CVE Tools

PyPI

4,514 CVEs tracked since 2000. Since Sep 2021, 5 of them reached CISA KEV.

PyPI CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
PyPI CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09290
2021-10290
2021-11560
2021-12260
2022-01400
2022-02750
2022-03540
2022-04140
2022-05450
2022-06370
2022-07341
2022-08260
2022-091140
2022-10310
2022-11590
2022-12420
2023-01380
2023-02340
2023-03null or fewer
2023-04341
2023-05310
2023-06300
2023-07460
2023-08470
2023-09471
2023-10530
2023-11540
2023-12520
2024-01770
2024-02660
2024-03480
2024-04660
2024-05650
2024-06830
2024-07590
2024-08400
2024-09530
2024-10450
2024-11510
2024-12320
2025-01230
2025-02250
2025-031660
2025-04361
2025-05470
2025-06470
2025-07510
2025-08750
2025-09570
2025-10700
2025-11470
2025-12741
2026-01980
2026-021260
2026-03940
2026-04590
2026-05370
2026-06980
2026-07330
2026-08560
2026-0960

Products

The products that kept showing up in PyPI's monthly top three, with their CVEs summed over those months.

  1. Tensorflow2015 months
  2. Tensorflow-gpu2006 months
  3. Tensorflow-cpu1985 months
  4. Picklescan625 months
  5. Apache-superset459 months
  6. Praisonai352 months
  7. Mlflow345 months
  8. Vyper318 months
  9. Paddlepaddle293 months
  10. Nltk241 month

Latest CVEs

The 15 most recently published vulnerabilities affecting PyPI.

  1. GHSA-62mm-xwmv-crhgkhoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem—
  2. GHSA-g28h-2cmm-rj9xlangchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs—
  3. GHSA-8pcw-h6w9-h46gplone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length—
  4. GHSA-39wr-7q6h-cf68LMDeploy has an SSRF bypass—
  5. GHSA-xjw9-38cr-6372djust: A template binding inherits a context safety grant it never earned (XSS)—
  6. GHSA-9395-2g46-rj3fdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)—
  7. GHSA-8423-8fgw-73vqtornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)—
  8. GHSA-wwv5-g3v4-889xTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`—
  9. GHSA-gqvg-gmmx-x4hmMLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact—
  10. GHSA-73p9-6hrp-8qhrAIIR verification and policy gates could report success without enforcing the control (fail-open)—
  11. GHSA-x287-5c68-36wpOpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses—
  12. GHSA-93qj-5q5v-3c2hTrojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)—
  13. GHSA-vwf3-4xxj-qg6hmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment—
  14. GHSA-8cp3-qxj6-px34utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion—
  15. GHSA-ppx3-28rw-8fpfutcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins—

The record

Peak rank
#2 in May 2021
Busiest month shown
Mar 2025, 166 CVEs
Months with a KEV entry
5 since Sep 2021
Monthly snapshots
196 since 2000
PyPI's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store