Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2144686
AlmaLinux
5779
Alpaquita
14297
Alpine
4586
Android
3666
Azure Linux
16341
BellSoft Hardened Containers
739
Bitnami
9134
Chainguard
998327
CleanStart
3765
CRAN
14
crates.io
2696
Debian
66084
Echo
8870
GHC
3
GIT
104040
GitHub Actions
55
Go
9067
Hackage
32
Hex
329
Julia
1713
Linux
28492
Mageia
6169
Maven
6965
MinimOS
139998
npm
228271
NuGet
1852
opam
29
openEuler
8541
openSUSE
14255
OSS-Fuzz
3994
Packagist
6997
Pub
11
PyPI
25014
Red Hat
22853
Rocky Linux
4154
Root
19316
RubyGems
4709
SUSE
22844
SwiftURL
59
TuxCare
8986
Ubuntu
62598
VSCode
21
Wolfi
279021
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2001
PyPI/uv
uv allows ZIP payload obfuscation through parsing differentials
07 Jul
Fix available
Severity - 6.8 (Medium)
GHSA-4gg8-gxpx-9rph
PyPI/uv
crates.io/uv
uv is vulnerable to arbitrary file write through entry point names
29 May
Fix available
GHSA-pjjw-68hj-v9mw
PyPI/uv
uv vulnerable to arbitrary file deletion through RECORD entries
10 Apr
Fix available
Severity - 2.1 (Low)
PYSEC-2026-2295
PyPI/uv
See record for full details
27 Feb
Fix available
Severity - 6.3 (Medium)
GHSA-pqhf-p39g-3x64
PyPI/uv
uv allows ZIP payload obfuscation through parsing differentials
29 Oct 2025
Fix available
Severity - 6.8 (Medium)
GHSA-w476-p2h3-79g9
PyPI/uv
uv has differential in tar extraction with PAX headers
21 Oct 2025
Fix available
GHSA-8qf3-x8v5-2pj8
PyPI/uv
uv allows ZIP payload obfuscation through parsing differentials
07 Aug 2025
Fix available
Severity - 6.8 (Medium)
PyPI - OSV