Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-11031
  • PyPI/govapkg
Malicious code in govapkg (PyPI) 10 hours ago
  • No fix available
GHSA-g867-7843-wf8q
  • PyPI/pypdf
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) 13 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-5xf7-4p34-54qr
  • PyPI/pypdf
pypdf: Possible infinite loop for not terminated inline images 13 hours ago
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3543
  • PyPI/open-webui
Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints 14 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-55h5-xmcq-c37v
  • PyPI/pypdf
pypdf: Possible long runtimes for repeated malformed cross-reference entries 15 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-5qjq-93h5-hrgp
  • PyPI/pypdf
pypdf: Possible large memory usage for wrong image dimensions 15 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-3478
  • PyPI/litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks 18 hours ago
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-3479
  • PyPI/litellm
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback 18 hours ago
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3476
  • PyPI/litellm
LiteLLM: Local file read via request-supplied OIDC file references 18 hours ago
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-3477
  • PyPI/litellm
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction 18 hours ago
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-3496
  • PyPI/pillow
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service 18 hours ago
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3495
  • PyPI/pillow
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() 18 hours ago
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3494
  • PyPI/pillow
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images 18 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3475
  • PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 18 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-3474
  • PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 18 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-3493
  • PyPI/pillow
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) 18 hours ago
  • Fix available
  • Severity - 8.3 (High)