boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

PyPI

Package ecosystem PyPI. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
484824

Monthly trend

▁▂▅▄▇█▂

2026-04 1 · 2026-05 2 · 2026-06 9 · 2026-07 6 · 2026-08 13 · 2026-09 15 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-54639.388.3—pymetasploit3 - Command Injection via Newline Injection in console.run_module_with_outp…
CVE-2026-768509.368.8—LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated S…
CVE-2026-153078.764.3—Server-side file-write and request forgery via spatial lookups
CVE-2026-768418.762.4—Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Mode…
CVE-2026-1053147.558.3——
CVE-2026-482079.855.7—Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement
CVE-2026-1051059.854.5—Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft comma…
CVE-2026-158306.953.8—Potential denial-of-service vulnerability via nested geometry collections
CVE-2026-728188.753.1—NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input
CVE-2026-936888.752.3—SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room
CVE-2026-842028.750.8—ModelScope through 1.40.0 Unsafe YAML Deserialization in Model Config Loading
CVE-2026-938388.249.5—SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
CVE-2026-777769.347.5—Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated…
CVE-2026-728487.747.1—langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Site…
CVE-2026-860998.846.8—Chainlit through 2.12.0 Path Traversal via socket.io sessionId
CVE-2026-145348.846.6—Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess,…
CVE-2026-777757.746.5—Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Va…
CVE-2026-153376.946.3—Potential denial-of-service vulnerability in check_for_language()
CVE-2026-1026348.745.9—SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room
CVE-2026-445457.545.4—Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of …

Most-affected packages

Packages with the most advisories
PackageCVEs
django12
snowflake-connector-python3
blackduck-c-cpp2
daphne2
fickling2
headroom-ai2
pretix2
reachy_mini2
aig-skill-scan1
ait-core1
chainlit1
django-allauth1
flair1
langchain-community1
lmdeploy1