Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16274
  • PyPI/requests-auroras
Malicious code in requests-auroras (PyPI) 16 hours ago
  • No fix available
MAL-2026-16275
  • PyPI/requests-triwes
Malicious code in requests-triwes (PyPI) 16 hours ago
  • No fix available
MAL-2026-16269
  • PyPI/requests-asetwe
Malicious code in requests-asetwe (PyPI) 17 hours ago
  • No fix available
MAL-2026-16268
  • PyPI/index-forum
Malicious code in index-forum (PyPI) 17 hours ago
  • No fix available
MAL-2026-16267
  • PyPI/pyjstat-smooth
Malicious code in pyjstat-smooth (PyPI) 18 hours ago
  • No fix available
GHSA-gjv8-xp57-g29c
  • PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns 19 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-j934-xhv5-fg8f
  • PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors) 19 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-xjw9-38cr-6372
  • PyPI/djust
djust: A template binding inherits a context safety grant it never earned (XSS) 19 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-9395-2g46-rj3f
  • PyPI/djust
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS) 19 hours ago
  • Fix available
GHSA-c3mw-737p-c7g2
  • PyPI/jupyter-server
Jupyter Server: 5xx request logging leaks token-bearing Referer header values 19 hours ago
  • Fix available
  • Severity - 7.1 (High)
MAL-2026-16264
  • PyPI/aiosendletter
Malicious code in aiosendletter (PyPI) 20 hours ago
  • No fix available
GHSA-8pw2-6jv3-mj5j
  • PyPI/vllm
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation 22 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-pq59-9fq7-m886
  • PyPI/accesscontrol
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions 23 hours ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-hp3v-5vw7-fx9w
  • PyPI/restrictedpython
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution 23 hours ago
  • Fix available
  • Severity - 8.4 (High)
GHSA-wmj6-g64g-j7q5
  • PyPI/sanic
sanic chunked trailer request smuggling allows hidden second request execution yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rw4j-r22c-9gc3
  • PyPI/asyncssh
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION yesterday
  • Fix available
  • Severity - 6.5 (Medium)