Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
1932362
AlmaLinux
5498
Alpaquita
12401
Alpine
4355
Android
2912
Azure Linux
12016
BellSoft Hardened Containers
612
Bitnami
8541
Chainguard
851240
CleanStart
1988
CRAN
14
crates.io
2603
Debian
61938
Docker Hardened Images
1
Echo
4306
GHC
3
GIT
95684
GitHub Actions
54
Go
8523
Hackage
32
Hex
219
Julia
1548
Linux
26003
Mageia
6096
Maven
6783
MinimOS
103609
npm
225743
NuGet
1818
opam
24
openEuler
7498
openSUSE
13830
OSS-Fuzz
3983
Packagist
6774
Pub
11
PyPI
24265
Red Hat
21891
Rocky Linux
3842
Root
18789
RubyGems
4583
SUSE
22121
SwiftURL
58
TuxCare
8256
Ubuntu
59211
VSCode
20
Wolfi
292666
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-13665
PyPI/riakcs
Malicious code in riakcs (PyPI)
2 hours ago
No fix available
GHSA-fp3f-mc75-235c
PyPI/pypdf
pypdf: Possible large memory usage for large /ToUnicode streams
yesterday
Fix available
Severity - 4.8 (Medium)
GHSA-fwg2-594c-jp42
PyPI/pypdf
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
yesterday
Fix available
Severity - 4.8 (Medium)
GHSA-gm37-52c6-37mw
PyPI/pymdown-extensions
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
yesterday
Fix available
Severity - 7.5 (High)
MAL-2026-13619
PyPI/atlas-internal
Malicious code in atlas-internal (PyPI)
yesterday
No fix available
GHSA-wvpp-8hx9-p66j
PyPI/gitpython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
yesterday
Fix available
Severity - 8.8 (High)
GHSA-jm78-9fvv-mhgr
PyPI/gitpython
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
yesterday
Fix available
Severity - 8.8 (High)
GHSA-hmq2-w58f-27jc
PyPI/gitpython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
yesterday
Fix available
Severity - 8.2 (High)
GHSA-hh9p-6wh2-4mfc
PyPI/gitpython
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
yesterday
Fix available
Severity - 6.5 (Medium)
GHSA-9rj7-rf2p-w77r
PyPI/gitpython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
yesterday
Fix available
Severity - 7.5 (High)
GHSA-4gmw-gg2m-w46p
PyPI/gitpython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
yesterday
Fix available
Severity - 8.1 (High)
MAL-2026-13606
PyPI/cdktn-provider-azurerm
Malicious code in cdktn-provider-azurerm (PyPI)
yesterday
No fix available
MAL-2026-13607
PyPI/speed-hashes
Malicious code in speed-hashes (PyPI)
yesterday
No fix available
MAL-2026-13490
PyPI/fast-hashes
Malicious code in fast-hashes (PyPI)
yesterday
No fix available
MAL-2026-13488
PyPI/idnna
Malicious code in idnna (PyPI)
yesterday
No fix available
MAL-2026-13489
PyPI/pydanticc
Malicious code in pydanticc (PyPI)
yesterday
No fix available
Load more...
PyPI - OSV