Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2376
  • PyPI/apache-superset
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2375
  • PyPI/apache-superset
Apache Superset allows authenticated users to view sensitive data without explicit permissions 13 Jul
  • Fix available
  • Severity - 2.3 (Low)
PYSEC-2026-2373
  • PyPI/apache-superset
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2374
  • PyPI/apache-superset
Apache Superset allows privileged users to conduct error-based SQL Injection 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2372
  • PyPI/apache-superset
Apache Superset Improper Authorization allows low-privileged users to bypass access controls 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-1178
  • PyPI/apache-superset
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1169
  • PyPI/apache-superset
Apache Superset data query improperly discloses database schema information to low-privileged guest user 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1176
  • PyPI/apache-superset
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1186
  • PyPI/apache-superset
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1164
  • PyPI/apache-superset
Apache Superset: Improper authorization bypass on row level security via SQL Injection 07 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-1189
  • PyPI/apache-superset
Apache Superset Allows Ownership Takeover 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1162
  • PyPI/apache-superset
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access 07 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-1154
  • PyPI/apache-superset
Apache Superset: Error verbosity exposes metadata in analytics databases 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1165
  • PyPI/apache-superset
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions 07 Jul
  • Fix available
  • Severity - 2.3 (Low)
PYSEC-2026-1156
  • PyPI/apache-superset
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled 07 Jul
  • Fix available
  • Severity - 7.6 (High)
PYSEC-2026-1155
  • PyPI/apache-superset
Apache Superset vulnerable to improper SQL authorization 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)