PyPI incidents
Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Malicious code in multyproccess (PyPI)
Malicious code in multyproccess (PyPI)
Malicious code in msrcpoc (PyPI)
Malicious code in msrcpoc (PyPI)
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway: before 1.0.2
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
Malicious code in envprovision (PyPI)
Malicious code in envprovision (PyPI)
Malicious code in cryptgraphy (PyPI)
Malicious code in cryptgraphy (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
Malicious code in scrambleeeer (PyPI)
Malicious code in scrambleeeer (PyPI)
Malicious code in requests-crypt (PyPI)
Malicious code in requests-crypt (PyPI)
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
xinference: before 2.7.0
Malicious code in boto4 (PyPI)
Malicious code in boto4 (PyPI)
Malicious code in reqcrypts (PyPI)
Malicious code in reqcrypts (PyPI)
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
hydra-core: before 1.3.4
Malicious code in scrambleeer (PyPI)
Malicious code in scrambleeer (PyPI)
asteval has a Sandbox Escape via BaseException Subclasses
asteval has a Sandbox Escape via BaseException Subclasses
asteval: before 1.0.9
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
wagtail: before 7.0.9
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb: before 0.3.0
Wagtail: Denial of service via unbounded filter specs in the image preview
Wagtail: Denial of service via unbounded filter specs in the image preview
wagtail: before 7.0.8
Wagtail: Improper permission handling in image preview
Wagtail: Improper permission handling in image preview
wagtail: before 7.0.8
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API
wagtail: before 7.0.9
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
wagtail: before 7.0.8
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
zoo-kcl: before 0.3.129
Wagtail: Pages translations can be created without page permissions when using simple_translation
Wagtail: Pages translations can be created without page permissions when using simple_translation
wagtail: before 7.0.8
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node: before 0.9.0a11
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
zoo-kcl: before 0.3.153
Wagtail: Reflected XSS in dynamic image URL generator view
Wagtail: Reflected XSS in dynamic image URL generator view
wagtail: 7.3 → 7.3.3
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval: before 1.0.9
Wagtail: Improper restriction handling on Page translation API endpoint
Wagtail: Improper restriction handling on Page translation API endpoint
wagtail: before 7.0.9
Wagtail: Identification of documents by SHA1 hash
Wagtail: Identification of documents by SHA1 hash
wagtail: before 7.0.9
Wagtail: Improper permission handling when copying snippets
Wagtail: Improper permission handling when copying snippets
wagtail: before 7.0.9
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
surfio has an out-of-bounds read
surfio has an out-of-bounds read
surfio: before 0.0.19
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
mobsf: before 4.5.1
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
glances: before 4.5.6
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
jupyterlab: 3.3.0 → 4.5.10
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
lemur: before 1.9.3
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
lemur: before 1.9.3
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
mobsf: before 4.5.1
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
jupyterlab: before 4.5.10
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
geolens: before 1.2.3
MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
mlflow: 2.14.0rc0 → 3.13.0rc0
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow: before 3.15.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai-slim: 1.65.0 → 1.106.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai: 1.65.0 → 1.106.0
Malicious code in rc4-secure (PyPI)
Malicious code in rc4-secure (PyPI)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
document-merge-service: before 9.1.0
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
lemur: before 1.9.3
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
geolens: before 1.2.4
Malicious code in libasync (PyPI)
Malicious code in libasync (PyPI)
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: before 0.10.0
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
copier: 9.5.0 → 9.15.2
devpi-server may leak database contents
devpi-server may leak database contents
devpi-server: before 6.20.2
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: before 0.10.0
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
jupyterlab: 4.5.0 → 4.5.10
Malicious code in reqcrypt-dev (PyPI)
Malicious code in reqcrypt-dev (PyPI)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
glances: before 4.5.6
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
ansible-jailexec: before 2.0.0
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
mcp-contextforge-gateway: before 1.0.3
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
stata-mcp: before 1.19.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle: before 4.1.0
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
homeassistant: before 2026.6.0
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata: before 6.2.9
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes: before 3.9.0
Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion
copyparty: before 1.20.17
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
lemur: before 1.9.3
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: before 0.22.0
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
glances: before 4.5.6
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
glances: 4.5.2 → 4.5.6
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: before 0.6.0
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
glances: before 4.5.6
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: all versions
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
lemur: before 1.9.3
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: before 0.6.0
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: before 3.10.0
SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
sglang: all versions
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: before 0.6.0
vLLM: Completion prompt lists fan out into unbounded engine requests
vLLM: Completion prompt lists fan out into unbounded engine requests
vllm: 0.19.0 → 0.26.0
libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
libp2p: all versions
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: before 6.1.0
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
lemur: before 1.9.3
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
geolens-cli: before 1.2.3
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
lemur: before 1.9.3
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: before 0.6.0
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
lemur: 0.5.0 → 1.9.3
MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check
mobsf: before 4.5.1
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
mobsf: before 4.5.1
