Conda-forge
4 CVEs tracked since 2025. Since Jun 2025, none of them reached CISA KEV.
Conda-forge CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-06 | 4 | 0 |
Products
The products that kept showing up in Conda-forge's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Conda-forge.
- CVE-2026-46699conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository7.6
- CVE-2025-49824conda-smithy Insecure Encryption Vulnerable to Oracle Padding Attack—
- CVE-2025-49843conda-smithy Has Incorrect Default File Permissions—
- CVE-2025-49842conda-forge-webservices Privilege Escalation Risk via Default Docker Root User—
- CVE-2025-49598conda-forge-ci-setup Allows Arbitrary Code Execution via Insecure Version Parsing—
- CVE-2025-35471conda-forge openssl-feedstock writable OPENSSLDIR7.3
- CVE-2025-32784conda-forge-webservices has an Unauthorized Artifact Modification Race Condition—
- CVE-2025-31484conda-forge infrastructure uses a bad token for Azure's cf-staging access—
- CVE-2025-27510RCE in the package conda-forge-metadata—
The record
- Peak rank
- #188 in Jun 2025
- Busiest month shown
- Jun 2025, 4 CVEs
- Months with a KEV entry
- 0 since Jun 2025
- Monthly snapshots
- 1 since 2025