Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
831752
AlmaLinux
5541
Alpaquita
12795
Alpine
4417
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
619
Bitnami
8525
Chainguard
10019
CleanStart
1988
CRAN
14
crates.io
2640
Debian
63432
Echo
7870
GHC
3
GIT
99198
GitHub Actions
54
Go
8603
Hackage
32
Hex
228
Julia
1655
Linux
27477
Mageia
6105
Maven
6833
MinimOS
116357
npm
226203
NuGet
1844
opam
24
openEuler
7592
openSUSE
13906
OSS-Fuzz
3979
Packagist
6822
Pub
11
PyPI
24364
Red Hat
22065
Rocky Linux
3901
Root
18881
RubyGems
4591
SUSE
22318
SwiftURL
59
TuxCare
8322
Ubuntu
59900
VSCode
20
Wolfi
7126
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1358
PyPI/fastapi-api-key
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
07 Jul
Fix available
Severity - 3.7 (Low)
PYSEC-2026-1363
PyPI/fastapi-users
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
07 Jul
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-1362
PyPI/fastapi-sso
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
07 Jul
Fix available
Severity - 5.4 (Medium)
PYSEC-2026-1360
PyPI/fastapi-guard
FastAPI Guard has a regex bypass
07 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-1359
PyPI/fastapi-guard
fastapi-guard is vulnerable to ReDoS through inefficient regex
07 Jul
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-1357
PyPI/fastapi-admin
FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
07 Jul
No fix available
Severity - 5.1 (Medium)
PYSEC-2026-1356
PyPI/fastapi-admin
FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
07 Jul
No fix available
Severity - 5.1 (Medium)
PYSEC-2026-1361
PyPI/fastapi-opa
OpaMiddleware does not filter HTTP OPTIONS requests
07 Jul
Fix available
Severity - 6.9 (Medium)
MAL-2026-1422
PyPI/fastapi-middleware-cors
Malicious code in fastapi-middleware-cors (PyPI)
13 Mar
No fix available
MAL-2026-1261
PyPI/fastapi-requests
Malicious code in fastapi-requests (PyPI)
06 Mar
No fix available
GHSA-95c6-p277-p87g
PyPI/fastapi-api-key
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
21 Jan
Fix available
Severity - 3.7 (Low)
GHSA-5j53-63w8-8625
PyPI/fastapi-users
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
19 Dec 2025
Fix available
Severity - 5.9 (Medium)
GHSA-hp6r-r9vc-q8wx
PyPI/fastapi-sso
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
19 Dec 2025
Fix available
Severity - 5.4 (Medium)
GHSA-rrf6-pxg8-684g
PyPI/fastapi-guard
FastAPI Guard has a regex bypass
23 Jul 2025
Fix available
Severity - 7.8 (High)
GHSA-j47q-rc62-w448
PyPI/fastapi-guard
fastapi-guard is vulnerable to ReDoS through inefficient regex
07 Jul 2025
Fix available
Severity - 6.9 (Medium)
PYSEC-2025-242
PyPI/fastapi-guard
See record for full details
06 May 2025
Fix available
Severity - 7.5 (High)
Load more...
(1 page left)
PyPI - OSV