MONAI vulnerable to OS command injection
MONAI vulnerable to OS command injection
monai: before 1.6.0
Malicious code in reqcrypt (PyPI)
Malicious code in reqcrypt (PyPI)
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
lemur: before 1.9.3
Malicious code in deepface-weights (PyPI)
Malicious code in deepface-weights (PyPI)
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
monai: before 1.6.0
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata: before 6.2.9
Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion
copyparty: before 1.20.17
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
lemur: before 1.9.3
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
monai: before 1.6.0
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
lemur: before 1.9.3
Malicious code in deepface-weight (PyPI)
Malicious code in deepface-weight (PyPI)
devpi-server may leak database contents
devpi-server may leak database contents
devpi-server: before 6.20.2
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
lemur: before 1.9.3
MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check
mobsf: before 4.5.1
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: before 6.1.0
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
lemur: before 1.9.3
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
lemur: 0.5.0 → 1.9.3
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
mobsf: before 4.5.1
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
lemur: before 1.9.3
Malicious code in httpz-requests (PyPI)
Malicious code in httpz-requests (PyPI)
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
lemur: before 1.9.3
surfio has an out-of-bounds read
surfio has an out-of-bounds read
surfio: before 0.0.19
Malicious code in infogram-bot (PyPI)
Malicious code in infogram-bot (PyPI)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
glances: before 4.5.6
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: before 0.6.0
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
glances: before 4.5.6
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: before 0.6.0
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
glances: 4.5.2 → 4.5.6
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
glances: before 4.5.6
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
glances: before 4.5.6
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: before 0.6.0
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: before 0.6.0
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow: before 3.15.0
Malicious code in kb-ai (PyPI)
Malicious code in kb-ai (PyPI)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
mcp-contextforge-gateway: before 1.0.3
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: before 1.1.0
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
nltk: before 3.10.0
vLLM: Completion prompt lists fan out into unbounded engine requests
vLLM: Completion prompt lists fan out into unbounded engine requests
vllm: 0.19.0 → 0.26.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai-slim: 1.65.0 → 1.106.0
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
ansible-jailexec: before 2.0.0
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configurat
apache-airflow: before 3.3.1
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
stata-mcp: before 1.19.0
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those se
apache-airflow: before 3.3.1
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: before 3.10.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle: before 4.1.0
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does n
apache-airflow: before 3.3.1
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
apache-airflow: before 3.3.1
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler proce
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore
apache-airflow: before 3.3.1
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unus
apache-airflow-providers-google: before 22.3.0
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m
apache-airflow: before 3.3.1
Malicious code in morpho-sdk (PyPI)
Malicious code in morpho-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
Malicious code in joule-btp-extension (PyPI)
Malicious code in joule-btp-extension (PyPI)
Malicious code in dlmm (PyPI)
Malicious code in dlmm (PyPI)
Malicious code in joule-sbx-poc (PyPI)
Malicious code in joule-sbx-poc (PyPI)
Malicious code in telebot-pro (PyPI)
Malicious code in telebot-pro (PyPI)
Malicious code in btcflip (PyPI)
Malicious code in btcflip (PyPI)
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
open-webui: 0.9.0 → 0.11.0
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
keras: before 3.12.3
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
awscli: before 1.45.28
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: before 11.0.1
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
open-webui: before 0.11.0
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
open-webui: 0.9.6 → 0.11.0
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
open-webui: 0.9.6 → 0.11.0
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: before 6.15.0
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
open-webui: 0.10.0 → 0.11.0
Keras: Lambda deserialization can bypass safe mode and execute code
Keras: Lambda deserialization can bypass safe mode and execute code
keras: before 3.12.3
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
open-webui: 0.9.6 → 0.11.0
h2: Duplicate Host header could facilitate request smuggling
h2: Duplicate Host header could facilitate request smuggling
h2: before 4.4.1
Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
keras: before 3.12.3
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: before 6.15.0
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
open-webui: 0.8.0 → 0.11.0
Keras: DiskIOStore permits path traversal through crafted layer names
Keras: DiskIOStore permits path traversal through crafted layer names
keras: before 3.12.3
Keras: HDF5 links can disclose local file contents
Keras: HDF5 links can disclose local file contents
keras: before 3.12.3
Open WebUI: DNS Rebinding SSRF Bypass
Open WebUI: DNS Rebinding SSRF Bypass
open-webui: before 0.11.0
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
open-webui: 0.8.8 → 0.11.0
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
open-webui: 0.6.34 → 0.11.0
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
open-webui: 0.9.6 → 0.11.0
Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
keras: before 3.12.3
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
open-webui: 0.5.0 → 0.11.0
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
open-webui: 0.10.0 → 0.11.0
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
open-webui: 0.9.0 → 0.11.0
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
open-webui: 0.8.8 → 0.11.0
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
open-webui: 0.9.0 → 0.11.0
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
open-webui: 0.7.0 → 0.11.0
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
aiosend: before 3.0.7
Malicious code in pytablute (PyPI)
Malicious code in pytablute (PyPI)
Malicious code in chaintest (PyPI)
