boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

PyPI

Package ecosystem PyPI. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals
CVEs all-timeCVEs YTDPackages affected
22227

Monthly trend

▂▃█▆▄

2026-04 1 · 2026-05 2 · 2026-06 9 · 2026-07 6 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-54639.378.3pymetasploit3 - Command Injection via Newline Injection in console.run_module_with_outp…
CVE-2026-482079.844.9Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement
CVE-2026-153078.743.0Server-side file-write and request forgery via spatial lookups
CVE-2026-158306.942.1Potential denial-of-service vulnerability via nested geometry collections
CVE-2026-153376.942.1Potential denial-of-service vulnerability in check_for_language()
CVE-2026-145348.829.9Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess,…
CVE-2026-485882.329.3Potential exposure of private data via cached Set-Cookie response
CVE-2026-351932.329.1Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddle…
CVE-2026-485872.328.6Potential exposure of private data via whitespace padding in Vary header
CVE-2026-133465.627.9pip absolute path traversal during download from malicious package indexes
CVE-2026-145359.826.2Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in Anal…
CVE-2026-445457.525.7Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of …
CVE-2026-86434.124.9pip can extract console_scripts and gui_scripts outside installation directory
CVE-2026-159205.123.1Potential cross-site scripting via URLField values in the admin
CVE-2026-84042.321.0Potential exposure of private data via case-sensitive Cache-Control directives in Updat…
CVE-2026-538776.320.6Heap buffer over-read in GDALRaster
CVE-2026-68732.316.0Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie
CVE-2026-117643.614.0Data exposed without proper permission
CVE-2026-97123.812.7Insecure direct object reference
CVE-2026-538785.311.0Header injection possibility since DomainNameValidator accepted newlines in input

Most-affected packages

Packages with the most advisories
PackageCVEs
django12
daphne2
fickling2
pretix2
pip1
pyfory1
pymetasploit31