Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
PyPI
Package ecosystem PyPI. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 48 | 48 | 24 |
Monthly trend
▁▂▅▄▇█▂
2026-04 1 · 2026-05 2 · 2026-06 9 · 2026-07 6 · 2026-08 13 · 2026-09 15 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-5463 | 9.3 | 88.3 | — | pymetasploit3 - Command Injection via Newline Injection in console.run_module_with_outp… |
| CVE-2026-76850 | 9.3 | 68.8 | — | LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated S… |
| CVE-2026-15307 | 8.7 | 64.3 | — | Server-side file-write and request forgery via spatial lookups |
| CVE-2026-76841 | 8.7 | 62.4 | — | Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Mode… |
| CVE-2026-105314 | 7.5 | 58.3 | — | — |
| CVE-2026-48207 | 9.8 | 55.7 | — | Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement |
| CVE-2026-105105 | 9.8 | 54.5 | — | Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft comma… |
| CVE-2026-15830 | 6.9 | 53.8 | — | Potential denial-of-service vulnerability via nested geometry collections |
| CVE-2026-72818 | 8.7 | 53.1 | — | NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input |
| CVE-2026-93688 | 8.7 | 52.3 | — | SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room |
| CVE-2026-84202 | 8.7 | 50.8 | — | ModelScope through 1.40.0 Unsafe YAML Deserialization in Model Config Loading |
| CVE-2026-93838 | 8.2 | 49.5 | — | SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx |
| CVE-2026-77776 | 9.3 | 47.5 | — | Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated… |
| CVE-2026-72848 | 7.7 | 47.1 | — | langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Site… |
| CVE-2026-86099 | 8.8 | 46.8 | — | Chainlit through 2.12.0 Path Traversal via socket.io sessionId |
| CVE-2026-14534 | 8.8 | 46.6 | — | Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess,… |
| CVE-2026-77775 | 7.7 | 46.5 | — | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Va… |
| CVE-2026-15337 | 6.9 | 46.3 | — | Potential denial-of-service vulnerability in check_for_language() |
| CVE-2026-102634 | 8.7 | 45.9 | — | SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room |
| CVE-2026-44545 | 7.5 | 45.4 | — | Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of … |
Most-affected packages
| Package | CVEs |
|---|---|
| django | 12 |
| snowflake-connector-python | 3 |
| blackduck-c-cpp | 2 |
| daphne | 2 |
| fickling | 2 |
| headroom-ai | 2 |
| pretix | 2 |
| reachy_mini | 2 |
| aig-skill-scan | 1 |
| ait-core | 1 |
| chainlit | 1 |
| django-allauth | 1 |
| flair | 1 |
| langchain-community | 1 |
| lmdeploy | 1 |