Malicious code in chaintest (PyPI)
Malicious code in bigtime (PyPI)
Malicious code in bigtime (PyPI)
Malicious code in neutrl-contracts (PyPI)
Malicious code in neutrl-contracts (PyPI)
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backe
apache-airflow-providers-yandex: before 4.5.1
Malicious code in btcflx (PyPI)
Malicious code in btcflx (PyPI)
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling
apache-airflow-providers-amazon: before 9.34.0
Malicious code in neutrl-core (PyPI)
Malicious code in neutrl-core (PyPI)
Malicious code in kotoraka (PyPI)
Malicious code in kotoraka (PyPI)
Malicious code in plp-contract (PyPI)
Malicious code in plp-contract (PyPI)
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-postgres: before 3.1.1
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-sqlite: before 3.1.1
Malicious code in cubesat-upstream-driver (PyPI)
Malicious code in cubesat-upstream-driver (PyPI)
Malicious code in kotanku (PyPI)
Malicious code in kotanku (PyPI)
Malicious code in riakcs (PyPI)
Malicious code in riakcs (PyPI)
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
gitpython: before 3.1.58
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
gitpython: before 3.1.58
Malicious code in pydanticc (PyPI)
Malicious code in pydanticc (PyPI)
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
gitpython: before 3.1.58
Malicious code in speed-hashes (PyPI)
Malicious code in speed-hashes (PyPI)
Malicious code in flasq (PyPI)
Malicious code in flasq (PyPI)
Malicious code in fast-hashes (PyPI)
Malicious code in fast-hashes (PyPI)
Malicious code in atlas-internal (PyPI)
Malicious code in atlas-internal (PyPI)
Malicious code in cdktn-provider-azurerm (PyPI)
Malicious code in cdktn-provider-azurerm (PyPI)
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
gitpython: before 3.1.58
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: Possible large memory usage for large /ToUnicode streams
pypdf: before 6.15.0
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
gitpython: before 3.1.58
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
gitpython: before 3.1.58
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
pypdf: before 6.15.0
Malicious code in fastapii (PyPI)
Malicious code in fastapii (PyPI)
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
pymdown-extensions: before 11.0.1
Malicious code in idnna (PyPI)
Malicious code in idnna (PyPI)
Malicious code in alphalend-layouts (PyPI)
Malicious code in alphalend-layouts (PyPI)
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside
apache-polaris: before 1.7.0
Malicious code in decapod-common (PyPI)
Malicious code in decapod-common (PyPI)
Malicious code in alphalend-abi (PyPI)
Malicious code in alphalend-abi (PyPI)
Malicious code in xayoub-xctxteam (PyPI)
Malicious code in xayoub-xctxteam (PyPI)
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
awscli: before 1.45.28
h2: Duplicate Host header could facilitate request smuggling
h2: Duplicate Host header could facilitate request smuggling
h2: before 4.4.1
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-postgres: before 3.1.1
Malicious code in crypto-trading-toolkit (PyPI)
Malicious code in crypto-trading-toolkit (PyPI)
Malicious code in numpyp (PyPI)
Malicious code in numpyp (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
Malicious code in mnemonic-py (PyPI)
Malicious code in mnemonic-py (PyPI)
Malicious code in eth-account-wallet (PyPI)
Malicious code in eth-account-wallet (PyPI)
Malicious code in uncrypt (PyPI)
Malicious code in uncrypt (PyPI)
Malicious code in defi-sdk-py (PyPI)
Malicious code in defi-sdk-py (PyPI)
Malicious code in solana-sniper-bot (PyPI)
Malicious code in solana-sniper-bot (PyPI)
Malicious code in gcli-control (PyPI)
Malicious code in gcli-control (PyPI)
Malicious code in bitcoinlib-py (PyPI)
Malicious code in bitcoinlib-py (PyPI)
Malicious code in bip39-py (PyPI)
Malicious code in bip39-py (PyPI)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator: 0.9.1 → 0.61.0
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
penelope-shell-handler: before 0.20.0
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
open-webui: 0.9.0 → 0.10.0
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
pypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
pypdf: before 6.14.1
pypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
pypdf: before 6.14.0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: before 2026.7.4
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
open-webui: 0.8.11 → 0.10.0
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
open-webui: before 0.10.0
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
open-webui: 0.9.5 → 0.10.0
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
thumbor: before 7.8.0
Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
open-webui: before 0.10.0
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
open-webui: 0.9.2 → 0.10.0
Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
open-webui: 0.8.12 → 0.10.0
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
open-webui: before 0.10.0
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
open-webui: 0.6.16 → 0.10.0
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
open-webui: 0.6.27 → 0.10.0
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
flyto-core: before 2.26.7
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro: before 5.1.6
OnionShare Receive mode writes uploaded files even when file uploads are disabled
OnionShare Receive mode writes uploaded files even when file uploads are disabled
onionshare-cli: before 2.6.4
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
onnx: 1.3.0 → 1.22.0
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
nltk: before 3.10.0
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
nltk: before 3.10.0
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator: 0.11.6 → 0.64.0
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
nanobot-ai: before 0.2.1
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: before 0.63.0
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
cryptography: before 49.0.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator: 0.14.1 → 0.60.2
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
flyto-core: before 2.26.7
AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
awscli: before 1.44.78
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
mysql-mcp-server: before 0.3.0
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
thumbor: before 7.8.0
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: before 49.0.0
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
open-webui: 0.7.0 → 0.10.0
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
open-webui: 0.9.0 → 0.10.0
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
open-webui: 0.9.6 → 0.10.0
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi: 2.0.0 → 2.2.1
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
pymdown-extensions: before 11.0.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: before 6.14.2
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
thumbor: before 7.8.0
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
