Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
| ID | Severity | Description | Package | Published | Updated |
|---|---|---|---|---|---|
| pysec-2026-4059 |
6.8 (3.1)
|
## Description A language pack ships a `Plural-Forms` header saying how the language cou… | jupyterlite-core | 2026-10-01T16:44:34.781942Z | 2026-10-01T17:10:25.828296Z |
| pysec-2026-4056 |
6.8 (3.1)
|
## Description A language pack ships a `Plural-Forms` header saying how the language cou… | jupyterlab | 2026-10-01T16:44:34.714662Z | 2026-10-01T17:10:25.646257Z |
| pysec-2026-4055 |
5.4 (3.1)
|
JupyterLab's PyPI extension manager runs `python -m pip uninstall` with the extension nam… | jupyterlab | 2026-10-01T16:44:34.569594Z | 2026-10-01T17:10:25.523160Z |
| pysec-2026-4060 |
8.1 (3.1)
|
## Description JupyterLab 4.5.0 enabled copying and pasing cells through the system clip… | jupyterlite-core | 2026-10-01T16:44:34.455277Z | 2026-10-01T17:10:25.896827Z |
| pysec-2026-4058 |
8.1 (3.1)
|
## Description JupyterLab 4.5.0 enabled copying and pasing cells through the system clip… | jupyterlite | 2026-10-01T16:44:34.300579Z | 2026-10-01T17:10:25.963722Z |
| pysec-2026-4112 |
8.1 (3.1)
|
## Description JupyterLab 4.5.0 enabled copying and pasing cells through the system clip… | notebook | 2026-10-01T16:44:34.145574Z | 2026-10-01T17:10:33.634055Z |
| pysec-2026-4057 |
8.1 (3.1)
|
## Description JupyterLab 4.5.0 enabled copying and pasing cells through the system clip… | jupyterlab | 2026-10-01T16:44:34.044285Z | 2026-10-01T17:10:25.762677Z |
| pysec-2026-4159 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:44:33.811924Z | 2026-10-01T17:10:42.141380Z |
| pysec-2026-4157 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:44:33.743667Z | 2026-10-01T17:10:42.015222Z |
| pysec-2026-4160 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to large … | pypdf | 2026-10-01T16:44:33.671507Z | 2026-10-01T17:10:42.203842Z |
| pysec-2026-4156 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:44:33.582610Z | 2026-10-01T17:10:41.950943Z |
| pysec-2026-4155 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to large … | pypdf | 2026-10-01T16:38:41.851001Z | 2026-10-01T17:10:41.886761Z |
| pysec-2026-4154 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to large … | pypdf | 2026-10-01T16:38:41.774257Z | 2026-10-01T17:10:41.825581Z |
| pysec-2026-4153 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:38:41.707415Z | 2026-10-01T17:10:41.759327Z |
| pysec-2026-4158 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to large … | pypdf | 2026-10-01T16:38:41.641499Z | 2026-10-01T17:10:42.078173Z |
| pysec-2026-4146 |
6.5 (3.1)
|
### Summary `PyJWT.decode()`/`decode_complete()` mutates a caller-supplied `options` dic… | pyjwt | 2026-10-01T16:38:41.559119Z | 2026-10-01T17:10:41.224315Z |
| pysec-2026-4066 |
6.5 (3.1)
|
### Impact Any authenticated LiteLLM proxy user could redirect an outbound provider call… | litellm | 2026-10-01T16:38:41.476323Z | 2026-10-01T17:10:28.075870Z |
| pysec-2026-4141 |
5.3 (3.1)
|
## Summary `PyJWKClient.get_signing_key_from_jwt(token)` — the first step of the JWKS ve… | pyjwt | 2026-10-01T16:38:41.274770Z | 2026-10-01T17:10:40.882194Z |
| pysec-2026-4176 |
6.9 (4.0)
|
### Impact urllib3's streaming API is designed for the efficient handling of large HTTP … | urllib3 | 2026-10-01T16:38:41.188251Z | 2026-10-01T17:10:45.203786Z |
| pysec-2026-4177 |
8.9 (4.0)
|
## Impact urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usa… | urllib3 | 2026-10-01T16:38:41.098900Z | 2026-10-01T17:10:45.268002Z |
| pysec-2026-4175 |
7.6 (4.0)
|
## Impact urllib3 supports configuring TLS independently for an HTTPS proxy and the targ… | urllib3 | 2026-10-01T16:38:40.937127Z | 2026-10-01T17:10:45.137691Z |
| pysec-2026-4148 |
4.4 (3.1)
|
### Summary There is a Re-DoS vulnerability in the `is_pem_format` function which results… | pyjwt | 2026-10-01T16:38:40.870806Z | 2026-10-01T17:10:41.357291Z |
| pysec-2026-4143 |
7.4 (3.1)
|
### Summary A service that verifies HS256 tokens using an empty oct JWK through PyJWK, i… | pyjwt | 2026-10-01T16:38:40.789707Z | 2026-10-01T17:10:41.017429Z |
| pysec-2026-4142 |
5.3 (3.1)
|
## Package pyjwt (PyPI) ## Affected versions tested & verified on: 2.13.0. Every versi… | pyjwt | 2026-10-01T16:38:40.723951Z | 2026-10-01T17:10:40.950901Z |
| pysec-2026-4147 |
4.8 (3.1)
|
## Summary PyJWT 2.13.0 accepts compact JWS signature segments containing characters tha… | pyjwt | 2026-10-01T16:38:40.657304Z | 2026-10-01T17:10:41.290228Z |
| pysec-2026-4145 |
9.1 (3.1)
|
**Prerequisites** (both conditions must hold; both are deployment properties, not attacke… | pyjwt | 2026-10-01T16:38:40.589286Z | 2026-10-01T17:10:41.156956Z |
| pysec-2026-4151 |
7.4 (3.1)
|
### Summary PyJWT 2.13.0 contains an incomplete defense against algorithm confusion when… | pyjwt | 2026-10-01T16:38:40.507318Z | 2026-10-01T16:38:40.507318Z |
| pysec-2026-4144 |
7.4 (3.1)
|
### Summary PyJWT 2.13.0 `PyJWKClient` followed HTTP redirects while fetching a JWKS, wi… | pyjwt | 2026-10-01T16:38:40.431819Z | 2026-10-01T17:10:41.093261Z |
| pysec-2026-4149 |
7.4 (3.1)
|
### Summary `HMACAlgorithm.prepare_key` blocks asymmetric keys from being used as HMAC s… | pyjwt | 2026-10-01T16:38:40.355706Z | 2026-10-01T17:10:41.430475Z |
| pysec-2026-4150 |
7.4 (3.1)
|
## Affected Package - **Package**: PyJWT (`pyjwt` on PyPI) - **Repository**: https://www… | pyjwt | 2026-10-01T16:38:40.289982Z | 2026-10-01T16:38:40.289982Z |