Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16298
  • PyPI/urc
Malicious code in urc (PyPI) 6 hours ago
  • No fix available
MAL-2026-16296
  • PyPI/py-venv-doctor
Malicious code in py-venv-doctor (PyPI) 15 hours ago
  • No fix available
GHSA-xcw4-53cc-hv32
  • PyPI/mnemosyne-memory
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass 19 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-3w57-8xmc-8v26
  • PyPI/anyio
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups 19 hours ago
  • Fix available
  • Severity - 7.0 (High)
GHSA-82r6-8w77-94w6
  • PyPI/anyio
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing 19 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-5p39-cfhj-2xmp
  • PyPI/anyio
AnyIO process-pool workers can block indefinitely on undrained stderr 19 hours ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-39wr-7q6h-cf68
  • PyPI/lmdeploy
LMDeploy has an SSRF bypass 19 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-3hmm-rh5q-gwwr
  • PyPI/lmdeploy
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading 19 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-2vh9-42vm-xmv2
  • PyPI/lmdeploy
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py 19 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
MAL-2026-16274
  • PyPI/requests-auroras
Malicious code in requests-auroras (PyPI) yesterday
  • No fix available
MAL-2026-16275
  • PyPI/requests-triwes
Malicious code in requests-triwes (PyPI) yesterday
  • No fix available
MAL-2026-16269
  • PyPI/requests-asetwe
Malicious code in requests-asetwe (PyPI) yesterday
  • No fix available
MAL-2026-16268
  • PyPI/index-forum
Malicious code in index-forum (PyPI) yesterday
  • No fix available
MAL-2026-16267
  • PyPI/pyjstat-smooth
Malicious code in pyjstat-smooth (PyPI) yesterday
  • No fix available
GHSA-gjv8-xp57-g29c
  • PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-j934-xhv5-fg8f
  • PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors) yesterday
  • Fix available
  • Severity - 5.3 (Medium)