thumbor: before 7.8.0
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: all versions
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: before 0.15.0
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
deepsearcher: all versions
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: before 6.0.0
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
proot-distro: before 5.1.5
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge: 1.0.0 → 1.3.1
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
flyto-core: before 2.26.7
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
open-webui: before 0.10.0
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
datamodel-code-generator: 0.17.0 → 0.60.2
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: before 6.14.0
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator: 0.59.0 → 0.62.0
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
flyto-core: before 2.26.7
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
flyto-core: before 2.26.7
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator: before 0.63.0
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator: 0.9.1 → 0.61.0
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
bedrock-agentcore: before 1.18.1
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator: before 0.62.0
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: 44.0.0 → 50.0.0
awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
awxkit: all versions
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
thumbor: before 7.8.0
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
aiohttp: before 3.14.2
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
aiohttp: before 3.14.3
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
datamodel-code-generator: 0.51.0 → 0.60.2
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
datamodel-code-generator: 0.52.1 → 0.60.2
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent: all versions
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
datamodel-code-generator: 0.25.0 → 0.60.1
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
open-webui: before 0.10.0
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui: 0.9.6 → 0.10.0
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
thumbor: before 7.8.0
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
flyto-core: before 2.26.7
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
open-webui: before 0.10.0
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: HTTP request smuggling via WebSocket upgrade
aiohttp: before 3.14.2
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
open-webui: before 0.10.0
Malicious code in psbt-helpers (PyPI)
Malicious code in psbt-helpers (PyPI)
Malicious code in coldcard-helpers (PyPI)
Malicious code in coldcard-helpers (PyPI)
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
open-webui: 0.9.6 → 0.11.0
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
open-webui: 0.9.0 → 0.11.0
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
open-webui: 0.8.8 → 0.11.0
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
open-webui: 0.9.6 → 0.11.0
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
open-webui: 0.5.0 → 0.11.0
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
open-webui: 0.8.8 → 0.11.0
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
open-webui: 0.8.0 → 0.11.0
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
open-webui: 0.10.0 → 0.11.0
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
open-webui: 0.10.0 → 0.11.0
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
open-webui: 0.9.6 → 0.11.0
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
open-webui: 0.9.6 → 0.11.0
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
open-webui: 0.7.0 → 0.11.0
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
open-webui: 0.6.34 → 0.11.0
Open WebUI: DNS Rebinding SSRF Bypass
Open WebUI: DNS Rebinding SSRF Bypass
open-webui: before 0.11.0
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
open-webui: before 0.11.0
Malicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code in psbt-utils (PyPI)
Malicious code in psbt-utils (PyPI)
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
open-webui: 0.9.0 → 0.11.0
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
open-webui: 0.9.0 → 0.11.0
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Ea
django: before 5.2.17
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
aiohttp: before 3.14.3
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
gitpython: before 3.1.56
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: 44.0.0 → 50.0.0
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
aiohttp: before 3.14.2
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: HTTP request smuggling via WebSocket upgrade
aiohttp: before 3.14.2
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
cryptography: before 49.0.0
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
gitpython: before 3.1.57
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
gitpython: before 3.1.57
Malicious code in instalogin1234 (PyPI)
Malicious code in instalogin1234 (PyPI)
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: before 49.0.0
Keras: HDF5 links can disclose local file contents
Keras: HDF5 links can disclose local file contents
keras: before 3.12.3
Malicious code in trongriden (PyPI)
Malicious code in trongriden (PyPI)
Malicious code in wacve-utils (PyPI)
Malicious code in wacve-utils (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Malicious code in telerape (PyPI)
Malicious code in telerape (PyPI)
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
nltk: before 3.10.0
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
thumbor: before 7.8.0
OnionShare Receive mode writes uploaded files even when file uploads are disabled
OnionShare Receive mode writes uploaded files even when file uploads are disabled
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
thumbor: before 7.8.0
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge: 1.0.0 → 1.3.1
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
thumbor: before 7.8.0
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
thumbor: before 7.8.0
Malicious code in aiprepkit (PyPI)
Malicious code in aiprepkit (PyPI)
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
thumbor: before 7.8.0
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
thumbor: before 7.8.0
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
nltk: before 3.10.0
Malicious code in aiassistcore (PyPI)
Malicious code in aiassistcore (PyPI)
Malicious code in cognikit (PyPI)
Malicious code in cognikit (PyPI)
Malicious code in aichannel (PyPI)
Malicious code in aichannel (PyPI)
Malicious code in reguestsc (PyPI)
Malicious code in reguestsc (PyPI)
Malicious code in walmart-genai-trace (PyPI)
Malicious code in walmart-genai-trace (PyPI)
Malicious code in ailaunchkit (PyPI)
Malicious code in ailaunchkit (PyPI)
Malicious code in catalogai (PyPI)
Malicious code in catalogai (PyPI)
Malicious code in ml-nps-shared (PyPI)
Malicious code in ml-nps-shared (PyPI)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
flyto-core: before 2.26.7
