Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
828145
AlmaLinux
5541
Alpaquita
12795
Alpine
4417
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
619
Bitnami
8525
Chainguard
10019
CleanStart
1988
CRAN
14
crates.io
2640
Debian
63410
Echo
7870
GHC
3
GIT
99191
GitHub Actions
54
Go
8603
Hackage
32
Hex
228
Julia
1655
Linux
27477
Mageia
6105
Maven
6833
MinimOS
112794
npm
226203
NuGet
1844
opam
24
openEuler
7592
openSUSE
13885
OSS-Fuzz
3978
Packagist
6822
Pub
11
PyPI
24363
Red Hat
22068
Rocky Linux
3901
Root
18886
RubyGems
4591
SUSE
22318
SwiftURL
59
TuxCare
8322
Ubuntu
59900
VSCode
20
Wolfi
7126
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9hgc-g3w5-67cm
PyPI/mcp-contextforge-gateway
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
yesterday
Fix available
Severity - 6.6 (Medium)
GHSA-m42h-3232-vpv3
PyPI/nltk
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
2 days ago
Fix available
Severity - 7.5 (High)
GHSA-87x5-vmc3-756j
PyPI/vllm
vLLM: Completion prompt lists fan out into unbounded engine requests
2 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-rm43-82j9-r4mj
PyPI/atomic-agents-stack
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
2 days ago
Fix available
Severity - 8.2 (High)
GHSA-h7p7-w5gc-xj3w
PyPI/pydantic-ai
PyPI/pydantic-ai-slim
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
2 days ago
Fix available
Severity - 6.8 (Medium)
GHSA-cxgv-hp74-jj7r
PyPI/ansible-jailexec
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
3 days ago
Fix available
Severity - 7.7 (High)
GHSA-49m4-vp58-wgc9
PyPI/stata-mcp
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
3 days ago
Fix available
Severity - 8.4 (High)
GHSA-h47f-gmjp-m7rr
PyPI/compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
3 days ago
Fix available
Severity - 8.6 (High)
GHSA-gqgw-jghv-mxwx
PyPI/tablib
tablib: Stored XSS in the HTML export via unescaped dataset title
4 days ago
Fix available
Severity - 4.8 (Medium)
MAL-2026-13756
PyPI/joule-sbx-poc
Malicious code in joule-sbx-poc (PyPI)
4 days ago
No fix available
MAL-2026-13757
PyPI/telebot-pro
Malicious code in telebot-pro (PyPI)
4 days ago
No fix available
MAL-2026-13732
PyPI/joule-btp-extension
Malicious code in joule-btp-extension (PyPI)
4 days ago
No fix available
MAL-2026-13730
PyPI/euler-sdk
Malicious code in euler-sdk (PyPI)
4 days ago
No fix available
MAL-2026-13731
PyPI/morpho-sdk
Malicious code in morpho-sdk (PyPI)
4 days ago
No fix available
MAL-2026-13729
PyPI/dlmm-sdk
Malicious code in dlmm-sdk (PyPI)
5 days ago
No fix available
MAL-2026-13728
PyPI/dlmm
Malicious code in dlmm (PyPI)
5 days ago
No fix available
Load more...
PyPI - OSV