PyPI
4,514 CVEs tracked since 2000. Since Sep 2021, 5 of them reached CISA KEV.
PyPI CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 29 | 0 |
| 2021-10 | 29 | 0 |
| 2021-11 | 56 | 0 |
| 2021-12 | 26 | 0 |
| 2022-01 | 40 | 0 |
| 2022-02 | 75 | 0 |
| 2022-03 | 54 | 0 |
| 2022-04 | 14 | 0 |
| 2022-05 | 45 | 0 |
| 2022-06 | 37 | 0 |
| 2022-07 | 34 | 1 |
| 2022-08 | 26 | 0 |
| 2022-09 | 114 | 0 |
| 2022-10 | 31 | 0 |
| 2022-11 | 59 | 0 |
| 2022-12 | 42 | 0 |
| 2023-01 | 38 | 0 |
| 2023-02 | 34 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 34 | 1 |
| 2023-05 | 31 | 0 |
| 2023-06 | 30 | 0 |
| 2023-07 | 46 | 0 |
| 2023-08 | 47 | 0 |
| 2023-09 | 47 | 1 |
| 2023-10 | 53 | 0 |
| 2023-11 | 54 | 0 |
| 2023-12 | 52 | 0 |
| 2024-01 | 77 | 0 |
| 2024-02 | 66 | 0 |
| 2024-03 | 48 | 0 |
| 2024-04 | 66 | 0 |
| 2024-05 | 65 | 0 |
| 2024-06 | 83 | 0 |
| 2024-07 | 59 | 0 |
| 2024-08 | 40 | 0 |
| 2024-09 | 53 | 0 |
| 2024-10 | 45 | 0 |
| 2024-11 | 51 | 0 |
| 2024-12 | 32 | 0 |
| 2025-01 | 23 | 0 |
| 2025-02 | 25 | 0 |
| 2025-03 | 166 | 0 |
| 2025-04 | 36 | 1 |
| 2025-05 | 47 | 0 |
| 2025-06 | 47 | 0 |
| 2025-07 | 51 | 0 |
| 2025-08 | 75 | 0 |
| 2025-09 | 57 | 0 |
| 2025-10 | 70 | 0 |
| 2025-11 | 47 | 0 |
| 2025-12 | 74 | 1 |
| 2026-01 | 98 | 0 |
| 2026-02 | 126 | 0 |
| 2026-03 | 94 | 0 |
| 2026-04 | 59 | 0 |
| 2026-05 | 37 | 0 |
| 2026-06 | 98 | 0 |
| 2026-07 | 33 | 0 |
| 2026-08 | 56 | 0 |
| 2026-09 | 6 | 0 |
Products
The products that kept showing up in PyPI's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting PyPI.
- GHSA-62mm-xwmv-crhgkhoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem—
- GHSA-g28h-2cmm-rj9xlangchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs—
- GHSA-8pcw-h6w9-h46gplone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length—
- GHSA-39wr-7q6h-cf68LMDeploy has an SSRF bypass—
- GHSA-xjw9-38cr-6372djust: A template binding inherits a context safety grant it never earned (XSS)—
- GHSA-9395-2g46-rj3fdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)—
- GHSA-8423-8fgw-73vqtornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)—
- GHSA-wwv5-g3v4-889xTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`—
- GHSA-gqvg-gmmx-x4hmMLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact—
- GHSA-73p9-6hrp-8qhrAIIR verification and policy gates could report success without enforcing the control (fail-open)—
- GHSA-x287-5c68-36wpOpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses—
- GHSA-93qj-5q5v-3c2hTrojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)—
- GHSA-vwf3-4xxj-qg6hmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment—
- GHSA-8cp3-qxj6-px34utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion—
- GHSA-ppx3-28rw-8fpfutcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins—
The record
- Peak rank
- #2 in May 2021
- Busiest month shown
- Mar 2025, 166 CVEs
- Months with a KEV entry
- 5 since Sep 2021
- Monthly snapshots
- 196 since 2000