Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Package ecosystem PyPI. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 22 | 22 | 7 |
▂▃█▆▄
2026-04 1 · 2026-05 2 · 2026-06 9 · 2026-07 6 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-5463 | 9.3 | 78.3 | — | pymetasploit3 - Command Injection via Newline Injection in console.run_module_with_outp… |
| CVE-2026-48207 | 9.8 | 44.9 | — | Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement |
| CVE-2026-15307 | 8.7 | 43.0 | — | Server-side file-write and request forgery via spatial lookups |
| CVE-2026-15830 | 6.9 | 42.1 | — | Potential denial-of-service vulnerability via nested geometry collections |
| CVE-2026-15337 | 6.9 | 42.1 | — | Potential denial-of-service vulnerability in check_for_language() |
| CVE-2026-14534 | 8.8 | 29.9 | — | Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess,… |
| CVE-2026-48588 | 2.3 | 29.3 | — | Potential exposure of private data via cached Set-Cookie response |
| CVE-2026-35193 | 2.3 | 29.1 | — | Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddle… |
| CVE-2026-48587 | 2.3 | 28.6 | — | Potential exposure of private data via whitespace padding in Vary header |
| CVE-2026-13346 | 5.6 | 27.9 | — | pip absolute path traversal during download from malicious package indexes |
| CVE-2026-14535 | 9.8 | 26.2 | — | Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in Anal… |
| CVE-2026-44545 | 7.5 | 25.7 | — | Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of … |
| CVE-2026-8643 | 4.1 | 24.9 | — | pip can extract console_scripts and gui_scripts outside installation directory |
| CVE-2026-15920 | 5.1 | 23.1 | — | Potential cross-site scripting via URLField values in the admin |
| CVE-2026-8404 | 2.3 | 21.0 | — | Potential exposure of private data via case-sensitive Cache-Control directives in Updat… |
| CVE-2026-53877 | 6.3 | 20.6 | — | Heap buffer over-read in GDALRaster |
| CVE-2026-6873 | 2.3 | 16.0 | — | Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie |
| CVE-2026-11764 | 3.6 | 14.0 | — | Data exposed without proper permission |
| CVE-2026-9712 | 3.8 | 12.7 | — | Insecure direct object reference |
| CVE-2026-53878 | 5.3 | 11.0 | — | Header injection possibility since DomainNameValidator accepted newlines in input |
| Package | CVEs |
|---|---|
| django | 12 |
| daphne | 2 |
| fickling | 2 |
| pretix | 2 |
| pip | 1 |
| pyfory | 1 |
| pymetasploit3 | 1 |