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
flyto-core: before 2.26.7
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
flyto-core: before 2.26.7
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
flyto-core: before 2.26.7
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
flyto-core: before 2.26.7
Malicious code in mcp-search-server (PyPI)
Malicious code in mcp-search-server (PyPI)
Malicious code in ml-data-shared (PyPI)
Malicious code in ml-data-shared (PyPI)
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
flyto-core: 2.26.6 → 2.26.7
Malicious code in ml-fdbk-shared (PyPI)
Malicious code in ml-fdbk-shared (PyPI)
Malicious code in ai-perf-toolkit (PyPI)
Malicious code in ai-perf-toolkit (PyPI)
Malicious code in ml-shared (PyPI)
Malicious code in ml-shared (PyPI)
Malicious code in phabricator-client (PyPI)
Malicious code in phabricator-client (PyPI)
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: before 6.0.0
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
penelope-shell-handler: before 0.20.0
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro: before 5.1.6
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
proot-distro: before 5.1.5
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from a
pip: before 26.2
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
matrix-commander: all versions
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator: before 0.62.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
datamodel-code-generator: 0.25.0 → 0.60.1
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator: 0.9.1 → 0.61.0
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator: 0.9.1 → 0.61.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator: 0.14.1 → 0.60.2
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator: 0.11.6 → 0.64.0
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator: before 0.63.0
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
datamodel-code-generator: 0.17.0 → 0.60.2
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: before 0.63.0
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
datamodel-code-generator: 0.51.0 → 0.60.2
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi: 2.0.0 → 2.2.1
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator: 0.59.0 → 0.62.0
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
datamodel-code-generator: 0.52.1 → 0.60.2
Malicious code in vtranalytic (PyPI)
Malicious code in vtranalytic (PyPI)
Malicious code in cfgzen (PyPI)
Malicious code in cfgzen (PyPI)
NLTK vulnerable to Eval Injection via collocations CLI arguments
NLTK vulnerable to Eval Injection via collocations CLI arguments
nltk: before 3.9.3
Malicious code in blessclient (PyPI)
Malicious code in blessclient (PyPI)
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
bedrock-agentcore: before 1.18.1
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
open-webui: 0.7.0 → 0.10.0
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
pymdown-extensions: before 11.0.0
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
gitpython: before 3.1.55
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
gitpython: before 3.1.54
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
open-webui: before 0.10.0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: before 2026.7.4
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
ray: before 2.56.0
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
open-webui: before 0.10.0
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
open-webui: before 0.10.0
libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
libp2p: all versions
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
gitpython: before 3.1.54
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
open-webui: 0.6.27 → 0.10.0
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
gitpython: before 3.1.54
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.
datasets: before 5.0.1
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
open-webui: 0.9.2 → 0.10.0
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
httplib2: before 0.32.0
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lo
nltk: before 3.9.3
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
open-webui: 0.9.0 → 0.10.0
Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
open-webui: before 0.10.0
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
open-webui: 0.6.16 → 0.10.0
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui: 0.9.6 → 0.10.0
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
open-webui: before 0.10.0
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
gitpython: before 3.1.53
Malicious code in discordnv (PyPI)
Malicious code in discordnv (PyPI)
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
open-webui: before 0.10.0
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
open-webui: 0.9.6 → 0.10.0
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
open-webui: before 0.10.0
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: all versions
AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
awscli: before 1.44.78
Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
open-webui: 0.8.12 → 0.10.0
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
onnx: 1.3.0 → 1.22.0
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
open-webui: 0.9.5 → 0.10.0
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
open-webui: 0.9.0 → 0.10.0
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
open-webui: 0.8.11 → 0.10.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: before 6.14.2
pypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
pypdf: before 6.14.0
pypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
pypdf: before 6.14.1
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: before 6.14.0
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
jupyterlab: 4.6.0 → 4.6.2
Malicious code in dev-helper-bg (PyPI)
Malicious code in dev-helper-bg (PyPI)
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
jupyterlab: 4.6.0 → 4.6.2
JupyterLab PluginManager lock-rule enforcement bypass
JupyterLab PluginManager lock-rule enforcement bypass
jupyterlab: 4.6.0 → 4.6.2
Malicious code in make-helper (PyPI)
Malicious code in make-helper (PyPI)
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
jupyterlab: 4.6.0 → 4.6.2
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
jupyterlab: 4.6.0 → 4.6.2
Malicious code in comp-colors (PyPI)
Malicious code in comp-colors (PyPI)
Malicious code in fluffy-octo-broccoli (PyPI)
Malicious code in fluffy-octo-broccoli (PyPI)
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
gitpython: before 3.1.51
GitPython unsafe clone option gate bypass through joined short options
GitPython unsafe clone option gate bypass through joined short options
gitpython: 3.1.50 → 3.1.51
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython: before 3.1.51
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1: before 0.6.4
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython: before 3.1.52
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
homeassistant: before 2026.6.0
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.
