Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-13665
  • PyPI/riakcs
Malicious code in riakcs (PyPI) 2 hours ago
  • No fix available
GHSA-fp3f-mc75-235c
  • PyPI/pypdf
pypdf: Possible large memory usage for large /ToUnicode streams yesterday
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-fwg2-594c-jp42
  • PyPI/pypdf
pypdf: Possible long runtimes/large memory usage for large CID font width ranges yesterday
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-gm37-52c6-37mw
  • PyPI/pymdown-extensions
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors yesterday
  • Fix available
  • Severity - 7.5 (High)
MAL-2026-13619
  • PyPI/atlas-internal
Malicious code in atlas-internal (PyPI) yesterday
  • No fix available
GHSA-wvpp-8hx9-p66j
  • PyPI/gitpython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-jm78-9fvv-mhgr
  • PyPI/gitpython
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE) yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-hmq2-w58f-27jc
  • PyPI/gitpython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython yesterday
  • Fix available
  • Severity - 8.2 (High)
GHSA-hh9p-6wh2-4mfc
  • PyPI/gitpython
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-9rj7-rf2p-w77r
  • PyPI/gitpython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-4gmw-gg2m-w46p
  • PyPI/gitpython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite yesterday
  • Fix available
  • Severity - 8.1 (High)
MAL-2026-13606
  • PyPI/cdktn-provider-azurerm
Malicious code in cdktn-provider-azurerm (PyPI) yesterday
  • No fix available
MAL-2026-13607
  • PyPI/speed-hashes
Malicious code in speed-hashes (PyPI) yesterday
  • No fix available
MAL-2026-13490
  • PyPI/fast-hashes
Malicious code in fast-hashes (PyPI) yesterday
  • No fix available
MAL-2026-13488
  • PyPI/idnna
Malicious code in idnna (PyPI) yesterday
  • No fix available
MAL-2026-13489
  • PyPI/pydanticc
Malicious code in pydanticc (PyPI) yesterday
  • No fix available