
gitpython: before 3.1.53
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
gitpython: before 3.1.54
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
gitpython: before 3.1.54
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
open-webui: before 0.10.0
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
open-webui: 0.9.2 → 0.10.0
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
pymdown-extensions: before 11.0.0
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
open-webui: before 0.10.0
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
open-webui: 0.9.5 → 0.10.0
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
open-webui: 0.9.6 → 0.10.0
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui: 0.9.6 → 0.10.0
AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
awscli: before 1.44.78
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
bedrock-agentcore: before 1.18.1
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
ray: before 2.56.0
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: all versions
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
open-webui: 0.7.0 → 0.10.0
libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
libp2p: all versions
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
open-webui: 0.6.16 → 0.10.0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: before 2026.7.4
Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
open-webui: before 0.10.0
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: before 6.14.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: before 6.14.2
pypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
pypdf: before 6.14.1
pypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
pypdf: before 6.14.0
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
litellm: before 1.82.0
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
jupyterlab: 4.6.0 → 4.6.2
JupyterLab PluginManager lock-rule enforcement bypass
JupyterLab PluginManager lock-rule enforcement bypass
jupyterlab: 4.6.0 → 4.6.2
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
jupyterlab: 4.6.0 → 4.6.2
Malicious code in make-helper (PyPI)
Malicious code in make-helper (PyPI)
Malicious code in dev-helper-bg (PyPI)
Malicious code in dev-helper-bg (PyPI)
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
litellm: before 1.83.7
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
jupyterlab: 4.6.0 → 4.6.2
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
litellm: before 1.84.0
LiteLLM: Local file read via request-supplied OIDC file references
LiteLLM: Local file read via request-supplied OIDC file references
litellm: before 1.83.10
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
jupyterlab: 4.6.0 → 4.6.2
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython: before 3.1.51
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
pyasn1: before 0.6.4
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython: before 3.1.52
Malicious code in lebinfmt (PyPI)
Malicious code in lebinfmt (PyPI)
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.
capstone: before 5.0.8
Malicious code in fluffy-octo-broccoli (PyPI)
Malicious code in fluffy-octo-broccoli (PyPI)
Malicious code in rasterkit (PyPI)
Malicious code in rasterkit (PyPI)
Malicious code in colorstack (PyPI)
Malicious code in colorstack (PyPI)
Malicious code in comp-colors (PyPI)
Malicious code in comp-colors (PyPI)
Malicious code in rasterkit-demo (PyPI)
Malicious code in rasterkit-demo (PyPI)
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
homeassistant: before 2026.6.0
Malicious code in reimagined-broccoli (PyPI)
Malicious code in reimagined-broccoli (PyPI)
Malicious code in animated-octo-spoon (PyPI)
Malicious code in animated-octo-spoon (PyPI)
GitPython unsafe clone option gate bypass through joined short options
GitPython unsafe clone option gate bypass through joined short options
gitpython: 3.1.50 → 3.1.51
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1: before 0.6.4
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
setuptools: before 83.0.0
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
pyasn1: before 0.6.4
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
gitpython: before 3.1.51
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
pillow: 5.1.0 → 12.3.0
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
pillow: before 12.3.0
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
pillow: 12.0.0 → 12.3.0
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
pillow: before 12.3.0
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
pillow: before 12.3.0
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
pillow: before 12.3.0
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
pillow: before 12.3.0
Malicious code in neroteam-v1 (PyPI)
Malicious code in neroteam-v1 (PyPI)
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
pillow: 5.2.0 → 12.3.0
vLLM denial of service via prompt embeds on M-RoPE models
vLLM denial of service via prompt embeds on M-RoPE models
vllm: 0.12.0 → 0.24.0
Malicious code in paperclip-ai (PyPI)
Malicious code in paperclip-ai (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
pillow: before 12.3.0
Malicious code in shark-e2e-bnsneo (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
Malicious code in roles-royce (PyPI)
Malicious code in roles-royce (PyPI)
Malicious code in trongrider (PyPI)
Malicious code in trongrider (PyPI)
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
pillow: before 12.3.0
Malicious code in kimitalk (PyPI)
Malicious code in kimitalk (PyPI)
Malicious code in nemopush (PyPI)
Malicious code in nemopush (PyPI)
Malicious code in kimichat (PyPI)
Malicious code in kimichat (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
Malicious code in automatic-octo-invention (PyPI)
Malicious code in automatic-octo-invention (PyPI)
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
pillow: 8.2.0 → 12.3.0
Malicious code in vantrala (PyPI)
Malicious code in vantrala (PyPI)
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
pillow: before 12.3.0
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
pillow: before 12.3.0
Malicious code in data-parser-utils (PyPI)
Malicious code in data-parser-utils (PyPI)
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
keras: before 3.12.3
Malicious code in python-devplatform-client (PyPI)
Malicious code in python-devplatform-client (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in mlflow-ui (PyPI)
Malicious code in mlflow-ui (PyPI)
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope.
surrealdb: before 1.0.1
Malicious code in dwh-kafka-client (PyPI)
Malicious code in dwh-kafka-client (PyPI)
Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
prompty: before 2.0.0b2
vLLM has Remote DoS via Invalid Recovered Token Reinjection
vLLM has Remote DoS via Invalid Recovered Token Reinjection
vllm: 0.17.1 → 0.24.0
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
vllm: before 0.24.0
Malicious code in discord-telemetry (PyPI)
Malicious code in discord-telemetry (PyPI)
Malicious code in abseil-py (PyPI)
Malicious code in abseil-py (PyPI)
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
mcp: before 1.28.1
Snowflake Connector for Python improperly verifies TLS hostnames
Snowflake Connector for Python improperly verifies TLS hostnames
snowflake-connector-python: before 3.18.1
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
mcp: 1.23.0 → 1.27.2
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
mcp: before 1.27.2
Malicious code in xyq-drama-skill (PyPI)
Malicious code in xyq-drama-skill (PyPI)
PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters
PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters
lightning: before 2022.6.15
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
ddtrace: before 4.8.2
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.
pytorch-lightning: before 2.6.6
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.
lightning: before 2.6.6
Malicious code in northstart-sdk (PyPI)
Malicious code in northstart-sdk (PyPI)
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools: before 1.15.1
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
snowflake-sqlalchemy: 1.1.6 → 1.11.0
Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
keras: before 3.12.3
PyOD persistence.load deserializes untrusted artifacts before validation
PyOD persistence.load deserializes untrusted artifacts before validation
pyod: 3.5.0 → 3.6.2
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
praisonaiagents: before 4.5.128
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
pytorch-lightning: all versions
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
ironic-python-agent: before 26.1.6
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while as
prowler-cloud: before 5.30.3
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: before 0.22.0
Tooling for PyPI
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.