capstone: before 5.0.8
Malicious code in lebinfmt (PyPI)
Malicious code in lebinfmt (PyPI)
Malicious code in colorstack (PyPI)
Malicious code in colorstack (PyPI)
Malicious code in rasterkit-demo (PyPI)
Malicious code in rasterkit-demo (PyPI)
Malicious code in reimagined-broccoli (PyPI)
Malicious code in reimagined-broccoli (PyPI)
Malicious code in animated-octo-spoon (PyPI)
Malicious code in animated-octo-spoon (PyPI)
Malicious code in rasterkit (PyPI)
Malicious code in rasterkit (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
Malicious code in kimichat (PyPI)
Malicious code in kimichat (PyPI)
Malicious code in automatic-octo-invention (PyPI)
Malicious code in automatic-octo-invention (PyPI)
Malicious code in neroteam-v1 (PyPI)
Malicious code in neroteam-v1 (PyPI)
Malicious code in trongrider (PyPI)
Malicious code in trongrider (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
Malicious code in roles-royce (PyPI)
Malicious code in roles-royce (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
Malicious code in vantrala (PyPI)
Malicious code in vantrala (PyPI)
Malicious code in kimitalk (PyPI)
Malicious code in kimitalk (PyPI)
vLLM denial of service via prompt embeds on M-RoPE models
vLLM denial of service via prompt embeds on M-RoPE models
vllm: 0.12.0 → 0.24.0
Malicious code in nemopush (PyPI)
Malicious code in nemopush (PyPI)
Malicious code in paperclip-ai (PyPI)
Malicious code in paperclip-ai (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
keras: before 3.12.3
Malicious code in data-parser-utils (PyPI)
Malicious code in data-parser-utils (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in python-devplatform-client (PyPI)
Malicious code in python-devplatform-client (PyPI)
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope.
surrealdb: before 1.0.1
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
vllm: before 0.24.0
Malicious code in dwh-kafka-client (PyPI)
Malicious code in dwh-kafka-client (PyPI)
Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
prompty: before 2.0.0b2
vLLM has Remote DoS via Invalid Recovered Token Reinjection
vLLM has Remote DoS via Invalid Recovered Token Reinjection
vllm: 0.17.1 → 0.24.0
Malicious code in discord-telemetry (PyPI)
Malicious code in discord-telemetry (PyPI)
Malicious code in abseil-py (PyPI)
Malicious code in abseil-py (PyPI)
Malicious code in northstart-sdk (PyPI)
Malicious code in northstart-sdk (PyPI)
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
ddtrace: before 4.8.2
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.
lightning: all versions
Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
keras: before 3.12.3
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
ironic-python-agent: before 26.1.6
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
praisonaiagents: before 4.5.128
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes: before 3.9.0
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: before 0.22.0
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator's configuration, not the attacker.
bbot: 1.1.7 → 3.0.0
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for example via filedownload), bypassed the guard and caused an attacker-controlled symlink to be written into the extraction directory. The effect is limited to planting the symlink (its tar
bbot: 2.3.1 → 3.0.0
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue
django: 5.2 → 5.2.16
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
django: before 5.2.16
Django: GDALRaster may over-read heap memory when constructed from bytes
Django: GDALRaster may over-read heap memory when constructed from bytes
django: before 5.2.16
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DAG read authorization. Deployments that co-locate multiple Dags in a single file and rely on per-DAG access control to limit source visibility are affected; single-Dag-p
apache-airflow: before 3.3.0
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
django: 5.2 → 5.2.16
Django: cache middleware may expose private responses when unrelated request cookies are present
Django: cache middleware may expose private responses when unrelated request cookies are present
django: before 5.2.16
apache-airflow DAG source authorization bypass exposes co-located DAG source
apache-airflow DAG source authorization bypass exposes co-located DAG source
apache-airflow: before 3.3.0
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
django: 5.2 → 5.2.16
Pulp incorrectly assigns RBAC permissions in tasks that create objects
Pulp incorrectly assigns RBAC permissions in tasks that create objects
pulpcore: all versions
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
aiosmtplib: before 5.1.1
Keras: Lambda deserialization can bypass safe mode and execute code
Keras: Lambda deserialization can bypass safe mode and execute code
keras: before 3.12.3
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: before 0.19.1
MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
mlflow: 2.14.0rc0 → 3.13.0rc0
Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
keras: before 3.12.3
NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAF
NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal `../` sequences but fails to account for percent-encoded traversal sequences such as `..%2f`. The `url2pathname()` function decodes these sequences after the validation step, allowing an attacker to bypass the protection. This vulnerability enables an attacker to read arbitrary files accessible to the Python process b
nltk: all versions
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.
