[go: up one dir, main page]

Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-11521
  • PyPI/psbt-helpers
Malicious code in psbt-helpers (PyPI) 4 hours ago
  • No fix available
MAL-2026-11519
  • PyPI/launchdarkly-ai-server-sdk
Malicious code in launchdarkly-ai-server-sdk (PyPI) 4 hours ago
  • No fix available
MAL-2026-11520
  • PyPI/psbt-utils
Malicious code in psbt-utils (PyPI) 4 hours ago
  • No fix available
MAL-2026-11516
  • PyPI/coldcard-helpers
Malicious code in coldcard-helpers (PyPI) 9 hours ago
  • No fix available
GHSA-m2h6-j472-rp4c
  • PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees 16 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-jwv3-5hgf-82ww
  • PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building 16 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-g6cj-pr64-35w5
  • PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing 17 hours ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-cq5v-8q36-5273
  • PyPI/aiohttp
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) 17 hours ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-mfx4-hv73-q22v
  • PyPI/aiohttp
AIOHTTP: HTTP request smuggling via WebSocket upgrade 17 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-mq44-7p77-q5h7
  • PyPI/aiohttp
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate 17 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
MAL-2026-11503
  • PyPI/instalogin1234
Malicious code in instalogin1234 (PyPI) 17 hours ago
  • No fix available
GHSA-p538-c434-8v24
  • PyPI/gitpython
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count 17 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-539m-9xh6-q6rr
  • PyPI/gitpython
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive() 18 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-3f7w-8rr8-f37f
  • PyPI/gitpython
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read 18 hours ago
  • Fix available
  • Severity - 8.1 (High)
MAL-2026-11429
  • PyPI/trongriden
Malicious code in trongriden (PyPI) 2 days ago
  • No fix available
MAL-2026-11428
  • PyPI/wacve-utils
Malicious code in wacve-utils (PyPI) 2 days ago
  • No fix available