Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
| ID | Severity | Description | Package | Published | Updated |
|---|---|---|---|---|---|
| pysec-2025-19 |
9.8 (3.1)
|
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for … | picklescan | 2025-03-03T19:15:34+00:00 | 2027-07-09T15:54:00+00:00 |
| pysec-2024-115 |
9.8 (3.1)
|
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain-community versi… | langchain-community | 2024-11-05T16:04:14Z | 2027-07-09T15:45:00Z |
| pysec-2025-102 |
6.6 (3.1)
|
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows at… | dagster-ge | 2025-07-22T17:15:33.543Z | 2026-10-01T17:25:55.006447Z |
| pysec-2026-4182 |
8.7 (4.0)
|
### Impact Denial of service via memory exhaustion. Affects all callers who streamed com… | zapros | 2026-10-01T16:38:38.425485Z | 2026-10-01T17:10:47.715391Z |
| pysec-2026-4181 |
6.9 (4.0)
|
### Impact **Who is impacted**: - Any application using Zapros to make HTTP requests t… | zapros | 2026-10-01T16:38:38.510801Z | 2026-10-01T17:10:47.653559Z |
| pysec-2026-4180 |
2.3 (3.1)
|
### Impact wlc could send an unscoped API token to an unintended server when run inside … | wlc | 2026-10-01T16:38:34.427351Z | 2026-10-01T17:10:47.471692Z |
| pysec-2026-4179 |
6.5 (3.1)
|
### Summary The audio decode-duration guard (`max_duration_s`, env `VLLM_MAX_AUDIO_DECODE… | vllm | 2026-10-01T16:38:32.289483Z | 2026-10-01T17:10:45.836187Z |
| pysec-2026-4178 |
6.5 (3.1)
|
## Summary Current vLLM `main` lets an inference request choose the PyNvVideoCodec GPU v… | vllm | 2026-10-01T16:38:32.983082Z | 2026-10-01T17:10:45.758005Z |
| pysec-2026-4177 |
8.9 (4.0)
|
## Impact urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usa… | urllib3 | 2026-10-01T16:38:41.098900Z | 2026-10-01T17:10:45.268002Z |
| pysec-2026-4176 |
6.9 (4.0)
|
### Impact urllib3's streaming API is designed for the efficient handling of large HTTP … | urllib3 | 2026-10-01T16:38:41.188251Z | 2026-10-01T17:10:45.203786Z |
| pysec-2026-4175 |
7.6 (4.0)
|
## Impact urllib3 supports configuring TLS independently for an HTTPS proxy and the targ… | urllib3 | 2026-10-01T16:38:40.937127Z | 2026-10-01T17:10:45.137691Z |
| pysec-2026-4174 |
7.8 (3.1)
|
A vulnerability in Hugging Face Transformers (versions 4.49.0, <= 5.8.1) allows remote Py… | transformers | 2026-10-01T16:38:29.265731Z | 2026-10-01T17:10:44.917354Z |
| pysec-2026-4173 |
5.4 (3.1)
5.3 (4.0)
|
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-… | swift | 2026-10-01T16:38:28.770708Z | 2026-10-01T17:10:44.620253Z |
| pysec-2026-4172 |
6.5 (3.1)
|
## Summary `HTTPSession` mounts a `FileAdapter` for the `file://` scheme and inherits re… | streamlink | 2026-10-01T16:38:38.819090Z | 2026-10-01T17:10:44.555055Z |
| pysec-2026-4171 |
5.3 (3.1)
|
## Summary Before tokenizing, `selector_iter` trims leading/trailing whitespace and comm… | soupsieve | 2026-10-01T16:38:33.150066Z | 2026-10-01T17:10:44.303865Z |
| pysec-2026-4170 |
5.3 (3.1)
|
## Summary soupsieve compiles CSS selector strings with a set of hand-written regular ex… | soupsieve | 2026-10-01T16:38:33.233778Z | 2026-10-01T17:10:44.232749Z |
| pysec-2026-4169 |
4.3 (3.1)
|
### Impact The LoginRadius backend did not validate OAuth state during the authenticatio… | social-auth-core | 2026-10-01T16:38:39.689011Z | 2026-10-01T17:10:44.167438Z |
| pysec-2026-4168 |
4.2 (3.1)
|
### Impact The partial-pipeline resume mechanism accepted `partial_token` as a bearer cr… | social-auth-core | 2026-10-01T16:38:39.841686Z | 2026-10-01T17:10:44.092164Z |
| pysec-2026-4167 |
6.4 (3.1)
|
### Impact The SAML backend accepted SAML responses on the Assertion Consumer Service en… | social-auth-core | 2026-10-01T16:38:39.533562Z | 2026-10-01T17:10:44.030888Z |
| pysec-2026-4166 |
6.8 (3.1)
|
### Impact The Vend OAuth2 backend used only the numeric Vend `user_id` as the social-au… | social-auth-core | 2026-10-01T16:38:39.609103Z | 2026-10-01T17:10:43.861661Z |
| pysec-2026-4165 |
7.4 (3.1)
|
### Impact The `vk-app` backend accepted VK application callback data without verifying … | social-auth-core | 2026-10-01T16:38:39.761759Z | 2026-10-01T17:10:43.798424Z |
| pysec-2026-4164 |
9.8 (3.1)
9.3 (4.0)
|
sentence-transformers contains a security control bypass vulnerability that allows attack… | sentence-transformers | 2026-10-01T16:38:29.083815Z | 2026-10-01T17:10:43.456495Z |
| pysec-2026-4163 |
7.5 (3.1)
|
### Summary The AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes… | scbe-aethermoore | 2026-10-01T16:38:39.907865Z | 2026-10-01T17:10:43.252711Z |
| pysec-2026-4162 |
6.5 (3.1)
|
## Description Sanic's HTTP/1.1 chunked-body handling does not fully consume the `traile… | sanic | 2026-10-01T16:38:32.632363Z | 2026-10-01T17:10:43.173636Z |
| pysec-2026-4161 |
8.4 (3.1)
|
### Impact RestrictedPython could allow a sandbox escape when a policy exposes the standa… | restrictedpython | 2026-10-01T16:38:32.711117Z | 2026-10-01T17:10:43.013392Z |
| pysec-2026-4160 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to large … | pypdf | 2026-10-01T16:44:33.671507Z | 2026-10-01T17:10:42.203842Z |
| pysec-2026-4159 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:44:33.811924Z | 2026-10-01T17:10:42.141380Z |
| pysec-2026-4158 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to large … | pypdf | 2026-10-01T16:38:41.641499Z | 2026-10-01T17:10:42.078173Z |
| pysec-2026-4157 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:44:33.743667Z | 2026-10-01T17:10:42.015222Z |
| pysec-2026-4156 |
8.7 (4.0)
|
### Impact An attacker who uses this vulnerability can craft a PDF which leads to long r… | pypdf | 2026-10-01T16:44:33.582610Z | 2026-10-01T17:10:41.950943Z |