msgpack: before 1.2.1
Flawfinder output manipulation via untrusted filenames and source text
Flawfinder output manipulation via untrusted filenames and source text
flawfinder: before 2.0.20
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
lemur: before 1.9.2
justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: 0.9.0 → 1.22.0
OctoPrint has XSS in its Suppressed Command Notifications
OctoPrint has XSS in its Suppressed Command Notifications
octoprint: before 1.11.8
OctoPrint has possible file exfiltration via query parameters on upload endpoints
OctoPrint has possible file exfiltration via query parameters on upload endpoints
octoprint: before 1.11.8
Keras: DiskIOStore permits path traversal through crafted layer names
Keras: DiskIOStore permits path traversal through crafted layer names
keras: before 3.12.3
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
msgpack: before 1.2.1
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
stigmem-node: before 0.9.0a12
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: before 0.42.1
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
jupyterlab: before 4.5.9
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
stigmem-node: before 0.9.0a12
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stigmem-node: before 0.9.0a12
OpenStack Horizon RC file generation does not escape special characters in project names
OpenStack Horizon RC file generation does not escape special characters in project names
horizon: all versions
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
langchain: before 1.3.9
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
vllm: before 0.22.0
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
pyjwt: 2.0.0 → 2.13.0
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
pyjwt: 2.0.0 → 2.13.0
ChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
chromadb: ≥ 0.4.17
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
chromadb: ≥ 0.5.0
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
chromadb: ≥ 0.4.17
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
meta-ads-mcp: before 1.0.109
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD) instead of the actual extraction destination. When the process runs with CWD set to `/`, which is common in Docker containers, CI/CD runners, and Jupyter environments, the validation boundary become
keras: before 3.14.0
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
vllm: 0.8.0 → 0.19.0
Keras archive extraction utilities allow path traversal and arbitrary file writes
Keras archive extraction utilities allow path traversal and arbitrary file writes
keras: before 3.14.0
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method splits the base64 data string on commas to extract individual JPEG frames without enforcing a frame count limit. An attacker can exploit this by crafting a single API request containing thousands of comma-separated base64-encoded JPEG frames in a data URL, causin
vllm: 0.8.0 → 0.19.0
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
vllm: before 0.22.0
Apache Airflow has a Path Traversal issue
Apache Airflow has a Path Traversal issue
apache-airflow-providers-samba: before 4.12.6
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write files to arbitrary locations on the Samba target when the operator ran. Upgrade apache-airflow-providers-sam
apache-airflow-providers-samba: before 4.12.6
awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
awxkit: all versions
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
deepsearcher: all versions
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
mysql-mcp-server: before 0.3.0
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
starlette: before 1.0.1
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
oslo-messaging: ≥ 1.0.0
SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
sglang: all versions
kas's late signature validation may allow unnoticed repository manipulations
kas's late signature validation may allow unnoticed repository manipulations
kas: 4.8 → 5.3
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to than
django: 5.2 → 5.2.15
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to
django: 5.2 → 5.2.15
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affec
django: 5.2 → 5.2.15
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
django: 5.2.0 → 5.2.15
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank A
django: 5.2 → 5.2.15
Django: signed cookies are vulnerable to salt namespace collisions
Django: signed cookies are vulnerable to salt namespace collisions
django: before 5.2.15
Django: has_vary_header may expose cached responses when Vary values contain whitespace
Django: has_vary_header may expose cached responses when Vary values contain whitespace
django: before 5.2.15
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
django: before 5.2.15
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: all versions
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
nanobot-ai: before 0.2.1
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: before 0.15.0
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent: all versions
kas checks out SHA-like git branches as valid commits
kas checks out SHA-like git branches as valid commits
kas: before 5.3
stigmem-node's Postgres schema identifier handling required defensive quoting
stigmem-node's Postgres schema identifier handling required defensive quoting
stigmem-node: before 0.9.0a2
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
stigmem-node: before 0.9.0a2
stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation
stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation
stigmem-node: before 0.9.0a2
stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment
stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment
stigmem-node: before 0.9.0a2
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
praisonai-platform: before 0.1.4
stigmem-node's federation peer registration lacked explicit out-of-band approval
stigmem-node's federation peer registration lacked explicit out-of-band approval
stigmem-node: before 0.9.0a2
stigmem-node's federation peer token timestamp validation may reject valid peer tokens
stigmem-node's federation peer token timestamp validation may reject valid peer tokens
stigmem-node: before 0.9.0a2
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
aiosend: before 3.0.7
justhtml introduces denial-of-service hardening
justhtml introduces denial-of-service hardening
justhtml: before 1.18.0
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
gitpython: before 3.1.50
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
jupyter-server: before 2.18.0
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
jupyter-server: before 2.18.0
OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere
OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere
ironic-python-agent: 1.0.0 → 11.6.0
justhtml has sanitization bypass in custom policies and programmatic DOM
justhtml has sanitization bypass in custom policies and programmatic DOM
justhtml: before 1.17.0
Multiple security fixes in justhtml
Multiple security fixes in justhtml
justhtml: before 1.16.0
justhtml includes multiple security fixes
justhtml includes multiple security fixes
justhtml: before 1.15.0
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
justhtml: 1.13.0 → 1.14.0
MONAI: Unsafe functions lead to pickle deserialization rce
MONAI: Unsafe functions lead to pickle deserialization rce
monai: before 1.6.0
vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
vllm: 0.7.0 → 0.19.0
openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys
openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys
openssl-encrypt: before 1.4.0
openssl-encrypt has no owner verification on key revocation — any client can revoke any key
openssl-encrypt has no owner verification on key revocation — any client can revoke any key
openssl-encrypt: before 1.4.0
openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage
openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage
openssl-encrypt: before 1.4.0
openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers
openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers
openssl-encrypt: before 1.4.0
openssl-encrypt has CORS wildcard with allow_credentials=True in standalone servers
openssl-encrypt has CORS wildcard with allow_credentials=True in standalone servers
openssl-encrypt: before 1.4.0
ONNX: TOCTOU arbitrary file read/write in save_external_dat
ONNX: TOCTOU arbitrary file read/write in save_external_dat
onnx: before 1.21.0
openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection
openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection
openssl-encrypt: before 1.4.0
openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification
openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification
openssl-encrypt: before 1.4.0
openssl-encrypt has visible password in process list via --password CLI argument
openssl-encrypt has visible password in process list via --password CLI argument
openssl-encrypt: before 1.4.0
openssl-encrypt silently skips schema validation when jsonschema library is not installed
openssl-encrypt silently skips schema validation when jsonschema library is not installed
openssl-encrypt: before 1.4.0
openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart
openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart
openssl-encrypt: before 1.4.0
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
justhtml: before 1.13.0
Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
nltk: all versions
JustHTML has a Sanitizer Bypass (in Markdown)
JustHTML has a Sanitizer Bypass (in Markdown)
justhtml: before 1.12.0
JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
justhtml: before 1.12.0
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
justhtml: before 1.10.0
Black: Arbitrary file writes from unsanitized user input in cache file name
Black: Arbitrary file writes from unsanitized user input in cache file name
black: 24.3.0 → 26.3.1
vLLM affected by RCE via auto_map dynamic module loading during model initialization
vLLM affected by RCE via auto_map dynamic module loading during model initialization
vllm: 0.10.1 → 0.14.0
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
distributed: before 2026.1.0
pyasn1 has a DoS vulnerability in decoder
pyasn1 has a DoS vulnerability in decoder
pyasn1: 0.6.1 → 0.6.2
XGrammar affected by Denial of Service by infinite recursion grammars
XGrammar affected by Denial of Service by infinite recursion grammars
xgrammar: before 0.1.21
Apache Superset data query improperly discloses database schema information to low-privileged guest user
Apache Superset data query improperly discloses database schema information to low-privileged guest user
apache-superset: before 4.1.3.post1
num2words subjected to phishing attack, two versions published containing malware
num2words subjected to phishing attack, two versions published containing malware
num2words: ≥ 0.5.15
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
dagster-ge: all versions
vLLM allows clients to crash the openai server with invalid regex
vLLM allows clients to crash the openai server with invalid regex
vllm: 0.8.0 → 0.9.0
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
vllm: before 0.9.0
vLLM vulnerable to Regular Expression Denial of Service
vLLM vulnerable to Regular Expression Denial of Service
vllm: 0.6.3 → 0.9.0
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
vllm: 0.7.0 → 0.9.0
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
vllm: 0.8.0 → 0.9.0
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
vllm: 0.8.0 → 0.9.0
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
vllm: 0.6.4 → 0.9.0
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
vllm: 0.6.5 → 0.8.5
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
vllm: 0.5.2 → 0.10.0
Data exposure via ZeroMQ on multi-node vLLM deployment
Data exposure via ZeroMQ on multi-node vLLM deployment
vllm: 0.5.2 → 0.8.5
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vllm: 0.6.5 → 0.8.5
vLLM: Quadratic Time Complexity in Input Token Processing leads to denial of service
vLLM: Quadratic Time Complexity in Input Token Processing leads to denial of service
vllm: 0.8.0 → 0.8.5
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
transformers: before 4.50.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
vllm: before 0.8.0
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
torch: before 2.6.0
PyTorch Improper Resource Shutdown or Release vulnerability
PyTorch Improper Resource Shutdown or Release vulnerability
torch: before 2.8.0
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
xgrammar: before 0.1.18
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
apache-airflow-providers-common-sql: before 1.24.1
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
vllm: all versions
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
transformers: before 4.48.0
vLLM Deserialization of Untrusted Data vulnerability
vLLM Deserialization of Untrusted Data vulnerability
vllm: all versions
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
vllm: all versions
vLLM denial of service via outlines unbounded cache on disk
vLLM denial of service via outlines unbounded cache on disk
vllm: before 0.8.0
vLLM Allows Remote Code Execution via Mooncake Integration
vLLM Allows Remote Code Execution via Mooncake Integration
vllm: 0.6.5 → 0.8.0
ray vulnerable to Insertion of Sensitive Information into Log File
ray vulnerable to Insertion of Sensitive Information into Log File
ray: before 2.43.0
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vllm: before 0.7.2
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: before 0.7.0
vLLM denial of service vulnerability
vLLM denial of service vulnerability
vllm: before 0.5.5
vLLM Denial of Service via the best_of parameter
vLLM Denial of Service via the best_of parameter
vllm: all versions
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
aiohttp: before 3.9.4
Pydantic regular expression denial of service
Pydantic regular expression denial of service
pydantic: 2.0.0 → 2.4.0
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.
airflow-diagrams: all versions
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
setuptools: before 65.5.1
OpenStack Neutron Improper Input Validation vulnerability
OpenStack Neutron Improper Input Validation vulnerability
neutron: 2000 → 2014.2.4
Tooling for PyPI
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.